Author

Topic: Data breach? (Read 410 times)

legendary
Activity: 2772
Merit: 2846
January 04, 2017, 06:16:55 AM
#4
Theymos warned us all that our email addresses, password hashes, and secret questions leaked to an attacker over a year ago. You should change your password if you haven't already done so.

Don't try accessing your account using your secret question because theymos has set the forum to lock any account that does so (as the attacker has our secret questions).

On May 22 at 00:56 UTC, an attacker gained root access to the forum's server. He then proceeded to try to acquire a dump of the forum's database before I noticed this at around 1:08 and shut down the server. In the intervening time, it seems that he was able to collect some or all of the "members" table. You should assume that the following information about your account was leaked:
- Email address

- Password hash (see below)
- Last-used IP address and registration IP address
- Secret question and a basic (not brute-force-resistant) hash of your secret answer
- Various settings

As such, you should change your password here and anywhere else you used that same password. You should disable your secret question and assume that the attacker now knows your answer to your secret question. You should prepare to receive phishing emails at your forum email address.


copper member
Activity: 1498
Merit: 1528
No I dont escrow anymore.
January 04, 2017, 03:52:00 AM
#3
There was a breach a while back, yes.
member
Activity: 112
Merit: 10
female ;)
January 04, 2017, 01:25:50 AM
#2
Your register date is     December 11, 2013, 09:47:36 PM

So yes, you're information was likely in a list of many others being spammed. Just ignore it.
newbie
Activity: 2
Merit: 0
January 04, 2017, 01:24:50 AM
#1
Has there been a recent data breach? I just received a spam message to my email. The email address used for this forum is ONLY used for this forum.

Whenever I give out an email address to someone I make sure I can identify who I gave a particular address to. If I start getting spam on that address it means 1 of 2 things usually...

1. My information was sold.

2. There was a data breach.

I checked and my email is set to not be visible publicly.
Jump to: