Getting Hacked

Status
Not open for further replies.

JHZR2

Staff member
Joined
Dec 14, 2002
Messages
56,180
Location
New Jersey
I was in Europe a few weeks ago. Not sure if that was/is the cause or what.

Last week, I got a "confirmation" from Amazon.ca that I bought a $150 gift certificate. It did not show up on my orders list/page on Amazon, but it sure looked official. I forwarded everything, email header included to Amazon, and they indicated that it was real.

Today I go on to my email, and see that Facebook tells me that I have had someone log into my facebook account from an unrecognized place. I didnt follow the link in the email, but went to Facebook directly, and it told me the same thing, that at 130AM, someone tried to log into Facebook from Verona Italy. Now, I was not there, but I did pass through Italy.

I used Hotel internet wifi with a code, but I didnt use any unsecured or open Wifi access points. In one cit I used their public wifi after verifying that it was actually public, city wifi that was the correct city offering.

UGH, very annoying. So far it seems limited to these two cases, and while I did use Facebook to post pictures, no idea why/how Amazon came into this.

Recommendations for steps to take for remediation, besides changing passwords on most everything? I run a mac, not windows, so if there is SW that I should use/run, keep that in mind.

Thanks!
 
I don't know but the one time I had my CC compromised, it involved Amazon. Same went for 2 other people in my extended family. I don't trust them.
 
Definitely change all your passwords. Let your credit card companies know - they have protections for things like this, and may even issue you a new card/number.

It's probably unnecessary to install anything on your computer - I don't know how this stuff happens, but they probably didn't actually get into your computer, they just got your account information.

Good luck!
 
Originally Posted By: cchase
I don't know but the one time I had my CC compromised, it involved Amazon. Same went for 2 other people in my extended family. I don't trust them.

I think the problem is that Amazon allows 1-click purchasing, by storing your CC information. Then anyone who gets your Amazon password can buy whatever they like without actually having your CC information.
 
Originally Posted By: NateDN10
Originally Posted By: cchase
I don't know but the one time I had my CC compromised, it involved Amazon. Same went for 2 other people in my extended family. I don't trust them.

I think the problem is that Amazon allows 1-click purchasing, by storing your CC information. Then anyone who gets your Amazon password can buy whatever they like without actually having your CC information.


The issue for me was that my computer did not have a virus and my password was not compromised. As a matter of fact, I use the same password to this day. Somehow whoever got my CC info got it from the back end of Amazons system, not the front end. The same went for at least 1 of my family members.
 
It's a bit odd. I never enter passwords at FB or amazon, they are stored.

The password admittedly was the same.

I logged into FB from wifi in Europe on my phone (but didn't physically type the pwd).
 
Originally Posted By: JHZR2
It's a bit odd. I never enter passwords at FB or amazon, they are stored.

The password admittedly was the same.

I logged into FB from wifi in Europe on my phone (but didn't physically type the pwd).

Does not matter if you type it in. If it is stored in browser, it is still transmitted over the Wi-Fi. Someone intercepted the signal.
 
Originally Posted By: Ursae_Majoris
Originally Posted By: JHZR2
It's a bit odd. I never enter passwords at FB or amazon, they are stored.

The password admittedly was the same.

I logged into FB from wifi in Europe on my phone (but didn't physically type the pwd).

Does not matter if you type it in. If it is stored in browser, it is still transmitted over the Wi-Fi. Someone intercepted the signal.


Yup, and in a lot of cases, even if the site uses SSL, the login page doesn't and your information is transmitted in clear-text.
 
Another thing when going to Facebook is make sure you use "HTTPS" rather than "HTTP". That offers more security.

If you use Wi-Fi and HTTP you are leaving yourself wide open as there are some simple ways to collect your information if you use HTTP for Facebook. Several other sites offer HTTPS security too.
 
Step 1 change your email password, Step 2 change your password on associated sites so the person doesn't have the ability to use the 'I forgot my password' steps which usually involve a verification email, and step 3 notify the CC company of fraud so they can credit your account and they'll tell amazon who will then void the gift card.
 
Originally Posted By: OVERK1LL
Originally Posted By: Ursae_Majoris
Originally Posted By: JHZR2
It's a bit odd. I never enter passwords at FB or amazon, they are stored.

The password admittedly was the same.

I logged into FB from wifi in Europe on my phone (but didn't physically type the pwd).

Does not matter if you type it in. If it is stored in browser, it is still transmitted over the Wi-Fi. Someone intercepted the signal.


Yup, and in a lot of cases, even if the site uses SSL, the login page doesn't and your information is transmitted in clear-text.


I was using the FB app, so no idea how that transmits...

Also used the mail app, But use SSL is checked to "on", fwiw.
 
Status
Not open for further replies.
Back
Top Bottom