Live data from Hacker News

Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

news.ycombinator.com

51–60 of 88 posts

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#51
post #6

This is very common issue; I've personally helped a company after they lost much more than this, and had to help prove to insurance/govt agencies/etc. Turn on DKIM, DMARC, and SPF records for your mail domain. Also, never send invoices over email that contain any payment terms (eg: accounts, addresses to mail check to, etc) they should always be in some sort of protected portal. Tell every customer never to accept pa…

Not sure if a portal is any better. Can't an email point to a fake portal?

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#52
post #47

Earlier quoted context omitted.

> my client received an email from "abicde@mydomain.com" stating that there is a change in invoice and revised invoice is again sent which had bank account details of a UK bank account. Emails sent from your domain usually constitute valid contracts. If you're letting other people send emails from your domain because you don't have SPF configured then there's a good chance a court would either rule that you've allowe…

That’s highly doubtful. I think it would maybe be arguable if someone actually hacked the OP’s account and the emails really did come from their outbox, but spoofed email is a different thing entirely. It seems more equivalent as a legal precedent to someone sending a forged letter from a nonexistent employee on similar looking letterhead. Or maybe someone showing up at the door and collecting payment wearing a stole…

> It seems more equivalent as a legal precedent to someone sending a forged letter from a nonexistent employee on similar looking letterhead.

Well that's the question I guess, if you don't have SPF enabled is it like what you said, or is it more like allowing random people to come into your office at night and send out whatever they want on your actual company letterhead?

I don't know if there is legal precedent there or what a judge would rule, but it doesn't strike me as being completely obvious that this is a simple cut-and-dried case where the client still owes the full amount of the original payment.

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#53

Earlier quoted context omitted.

I stated in the next paragraph that the situation could just as easily be reversed. We do not have any way to know in this situation whose mailbox was accessed, the OP, or their client.

If OP's mail was hacked, the attacker wouldn't have needed to use a confusingly-similar email address ("abicde@mydomain.com" instead of "abcde@mydomain.com"). They could have used OP's actual address.

Good theory but not necessarily true. The attacker might still wish to use a spoofed domain to ensure that they get delivery of all replies.

In cases where Gmail and Office 365 accounts get hacked like this, the attacker will enable email forwarding to an address they can monitor for replies, and delete replies from the clients so that the compromised person does not see them. I am not sure if you can do this easily with a godaddy mailbox.

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#54
post #14

I'm surprised I'm the first person to point this out, but you have not lost any money, your client has. You sent the goods to the client, and they have yet to remit the payment to you. So they still owe you the money and you should insist they pay it. Granted, they're not going to like that, but the reality is they sent payment due to you to some other person. That's something they did not something you did. They may…

I strongly disagree with you. The person who sent that money will want to get their money back and you are in the middle. At the very least I would want to stop doing business with someone who communicates bank information in such a careless manner. It's possible these are such tiny companies that they do things like that. In any case, I'd blame the other person whom I thought I was sending money to.

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#55
post #49

Earlier quoted context omitted.

> my client received an email from "abicde@mydomain.com" stating that there is a change in invoice and revised invoice is again sent which had bank account details of a UK bank account. Emails sent from your domain usually constitute valid contracts. If you're letting other people send emails from your domain because you don't have SPF configured then there's a good chance a court would either rule that you've allowe…

Amusingly in a thread on email scams and such you didn't read quite closely enough (plus OP didn't do a great job of differentiating either, maybe on purpose) :). Even ignoring the "sent from your domain = contract" assertion: > Now on the next day my client received an email from "abicde@mydomain.com" stating that there is a change in invoice and revised invoice is again sent which had bank account details of a UK b…

> Notice the "i", different from abcde@mydomain.com

The username on the domain doesn't matter, only the domain itself.

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#56
post #14

I'm surprised I'm the first person to point this out, but you have not lost any money, your client has. You sent the goods to the client, and they have yet to remit the payment to you. So they still owe you the money and you should insist they pay it. Granted, they're not going to like that, but the reality is they sent payment due to you to some other person. That's something they did not something you did. They may…

> my client received an email from "abicde@mydomain.com" stating that there is a change in invoice and revised invoice is again sent which had bank account details of a UK bank account. Emails sent from your domain usually constitute valid contracts. If you're letting other people send emails from your domain because you don't have SPF configured then there's a good chance a court would either rule that you've allowe…

SPFs are not a legal enforcement and a court cannot penalize an entity for not having an SPF.

It is sort of like saying "because you are not sending encrypted emails, you are purposefully and negligently jeopardizing your privacy and information security."

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#57

Earlier quoted context omitted.

> my client received an email from "abicde@mydomain.com" stating that there is a change in invoice and revised invoice is again sent which had bank account details of a UK bank account. Emails sent from your domain usually constitute valid contracts. If you're letting other people send emails from your domain because you don't have SPF configured then there's a good chance a court would either rule that you've allowe…

> Emails sent from your domain usually constitute valid contracts Gonna need a source on that one, chief.

> Gonna need a source on that one, chief.

The example I always use is when a college coach tells an athlete they've been accepted to a college before the admissions committee formerly approves them, and they actually get rejected. This happens dozens of times per year, and the reason you never see any lawsuits about it is that the colleges just let them in to avoid the bad publicity.

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#58

Earlier quoted context omitted.

> Emails sent from your domain usually constitute valid contracts Gonna need a source on that one, chief.

> Gonna need a source on that one, chief. The example I always use is when a college coach tells an athlete they've been accepted to a college before the admissions committee formerly approves them, and they actually get rejected. This happens dozens of times per year, and the reason you never see any lawsuits about it is that the colleges just let them in to avoid the bad publicity.

Hardly seems like the same thing -- the coach is a representative of the organization and communicated something (by whatever means) that they shouldn't have. The organization honored that commitment.

If the athlete turned up waving a _spoofed_ email and they let them in then that would be a more appropriate example.

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#59

Earlier quoted context omitted.

> my client received an email from "abicde@mydomain.com" stating that there is a change in invoice and revised invoice is again sent which had bank account details of a UK bank account. Emails sent from your domain usually constitute valid contracts. If you're letting other people send emails from your domain because you don't have SPF configured then there's a good chance a court would either rule that you've allowe…

SPFs are not a legal enforcement and a court cannot penalize an entity for not having an SPF. It is sort of like saying "because you are not sending encrypted emails, you are purposefully and negligently jeopardizing your privacy and information security."

> It is sort of like saying "because you are not sending encrypted emails, you are purposefully and negligently jeopardizing your privacy and information security."

Of course a court can say that. The phrase used to describe email is literally like a postcard. If you sent out HIPAA or FERPA protected information on a postcard, would you really expect not to pay a huge fine or go to prison?

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#60
post #47

Earlier quoted context omitted.

That’s highly doubtful. I think it would maybe be arguable if someone actually hacked the OP’s account and the emails really did come from their outbox, but spoofed email is a different thing entirely. It seems more equivalent as a legal precedent to someone sending a forged letter from a nonexistent employee on similar looking letterhead. Or maybe someone showing up at the door and collecting payment wearing a stole…

> It seems more equivalent as a legal precedent to someone sending a forged letter from a nonexistent employee on similar looking letterhead. Well that's the question I guess, if you don't have SPF enabled is it like what you said, or is it more like allowing random people to come into your office at night and send out whatever they want on your actual company letterhead? I don't know if there is legal precedent ther…

It’s not like having someone come into your office at night if it’s a spoofed email. It’s just someone figuring out what your letterhead looks like.

Either way though the client owes the original payment. That’s not in dispute. Legal issues don’t work in some holistic “who do you think should have the money” way, there are specific causes of action.

The first thing a court would ask is does the client owe the money, and is the obligation satisfied. The first answer is yes the second one is no, the client never sent the supplier the money. Nobody claims they did. Period.

Then the client would have a cause of action for negligence, due to someone else spoofing their email. Who wins that one? I don’t know but you’d have to look for some precedent and claim that the supplier was actually the proximate cause for some third party defrauding you. Maybe but it’s a pretty tenuous argument and you’d have to demonstrate clear causality.

Post reply on HN