Live data from Hacker News

Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

news.ycombinator.com

71–80 of 88 posts

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#71
post #61

Earlier quoted context omitted.

> Notice the "i", different from abcde@mydomain.com The username on the domain doesn't matter, only the domain itself.

> The username on the domain doesn't matter, only the domain itself. Of course it matters if it means that it wasn't actually sent from the domain in the first place and there were no "hacks" involved. You said "emails sent from your domain..." but you do know the "From" address in standard email is utterly meaningless from a security perspective right? You can just sendmail -f any.address@example.com any.target@exam…

Additionally, it could very well be that one of the letters in the domain name looks like but isn’t one of the normal English ascii characters. I’ve seen scans like this before — they are visually indistinguishable (or extremely close to, eg I’ve seen one that had a tiny dot above the character it was mimicking) from the real thing, but are a completely different Unicode character.

But if you don’t check the email headers, emails are easy to spoof, hell, I did it when I was a kid...

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#72
post #20

If I'm reading your story correctly, it matches up with a tactic my clients have been seeing more lately. The scammer has already accessed your account because you fell for a phishing scam, typed your email credentials into a fake login site for a fake Office 365 or Dropbox page or something. Now the scammers are watching your email closely waiting for the opportunity to do this. Waiting for you to send an invoice to…

> The scammer has already accessed your account because you fell for a phishing scam > It's not your fault that they paid the wrong person. How is this not the OP's fault? It's absolutely their fault - the fault that lead to their email being compromised

You don’t know t was the OP’s email that was compromised. It could have been the clients or something else entirely.

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#73
post #65
post #50

Earlier quoted context omitted.

> Banking standards here in the EU impose a 13 months period during which the sender (order sender) can ask for a full refund Is this really true? Do EU bank transactions really take 13 months to fully clear?

No, they don't take 13 months to clear. The idea is to protect the payer (the one losing money) from either their human error, or an unlawful debit. See https://www.europeanpaymentscouncil.eu/what-we-do/sepa-direc... .

Is that for “direct debit” only or all transactions?

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#74
post #58

Earlier quoted context omitted.

> Gonna need a source on that one, chief. The example I always use is when a college coach tells an athlete they've been accepted to a college before the admissions committee formerly approves them, and they actually get rejected. This happens dozens of times per year, and the reason you never see any lawsuits about it is that the colleges just let them in to avoid the bad publicity.

Hardly seems like the same thing -- the coach is a representative of the organization and communicated something (by whatever means) that they shouldn't have. The organization honored that commitment. If the athlete turned up waving a _spoofed_ email and they let them in then that would be a more appropriate example.

> If the athlete turned up waving a _spoofed_ email and they let them in then that would be a more appropriate example.

Fair, I was just making the point about the validity of email agreements in general.

But let's say Harvard let others send email that appeared to come from their domain (by not having SPF enabled) and some kid withdrew all their other college applications because one of their friends was playing a prank on them or whatever, almost certainly the college would either let them in or else settle and pay damages. No way in hell they would want that going to trial even if they thought they could win.

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#75
post #49

Earlier quoted context omitted.

Amusingly in a thread on email scams and such you didn't read quite closely enough (plus OP didn't do a great job of differentiating either, maybe on purpose) :). Even ignoring the "sent from your domain = contract" assertion: > Now on the next day my client received an email from "abicde@mydomain.com" stating that there is a change in invoice and revised invoice is again sent which had bank account details of a UK b…

> Notice the "i", different from abcde@mydomain.com The username on the domain doesn't matter, only the domain itself.

This is one of the most hilariously wrong things I've ever heard of. So if I send an invoice to billing@facebook.com and reply from (my account) uh_what@facebook.com agreeing to the terms, Facebook legally owes me the amount on the invoice?

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#76
post #75

Earlier quoted context omitted.

> Notice the "i", different from abcde@mydomain.com The username on the domain doesn't matter, only the domain itself.

This is one of the most hilariously wrong things I've ever heard of. So if I send an invoice to billing@facebook.com and reply from (my account) uh_what@facebook.com agreeing to the terms, Facebook legally owes me the amount on the invoice?

Clearly not. It's a general principle of law, not an ATM machine.

E.g. employers are on the hook for damages due to sexual harassment among their employees, but that doesn't mean you can sexually harass yourself and then automatically collect free money.

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#77
post #19

Your email did not get hacked most likely. Your client got tricked. They spoofed an email with your domain, but the reply-to email was their own (the attacker). So the client thinks they responded to you, but they responded to the fake address. Also, generally when they do this, they spoof the body and the conversation of the email. Most likely, your client's emails were compromised in this case. Ask them to forward…

I agree. A few (10? 20?) years ago it was very easy to spoof email and send an email "from" mickey@disney.com if you wish. The original email specification has almost no security features. Now, most of the email servers will sign the outgoing email, and if you receive an email with the signature gmail and others big webmail providers will show a big warning. So, to understand the problem it is very important to get a…

[deleted]

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#78
post #58

Earlier quoted context omitted.

Hardly seems like the same thing -- the coach is a representative of the organization and communicated something (by whatever means) that they shouldn't have. The organization honored that commitment. If the athlete turned up waving a _spoofed_ email and they let them in then that would be a more appropriate example.

> If the athlete turned up waving a _spoofed_ email and they let them in then that would be a more appropriate example. Fair, I was just making the point about the validity of email agreements in general. But let's say Harvard let others send email that appeared to come from their domain (by not having SPF enabled) and some kid withdrew all their other college applications because one of their friends was playing a p…

I think you’re greatly mistaken in your assumptions. Harvard would suffer much greater damage to their reputation if they honored a fake acceptance email. To my knowledge, no university has ever honored a fake (physical) acceptance letter either, and those have existed (as pranks or otherwise) for a while.

It’s highly unlikely that such a case would even get to trial without being dismissed. For example, see this Quora thread [1] about the case of the university itself sending out the actual acceptance letter. Columbia University also had an incident where a system error accidentally sent out acceptance emails, which they quickly retracted, and no lawsuit or settlement came out of that.

I think it would be incredibly difficult to prove damages in such a case, especially since a fake acceptance letter doesn’t prevent you from going to another college. Your example of the student withdrawing their other applications is also unlikely to be blamed on Harvard, particularly before the student has officially accepted (at which point Harvard would notice they didn’t accept the student).

[1] https://www.quora.com/Can-a-university-be-sued-if-it-first-s...

Re: Ask HN: Lost $10k as my email was hacked. Any ways to recover it?

#79
you or your client using Google’s Gsuite as email service provider?

cause the same thing happened to one of client in Chennai, India.

but they client didnt tranfer the funds since he found that the bank account the fake guy sent was new to them. so the client called orginal company back and reported it.

Post reply on HN