Earlier quoted context omitted.
As a general rule, if you receive an email referencing wire transfers, it's probably bogus.
Given the ratio of spam to ham, as a general rule every email is probably bogus.
DocuSign email address database breached and used for phishing campaign
91–100 of 141 posts
Re: DocuSign email address database breached and used for phishing campaign
#92I would like to urge the Google team to solve one aspect of this problem, forever. It takes no more than 20 minutes to prototype and then approximately 1 day to fully test the final solution that is necessary on their end to keep compromised emails from being fully compromised addresses forever, without any chance for you to ever know at any point in the future where mail REALLY comes from. Here is a description: 1 -…
> The full and complete solution is to allow me to create a new inbox in Gmail through a single step, for example "j45rsdfjdocusign" which is linked to jsmith747 in a single direction. When hosting your own email on your own domain you get this benefit out of the box now, without waiting for google to add it for you. I've been doing this for years, each different company gets a unique email address. Real easy to see…
[1] https://www.quora.com/How-many-software-engineers-does-Googl...
Re: DocuSign email address database breached and used for phishing campaign
#93I would like to urge the Google team to solve one aspect of this problem, forever. It takes no more than 20 minutes to prototype and then approximately 1 day to fully test the final solution that is necessary on their end to keep compromised emails from being fully compromised addresses forever, without any chance for you to ever know at any point in the future where mail REALLY comes from. Here is a description: 1 -…
> The full and complete solution is to allow me to create a new inbox in Gmail through a single step, for example "j45rsdfjdocusign" which is linked to jsmith747 in a single direction. When hosting your own email on your own domain you get this benefit out of the box now, without waiting for google to add it for you. I've been doing this for years, each different company gets a unique email address. Real easy to see…
Re: DocuSign email address database breached and used for phishing campaign
#94I'm not sure DocuSign has a full handle on what happened here yet. I received six (6) DocuSign emails, half of which used a convincing subject derived from actual DocuSign documents I have signed or processed through the system. Perhaps a coincidence? Or these hackers gained access to more than just "email addresses".
Re: DocuSign email address database breached and used for phishing campaign
#95Is there a chance I could've been compromised in any way? I'm guessing they couldn't have gotten much more than my IP address, maybe some cookies, all my passwords, private life?
Re: DocuSign email address database breached and used for phishing campaign
#96Earlier quoted context omitted.
With credit cards, you personally do not have much to worry about, since your card issuer holds the ultimate liability for any fraud that occurs. Just be careful to use a credit card (attached to a reversible ledger) and not a debit card (attached to a less-reversible cash account).
This is not an accurate description of the difference between credit cards and offline debit cards with regard to disputed transactions. In both cases, fraud disputes are handled in the same way. Either the issuer or the account holder suspects fraudulent transactions and the bank engages an investigation in order to determine veracity of the claim. Where things differ is that the onus of proof for credit card accoun…
Your note about "onus on proof lies with the cardholder" is less true for Visa, for example.
The best resource I've seen is this one: https://www.minneapolisfed.org/~/media/files/about/what-we-d... See pages 6 through 18.
Re: DocuSign email address database breached and used for phishing campaign
#97The phishing emails had the color scheme changed, making them very phony and easy to classify.
Re: DocuSign email address database breached and used for phishing campaign
#98Earlier quoted context omitted.
I do the same without using 33mail. I have my mail hosted on zoho mail which gives me infinite aliases that get redirected to my main address and in case I ever need to forward a mail from an alias I can create a new address with that alias, use it and then delete it. So when I register to a new site I usually input @mydomain.com and then if I want I can create a filter to sort them automatically
me too. any new email address is businessname@mydomain.io Already caught a few selling my info
Re: DocuSign email address database breached and used for phishing campaign
#99> Ensure your anti-virus software is enabled and up to date Uh, really, endorsing antivirus? They could at least have written something like "Ensure your system is properly secured" if they felt they need to stress that out.
Re: DocuSign email address database breached and used for phishing campaign
#100Earlier quoted context omitted.
AliExpress does this, they don't accept "aliexpress@foo.bar". I suppose it's meant to stop you from providing "foo@aliexpress.com", implemented lazily by rejecting anything that contains the substring "aliexpress". Best response I've received when giving an email address of the form "company@mydoma.in" to a representative in person was "oh you work here too?". The concept of catch-all domains is so foreign to most la…
A catchall on my domain was all fun and games till the second dictionary spam run.
So, if I'm dealing with Walmart, I would give them:
[keyword].walmart@example.com
or
walmart.[keyword]@example.com
Then I configure my catch-all settings to reject any email addresses that don't have that keyword.
Of course, the keyword is not secret, so it's possible for someone to infer what I'm doing and construct an email address that passes my spam check, but in practice, nobody goes through the trouble, because I'm not a big enough target.