Earlier quoted context omitted.
To do something similar as an individual, I highly recommend 33mail.com [1], which provides a generous free tier, and lets you supply arbitrary . As well as knowing where a leak originated, you can easily block any inbound email address if it is being abused. Not affiliated, just a happy long-time paying customer. [1] http://33mail.com/rj37w3
I do the same without using 33mail. I have my mail hosted on zoho mail which gives me infinite aliases that get redirected to my main address and in case I ever need to forward a mail from an alias I can create a new address with that alias, use it and then delete it. So when I register to a new site I usually input @mydomain.com and then if I want I can create a filter to sort them automatically
DocuSign email address database breached and used for phishing campaign
101–110 of 141 posts
Re: DocuSign email address database breached and used for phishing campaign
#102Earlier quoted context omitted.
I do the same without using 33mail. I have my mail hosted on zoho mail which gives me infinite aliases that get redirected to my main address and in case I ever need to forward a mail from an alias I can create a new address with that alias, use it and then delete it. So when I register to a new site I usually input @mydomain.com and then if I want I can create a filter to sort them automatically
me too. any new email address is businessname@mydomain.io Already caught a few selling my info
Re: DocuSign email address database breached and used for phishing campaign
#103This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…
Looks cool though, I subscribed to the list.
Re: DocuSign email address database breached and used for phishing campaign
#104Earlier quoted context omitted.
Someone asked me to pay a bill using docusign and entering my credit card information into one of those free text boxes They couldn't understand why I refused to do it.
Apparently it's as safe as entering credit card details into another online merchants form who is PCI compliant. https://support.docusign.com/en/answers/00004343
Re: DocuSign email address database breached and used for phishing campaign
#105This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…
I presume canary is an established term in this context but since I don't know what it is I don't understand your service. It sounds good though.
Re: DocuSign email address database breached and used for phishing campaign
#106Earlier quoted context omitted.
A catchall on my domain was all fun and games till the second dictionary spam run.
The way I get around that is by having a static keyword that must also appear on the user side of the email address. So, if I'm dealing with Walmart, I would give them: [keyword].walmart@example.com or walmart.[keyword]@example.com Then I configure my catch-all settings to reject any email addresses that don't have that keyword. Of course, the keyword is not secret, so it's possible for someone to infer what I'm doin…
(fwiw, this domain is almost 20 years old, so that's forever in internet years)
Re: DocuSign email address database breached and used for phishing campaign
#107I would like to urge the Google team to solve one aspect of this problem, forever. It takes no more than 20 minutes to prototype and then approximately 1 day to fully test the final solution that is necessary on their end to keep compromised emails from being fully compromised addresses forever, without any chance for you to ever know at any point in the future where mail REALLY comes from. Here is a description: 1 -…
> The full and complete solution is to allow me to create a new inbox in Gmail through a single step, for example "j45rsdfjdocusign" which is linked to jsmith747 in a single direction. When hosting your own email on your own domain you get this benefit out of the box now, without waiting for google to add it for you. I've been doing this for years, each different company gets a unique email address. Real easy to see…
Re: DocuSign email address database breached and used for phishing campaign
#108This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…
The second Get early access box says 'Entry your e-mail address' instead of 'Enter'. Looks cool though, I subscribed to the list.
Edit: fixed
Re: DocuSign email address database breached and used for phishing campaign
#109Earlier quoted context omitted.
I presume canary is an established term in this context but since I don't know what it is I don't understand your service. It sounds good though.
Apologies, you're right, it's not really covered as it's a bit of a niche industry term. It relates back to the days of coal mines, and the birds being used as an early warning system - https://en.m.wiktionary.org/wiki/canary_in_a_coal_mine
Re: DocuSign email address database breached and used for phishing campaign
#110This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…