Live data from Hacker News

DocuSign email address database breached and used for phishing campaign

trust.docusign.com

101–110 of 141 posts

Re: DocuSign email address database breached and used for phishing campaign

#101
post #73

Earlier quoted context omitted.

To do something similar as an individual, I highly recommend 33mail.com [1], which provides a generous free tier, and lets you supply arbitrary . As well as knowing where a leak originated, you can easily block any inbound email address if it is being abused. Not affiliated, just a happy long-time paying customer. [1] http://33mail.com/rj37w3

I do the same without using 33mail. I have my mail hosted on zoho mail which gives me infinite aliases that get redirected to my main address and in case I ever need to forward a mail from an alias I can create a new address with that alias, use it and then delete it. So when I register to a new site I usually input @mydomain.com and then if I want I can create a filter to sort them automatically

If you set up a catch-all for your domain, then you don't even need to create addresses unless you need to reply from that address.

Re: DocuSign email address database breached and used for phishing campaign

#102

Earlier quoted context omitted.

I do the same without using 33mail. I have my mail hosted on zoho mail which gives me infinite aliases that get redirected to my main address and in case I ever need to forward a mail from an alias I can create a new address with that alias, use it and then delete it. So when I register to a new site I usually input @mydomain.com and then if I want I can create a filter to sort them automatically

me too. any new email address is businessname@mydomain.io Already caught a few selling my info

What do you do after you catch them? Is there any place to report them, maybe depending on which country they are based, or you simply stop doing business with them?

Re: DocuSign email address database breached and used for phishing campaign

#103

This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…

The second Get early access box says 'Entry your e-mail address' instead of 'Enter'.

Looks cool though, I subscribed to the list.

Re: DocuSign email address database breached and used for phishing campaign

#104
post #8

Earlier quoted context omitted.

Someone asked me to pay a bill using docusign and entering my credit card information into one of those free text boxes They couldn't understand why I refused to do it.

Apparently it's as safe as entering credit card details into another online merchants form who is PCI compliant. https://support.docusign.com/en/answers/00004343

It doesn't really spell out, though, how they differentiate CC info and avoid storing it with the rest of the data in the pdf form. There's just some hand wavy language about "Bank-grade Security". I suspect this means they store the CC data, which would be significantly different from how must online merchants operate.

Re: DocuSign email address database breached and used for phishing campaign

#105
post #50

This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…

I presume canary is an established term in this context but since I don't know what it is I don't understand your service. It sounds good though.

See here: https://en.m.wikipedia.org/wiki/Canary_trap

Re: DocuSign email address database breached and used for phishing campaign

#106
post #100

Earlier quoted context omitted.

A catchall on my domain was all fun and games till the second dictionary spam run.

The way I get around that is by having a static keyword that must also appear on the user side of the email address. So, if I'm dealing with Walmart, I would give them: [keyword].walmart@example.com or walmart.[keyword]@example.com Then I configure my catch-all settings to reject any email addresses that don't have that keyword. Of course, the keyword is not secret, so it's possible for someone to infer what I'm doin…

Yeah, I wound up using name-tag@domain, but because I used a dash rather than plus, I'm forever doomed to run my own mailserver.

(fwiw, this domain is almost 20 years old, so that's forever in internet years)

Re: DocuSign email address database breached and used for phishing campaign

#107
post #78

I would like to urge the Google team to solve one aspect of this problem, forever. It takes no more than 20 minutes to prototype and then approximately 1 day to fully test the final solution that is necessary on their end to keep compromised emails from being fully compromised addresses forever, without any chance for you to ever know at any point in the future where mail REALLY comes from. Here is a description: 1 -…

> The full and complete solution is to allow me to create a new inbox in Gmail through a single step, for example "j45rsdfjdocusign" which is linked to jsmith747 in a single direction. When hosting your own email on your own domain you get this benefit out of the box now, without waiting for google to add it for you. I've been doing this for years, each different company gets a unique email address. Real easy to see…

You also get the same benefit of catch-all support if you pay Google $5/month for your own domain on Gsuite.

Re: DocuSign email address database breached and used for phishing campaign

#108

This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…

The second Get early access box says 'Entry your e-mail address' instead of 'Enter'. Looks cool though, I subscribed to the list.

Thank you, I'll fix that now :) Serves me right for rushing out a landing page, after reading all the "you should start marketing yesterday" comments on startups!

Edit: fixed

Re: DocuSign email address database breached and used for phishing campaign

#109
post #50

Earlier quoted context omitted.

I presume canary is an established term in this context but since I don't know what it is I don't understand your service. It sounds good though.

Apologies, you're right, it's not really covered as it's a bit of a niche industry term. It relates back to the days of coal mines, and the birds being used as an early warning system - https://en.m.wiktionary.org/wiki/canary_in_a_coal_mine

I wouldn't call it a niche term, maybe in the context of calling something a canary, but the term canary in a coal mine is a common idiomatic expression in American English, at least in the mid-west.

Re: DocuSign email address database breached and used for phishing campaign

#110

This is the exact reason I started building Breach Canary[0], so that businesses can be alerted as soon as their user data is used in a way they wouldn't expect it to be. We produce authentic users with real working email addresses and phone numbers, so that as soon as they are contacted, you know someone has a copy of your userbase and is using it for reason x. We have already started seeing a tonne of DocuSign phis…

Sounds like "Have I Been Pwned?"[0] which I have been using to identify which addresses were hacked/sold. Together with a unique email address per site registration, which all get captured by a catch-all on my domains, I have some information on which addresses are compromised.

[0]https://haveibeenpwned.com

Post reply on HN