Live data from Hacker News

The unattributable “db8151dd” data breach

troyhunt.com

11–20 of 155 posts

Re: The unattributable “db8151dd” data breach

#11
post #2

For the people that use unique per-merchant e-mail addresses (like someone+amazon@...), could you try some of those aliases on HaveIBeenPwned and see which ones come up in this breach? That might shed some light onto its origin.

BTW, since many people don't seem to be aware of this: If you have your own domain, you can get informed by haveibeenpwned automatically if any mail address from that domain is in a breach. All that is required is that you're reachable on that domain through an address like 'postmaster'. This feature can be found under 'domain search'. Since I use a new address for pretty much anything this is very handy.

Re: The unattributable “db8151dd” data breach

#12
post #4

Is this dump online anywhere? I got the notification from HIBP but it only tells me my email address appeared and I'm curious how accurate the rest of the data is.

> Back in Feb, Dehashed reached out to me with a massive trove of data

I guess searching on https://www.dehashed.com/ should give you some additional data.

Re: The unattributable “db8151dd” data breach

#14
post #12
post #4

Is this dump online anywhere? I got the notification from HIBP but it only tells me my email address appeared and I'm curious how accurate the rest of the data is.

> Back in Feb, Dehashed reached out to me with a massive trove of data I guess searching on https://www.dehashed.com/ should give you some additional data.

Surprisingly enough searching my pwned address in this breach doesn't bring it up on Dehashed.

Re: The unattributable “db8151dd” data breach

#15
> Recommended by Andie [redacted last name]. Arranged for carpenter apprentice Devon [redacted last name] to replace bathroom vanity top at [redacted street address], Vancouver, on 02 October 2007.

Given that, surely Troy can contact those people and ask "who knew this info?". Not many people would know who replaced my bathroom vanity top...

Re: The unattributable “db8151dd” data breach

#16
post #9
post #8

Earlier quoted context omitted.

I use unique emails. My record in this breach is just a generic "contact@" address.

Could it be from whois data? Seems like a reasonable place for which to submit such a generic address.

Or could be the spammers sanitized them.

Re: The unattributable “db8151dd” data breach

#17

> Recommended by Andie [redacted last name]. Arranged for carpenter apprentice Devon [redacted last name] to replace bathroom vanity top at [redacted street address], Vancouver, on 02 October 2007. Given that, surely Troy can contact those people and ask "who knew this info?". Not many people would know who replaced my bathroom vanity top...

Sure but perhaps Devon used a SAAS CRM system whose servers were breached... Or maybe Andie posted on Devon's public Facebook page to organise the job. Maybe it's just the LinkedIn leaks resurfacing, etc, etc.

Re: The unattributable “db8151dd” data breach

#18
post #2

For the people that use unique per-merchant e-mail addresses (like someone+amazon@...), could you try some of those aliases on HaveIBeenPwned and see which ones come up in this breach? That might shed some light onto its origin.

HaveIBeenPwned now has feature set to find e-mail addresses which were breached under a domain, there is normally no need to search for separate aliases if you own the e-mail domain.

https://haveibeenpwned.com/DomainSearch

Re: The unattributable “db8151dd” data breach

#19
post #12

Earlier quoted context omitted.

> Back in Feb, Dehashed reached out to me with a massive trove of data I guess searching on https://www.dehashed.com/ should give you some additional data.

Surprisingly enough searching my pwned address in this breach doesn't bring it up on Dehashed.

The Dehashed indexer is extremely slow, according to their FAQ. Mine hasn’t showed up there yet either, but I was informed by HIBP. Could still be indexing I suppose.

Re: The unattributable “db8151dd” data breach

#20
post #7

Earlier quoted context omitted.

That was my first though, I also use "company@mydomain" sometimes. Too many to go through... if only I could get hold of my record....

I believe HIBP offers domain admins a way to get all their pwned users after domain verification.

Instructions are on this page: https://haveibeenpwned.com/DomainSearch
Post reply on HN