In the first image with the telegram id the other id is for discord. I don't recall discord being e2e encrypted so that is an interesting choice to offer. Especially since discord is known to have access to all data since they regularly remove chats/servers that don't follow their tos.
773M Password ‘Megabreach’ Is Years Old
21–30 of 177 posts
Re: 773M Password ‘Megabreach’ Is Years Old
#22Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…
I've received the same emails, for livejournal accounts. They seem to reuse bitcoin addresses. Bitcoin blockchain explorers show that the addresses are recently created, and that people have sent them money.
I find it difficult to reconcile someone tech savey enough to use bitcoin falling for a scam of this nature.
On the otherhand, it might explain a lot about the crypto space!
Re: 773M Password ‘Megabreach’ Is Years Old
#23Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…
Re: 773M Password ‘Megabreach’ Is Years Old
#24So the seller shows a screenshot with browser tabs, a date and a time. One of the tabs is really very specific, looking at a particular disqus profile. I'm not familiar with Windows; is there anything in the screenshot to suggest its torbrowser or anything like that? Presumably the miscreant's ISP and e.g. the Russian government can guess real easy whom generated that screenshot...? Of course what they'd do with that…
The screenshot has a tab open on this article: https://www.troyhunt.com/the-773-million-record-collection-1... I don't think it's from the seller - looks like it was taken by the author of this article.
[0] https://krebsonsecurity.com/wp-content/uploads/2019/01/sanix...
Re: 773M Password ‘Megabreach’ Is Years Old
#25So the seller shows a screenshot with browser tabs, a date and a time. One of the tabs is really very specific, looking at a particular disqus profile. I'm not familiar with Windows; is there anything in the screenshot to suggest its torbrowser or anything like that? Presumably the miscreant's ISP and e.g. the Russian government can guess real easy whom generated that screenshot...? Of course what they'd do with that…
The screenshot has a tab open on this article: https://www.troyhunt.com/the-773-million-record-collection-1... I don't think it's from the seller - looks like it was taken by the author of this article.
Re: 773M Password ‘Megabreach’ Is Years Old
#26I can't remember if it was haveibeenpwned.com or some other site, but I seem to recall once a few years ago checking my email on a site which also showed you the first two characters of the password which had been compromised. Maybe it has since been discontinued because of security concerns, but I found it really useful at the time because it let me know that the leaked password was an old one that I hadn't used in…
The way I use to recognize which service has been compromised is using unique email addresses. Most providers let you do either a catchall address, or xyz+alias@provider.com, meaning you should have a user+hn@domain.com for your Hacker News user account. Makes both knowing which services has been hacked easy, but also who sells your contact information to spammers easy! :)
Edit: actually, using random passwords from a manager, you should be able to identify it through https://haveibeenpwned.com/Passwords
Re: 773M Password ‘Megabreach’ Is Years Old
#27Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…
What a damning position to be in, in 2019.
Re: 773M Password ‘Megabreach’ Is Years Old
#28Earlier quoted context omitted.
I've received the same emails, for livejournal accounts. They seem to reuse bitcoin addresses. Bitcoin blockchain explorers show that the addresses are recently created, and that people have sent them money.
> Bitcoin blockchain explorers show that the addresses are recently created, and that people have sent them money. I find it difficult to reconcile someone tech savey enough to use bitcoin falling for a scam of this nature. On the otherhand, it might explain a lot about the crypto space!
> You will make the payment by Bitcoin (if you do not know this, search 'how to buy bitcoin' in Google).
The top result is from coinbase [1]. I would say everyone capable of online banking is capable of following these steps.
Re: 773M Password ‘Megabreach’ Is Years Old
#29Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…
> recorded watching porn What a damning position to be in, in 2019.
Re: 773M Password ‘Megabreach’ Is Years Old
#30Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…