Live data from Hacker News

Ask HN: Has AWS Been Hacked?

news.ycombinator.com

1–10 of 23 posts

Ask HN: Has AWS Been Hacked?

#1
I just received the following email, to an email address that has only ever been used once, to register an AWS account in 2021.

---- On Thu, 19 May 2022 03:47:29 +1000 Carent Domingo wrote ----

    Hello,

    My name is Carent from TDS. We have a domain that is currently on sale that you might be interested in - TeamFortress.net
     
    Anytime someone types Team Fortress, Team Fortress Online, The Best Team Fortress, or any other phrase with these keywords into their browser, your site could be the first they see!

    The internet is the most efficient way to acquire new customers

    Avg Google Search Results for this domain is: 68,500,000
    You can easily redirect all the traffic this domain gets to your current site!

    GoDaddy.com appraises this domain at $1,345. 

    Priced at only $398 for a limited time! If interested please go to TeamFortress.net and select Buy Now, or purchase directly at GoDaddy.  
    Act Fast! First person to select Buy Now gets it!  

    Thank you very much for your time.
    Top Domain Sellers (TDS)
    Carent Domingo

Re: Ask HN: Has AWS Been Hacked?

#2
Are you certain you did not use the email anywhere else, including in WHOIS records for any domain?

Is the email predictable?

I use a dedicated email address for AWS and I have only ever received AWS correspondence to it.

Re: Ask HN: Has AWS Been Hacked?

#3
post #2

Are you certain you did not use the email anywhere else, including in WHOIS records for any domain? Is the email predictable? I use a dedicated email address for AWS and I have only ever received AWS correspondence to it.

Likely they issue. Might be worth taking the deal as I imagine Team Fortress is trademarked by Valve.

Re: Ask HN: Has AWS Been Hacked?

#4
post #2

Are you certain you did not use the email anywhere else, including in WHOIS records for any domain? Is the email predictable? I use a dedicated email address for AWS and I have only ever received AWS correspondence to it.

Likely they issue. Might be worth taking the deal as I imagine Team Fortress is trademarked by Valve.

https://trademarks.justia.com/755/42/team-75542473.html

Trademark filed 1998-08-25.

WHOIS reports this domain was registered 2021-06-01.

A risky purchase.

Re: Ask HN: Has AWS Been Hacked?

#5
post #2

Are you certain you did not use the email anywhere else, including in WHOIS records for any domain? Is the email predictable? I use a dedicated email address for AWS and I have only ever received AWS correspondence to it.

Yep the email address is of the format: name+serverlocationyear@domain.tld and has absolutely only ever been used for this one purpose.

Re: Ask HN: Has AWS Been Hacked?

#7
This is almost certainly leaking without you realizing it via a WHOIS contact email somewhere or another

Another possibilty is that overseas contractors for AWS regularly harvest email addresses from the support UI and spam them. Wouldn't surprise me, but the first is more likely. Wouldn't really call this a hack though either way.

Re: Ask HN: Has AWS Been Hacked?

#8
Considering you're a developer of a game called "team fortress" (based on your HN comment history) who had a domain for team fortress with WHOIS info updated in 2021, I'd say that its probably someone on your dev team trying to make a few bucks and knew the address. But maybe you registered this with Cloudflare and forgot, and Cloudflare is forwarding the email to you.

Re: Ask HN: Has AWS Been Hacked?

#9
post #7

This is almost certainly leaking without you realizing it via a WHOIS contact email somewhere or another Another possibilty is that overseas contractors for AWS regularly harvest email addresses from the support UI and spam them. Wouldn't surprise me, but the first is more likely. Wouldn't really call this a hack though either way.

> Another possibilty is that overseas contractors for AWS regularly harvest email addresses from the support UI and spam them.

If this was a practice that was possible and occurring then I suspect we'd have heard of many more cases by now. Most big companies don't use contractors for work that gives them access to customer data like that, and most don't just allow anyone easy access to raw customer data without a paper trail and reason.

Post reply on HN