Hi everyone! πŸ‘‹ Someone I know recently got an email informing them that their account had been hacked. The subject of the email had their password and the email went like this:

π™Έπš πšœπšŽπšŽπš–πšœ πšπš‘πšŠπš, xxxxxxxx, πš’πšœ πš’πš˜πšžπš› πš™πšŠπšœπšœπš πš˜πš›πš.

𝙸 πš›πšŽπššπšžπš’πš›πšŽ πš’πš˜πšžπš› πšŒπš˜πš–πš™πš•πšŽπšπšŽ πšŠπšπšπšŽπš—πšπš’πš˜πš— πšπš˜πš› πšπš‘πšŽ πšπš‘πšŽ πš—πšŽπš‘πš 𝟸𝟺 πš‘πš˜πšžπš›πšœ, πš˜πš› 𝙸 πš πš’πš•πš• πšŒπšŽπš›πšπšŠπš’πš—πš•πš’ πš–πšŠπš”πšŽ πšœπšžπš›πšŽ 𝚒𝚘𝚞 πšπš‘πšŠπš 𝚒𝚘𝚞 πš•πš’πšŸπšŽ 𝚘𝚞𝚝 𝚘𝚏 πšŽπš–πš‹πšŠπš›πš›πšŠπšœπšœπš–πšŽπš—πš πšπš˜πš› πšπš‘πšŽ πš›πšŽπšœπš 𝚘𝚏 πš’πš˜πšžπš› πš•πš’πšπšŽ.

π™·πšŽπš•πš•πš˜, 𝚒𝚘𝚞 𝚍𝚘 πš—πš˜πš πš”πš—πš˜πš  πš–πšŽ πš™πšŽπš›πšœπš˜πš—πšŠπš•πš•πš’. π™±πšžπš 𝙸 πš”πš—πš˜πš  πšŽπšŸπšŽπš›πš’πšπš‘πš’πš—πš πšŒπš˜πš—πšŒπšŽπš›πš—πš’πš—πš 𝚒𝚘𝚞. πšˆπš˜πšžπš› πšŽπš—πšπš’πš›πšŽ πšπš‹ πšŒπš˜πš—πšπšŠπšŒπš πš•πš’πšœπš, πšœπš–πšŠπš›πšπš™πš‘πš˜πš—πšŽ πšŒπš˜πš—πšπšŠπšŒπšπšœ πšŠπš•πš˜πš—πš πš πš’πšπš‘ πšŠπš•πš• πšπš‘πšŽ πšŸπš’πš›πšπšžπšŠπš• πšŠπšŒπšπš’πšŸπš’πšπš’ πš’πš— πš’πš˜πšžπš› πšŒπš˜πš–πš™πšžπšπšŽπš› πšπš›πš˜πš– πš™πš›πšŽπšŸπš’πš˜πšžπšœ 𝟷𝟽𝟼 𝚍𝚊𝚒𝚜.

π™Έπš—πšŒπš•πšžπšπš’πš—πš, πš’πš˜πšžπš› πšœπšŽπš•πš πš™πš•πšŽπšŠπšœπšžπš›πšŽ πšŸπš’πšπšŽπš˜, πš πš‘πš’πšŒπš‘ πš‹πš›πš’πš—πšπšœ πš–πšŽ 𝚝𝚘 πšπš‘πšŽ πš™πš›πš’πš–πšŠπš›πš’ πš–πš˜πšπš’πšŸπšŽ πš πš‘πš’ 𝙸 ‘πš– πšŒπš˜πš–πš™πš˜πšœπš’πš—πš πšπš‘πš’πšœ πšœπš™πšŽπšŒπš’πšπš’πšŒ πšŽπš–πšŠπš’πš• 𝚝𝚘 𝚒𝚘𝚞.

πš†πšŽπš•πš• πšπš‘πšŽ πš™πš›πšŽπšŸπš’πš˜πšžπšœ πšπš’πš–πšŽ 𝚒𝚘𝚞 πš πšŽπš—πš 𝚝𝚘 πšπš‘πšŽ πš™πš˜πš›πš— πš–πšŠπšπšŽπš›πš’πšŠπš• πš πšŽπš‹πšœπš’πšπšŽπšœ, πš–πš’ πšœπš™πš’πš πšŠπš›πšŽ 𝚠𝚊𝚜 πšπš›πš’πšπšπšŽπš›πšŽπš πš’πš—πšœπš’πšπšŽ πš’πš˜πšžπš› πšŒπš˜πš–πš™πšžπšπšŽπš› πšœπš’πšœπšπšŽπš– πš πš‘πš’πšŒπš‘ πšŽπš—πšπšŽπš πšžπš™ πš›πšŽπšŒπš˜πš›πšπš’πš—πš 𝚊 𝚎𝚒𝚎-πšŒπšŠπšπšŒπš‘πš’πš—πš πšŸπš’πšπšŽπš˜ 𝚏𝚘𝚘𝚝𝚊𝚐𝚎 𝚘𝚏 πš’πš˜πšžπš› πšœπšŽπš•πš πš™πš•πšŽπšŠπšœπšžπš›πšŽ πš™πš•πšŠπš’ πš‹πš’ πšŠπšŒπšπš’πšŸπšŠπšπš’πš—πš πš’πš˜πšžπš› πš πšŽπš‹ πšŒπšŠπš–. (𝚒𝚘𝚞 𝚐𝚘𝚝 𝚊 πš’πš—πšŒπš›πšŽπšπš’πš‹πš•πš’ πšœπšπš›πšŠπš—πšπšŽ 𝚝𝚊𝚜𝚝𝚎 πš‹πš’ πšπš‘πšŽ 𝚠𝚊𝚒 πš•πš–πšŠπš˜)

𝙸 πš˜πš πš— πšπš‘πšŽ πšŽπš—πšπš’πš›πšŽ πš›πšŽπšŒπš˜πš›πšπš’πš—πš. π™Έπš, πš™πšŽπš›πš‘πšŠπš™πšœ 𝚒𝚘𝚞 πšπš‘πš’πš—πš” 𝙸 πšŠπš– πšπš˜πš˜πš•πš’πš—πš πšŠπš›πš˜πšžπš—πš, πš“πšžπšœπš πš›πšŽπš™πš•πš’ πš™πš›πš˜πš˜πš πšŠπš—πš 𝙸 πš πš’πš•πš• πš‹πšŽ πšπš˜πš›πš πšŠπš›πšπš’πš—πš πšπš‘πšŽ πš›πšŽπšŒπš˜πš›πšπš’πš—πš πš›πšŠπš—πšπš˜πš–πš•πš’ 𝚝𝚘 𝟷𝟸 πš™πšŽπš˜πš™πš•πšŽ 𝚒𝚘𝚞’πš›πšŽ πšπš›πš’πšŽπš—πšπšœ πš πš’πšπš‘.

π™Έπš πš–πšŠπš’ πš‹πšŽ πš’πš˜πšžπš› πšπš›πš’πšŽπš—πš, 𝚌𝚘 πš πš˜πš›πš”πšŽπš›πšœ, πš‹πš˜πšœπšœ, πš™πšŠπš›πšŽπš—πšπšœ (𝙸’πš– πš—πš˜πš πšœπšžπš›πšŽ! π™Όπš’ πšœπš˜πšπšπš πšŠπš›πšŽ πš πš’πš•πš• πš›πšŠπš—πšπš˜πš–πš•πš’ πšœπšŽπš•πšŽπšŒπš πšπš‘πšŽ πšŒπš˜πš—πšπšŠπšŒπšπšœ).

πš†πš’πš•πš• 𝚒𝚘𝚞 πš‹πšŽ πšŒπšŠπš™πšŠπš‹πš•πšŽ 𝚝𝚘 πš•πš˜πš˜πš” πš’πš—πšπš˜ πšŠπš—πš’πš˜πš—πšŽ’𝚜 𝚎𝚒𝚎𝚜 πšŠπšπšŠπš’πš— πšŠπšπšπšŽπš› πš’πš? 𝙸 πššπšžπšŽπšœπšπš’πš˜πš— πšπš‘πšŠπš…

π™±πšžπš, πš’πš 𝚍𝚘𝚎𝚜 πš—πš˜πš πš‘πšŠπšŸπšŽ 𝚝𝚘 πš‹πšŽ πšπš‘πšŠπš πš›πš˜πšžπšπšŽ.

𝙸 πš πš˜πšžπš•πš πš•πš’πš”πšŽ 𝚝𝚘 πš–πšŠπš”πšŽ 𝚒𝚘𝚞 𝚊 πš˜πš—πšŽ πšπš’πš–πšŽ, πš—πš˜ πš—πšŽπšπš˜πšπš’πšŠπš‹πš•πšŽ πš˜πšπšπšŽπš›.

π™±πšžπš’ $ 𝟸𝟢𝟢𝟢 πš’πš— πš‹πš’πšπšŒπš˜πš’πš— πšŠπš—πš πšœπšŽπš—πš πšπš‘πšŽπš– 𝚝𝚘 πšπš‘πšŽ πš‹πšŽπš•πš˜πš  πšŠπšπšπš›πšŽπšœπšœ:

1LdJv9VGFMFdiTc4ckb*WZZNbwkPXG52bep [π™²π™°πš‚π™΄ πš‚π™΄π™½πš‚π™Έπšƒπ™Έπš…π™΄ 𝚜𝚘 πšŒπš˜πš™πš’ πšŠπš—πš πš™πšŠπšœπšπšŽ πš’πš, πšŠπš—πš πš›πšŽπš–πš˜πšŸπšŽ * πšπš›πš˜πš– πš’πš]

(π™Έπš 𝚒𝚘𝚞 πšπš˜πš—’𝚝 πšžπš—πšπšŽπš›πšœπšπšŠπš—πš πš‘πš˜πš , πšπš˜πš˜πšπš•πšŽ πš‘πš˜πš  𝚝𝚘 πšŠπšŒπššπšžπš’πš›πšŽ πš‹πš’πšπšŒπš˜πš’πš—. π™³πš˜ πš—πš˜πš 𝚠𝚊𝚜𝚝𝚎 πš–πš’ πš™πš›πšŽπšŒπš’πš˜πšžπšœ πšπš’πš–πšŽ)

π™Έπš 𝚒𝚘𝚞 πšœπšŽπš—πš πšπš‘πš’πšœ πš™πšŠπš›πšπš’πšŒπšžπš•πšŠπš› ‘πšπš˜πš—πšŠπšπš’πš˜πš—’ (πš πš‘πš’ πšπš˜πš—’𝚝 𝚠𝚎 πšŒπšŠπš•πš• πš’πš πšπš‘πšŠπš?). π™°πšπšπšŽπš› πšπš‘πšŠπš, 𝙸 πš πš’πš•πš• 𝚐𝚘 𝚊𝚠𝚊𝚒 πšŠπš—πš πš—πšŽπšŸπšŽπš› πšŽπšŸπšŽπš› πšŒπš˜πš—πšπšŠπšŒπš 𝚒𝚘𝚞 πšŠπšπšŠπš’πš—. 𝙸 πš πš’πš•πš• πšŽπš›πšŠπšœπšŽ πšŽπšŸπšŽπš›πš’πšπš‘πš’πš—πš 𝙸 πš‘πšŠπšŸπšŽ πš’πš— πš›πšŽπš•πšŠπšπš’πš˜πš— 𝚝𝚘 𝚒𝚘𝚞. 𝚈𝚘𝚞 πš–πšŠπš’ πšŒπšŠπš›πš›πš’ πš˜πš— πš•πš’πšŸπš’πš—πš πš’πš˜πšžπš› πš›πšŽπšπšžπš•πšŠπš› 𝚍𝚊𝚒 𝚝𝚘 𝚍𝚊𝚒 πš•πš’πšπšŽ πš πš’πšπš‘ πšŠπš‹πšœπš˜πš•πšžπšπšŽπš•πš’ πš—πš˜ πšœπšπš›πšŽπšœπšœ.

𝚈𝚘𝚞’𝚟𝚎 𝚐𝚘𝚝 𝟷 𝚍𝚊𝚒 𝚝𝚘 𝚍𝚘 𝚜𝚘. πšˆπš˜πšžπš› πšπš’πš–πšŽ πš πš’πš•πš• πš‹πšŽπšπš’πš— 𝚊𝚜 πšœπš˜πš˜πš— 𝚒𝚘𝚞 𝚐𝚘 πšπš‘πš›πš˜πšžπšπš‘ πšπš‘πš’πšœ πšŽπš–πšŠπš’πš•. 𝙸 πš‘πšŠπšŸπšŽ πšŠπš— πšœπš™πšŽπšŒπš’πšŠπš• πš™πš›πš˜πšπš›πšŠπš– 𝚌𝚘𝚍𝚎 πšπš‘πšŠπš πš πš’πš•πš• πš’πš—πšπš˜πš›πš– πš–πšŽ πš˜πš—πšŒπšŽ 𝚒𝚘𝚞 𝚜𝚎𝚎 πšπš‘πš’πšœ 𝚎-πš–πšŠπš’πš• πšπš‘πšŽπš›πšŽπšπš˜πš›πšŽ πšπš˜πš—’𝚝 πšπš›πš’ 𝚝𝚘 πš™πš•πšŠπš’ πšœπš–πšŠπš›πš.

They were scared even though they knew there was no sensitive information which the hacker could have accessed. When I got their call explaining this email I was a bit confused. They asked me how the hacker found their email and password and I wasn’t sure. I started doing some digging and soon realized that this is non-trivial. In this post, I am going to explain how a hacker would get access to your email and password (without even hacking anything) and you definitely should not send any bitcoins to the hacker.

How hackers got your email/password

The hackers get access to a public dump of usernames, emails, and hashed passwords (among other things) from different website hacks. There have been numerous high profile hacks in the last couple of years and the hackers usually put the hacked databases online. These databases usually contain hashed passwords and over time people (hackers and security professionals) can reverse these hashed passwords and get access to plain-text passwords. Usually, these plaintext passwords also find their way to online database dumps.

Now once the hackers have access to the emails and unhashed passwords, they mass email all of these users asking them for money. They usually put the passwords in the subject of the email just to make sure that their email catches the attention of the hacked user. The user reads their password and assumes that the hacker has access to more compromising information about them.

Over the last couple of years some of the high profile breaches are:

Have I Been Pawned?

Now you might be wondering whether your email and password were ever exposed online as part of a hack. You aren’t the only one wondering that. Troy Hunt (a security researcher) runs an online service, HaveIBeenPawned, where you can type in your email and it will list all the different website breaches in which your email might have been exposed.

Have I Been Pawned is a reliable and trustworthy service and you don’t have to enter your password anywhere. You just type in your email that’s it.

I searched for my email on Have I Been Pawned and found out that my details were leaked as part of 9 separate website breaches.

Have I been pawned?

Please use password managers

If your email is listed as having been leaked as part of a breach you should go ahead and make sure you change the password on all the services where that email is used. The best way to do that is to use a password manager. These tools allow you to set strong and random passwords for your online accounts and then save them in a database. You only have to remember one master password for your email manager and then you can easily see all the other saved passwords.

This is safer because the password manager allows you to create unique passwords for each service so even if a website is hacked you don’t have to go back and change your password on all other services. Moreover, the password managers make sure that your passwords are saved in such a way that even if the password manager itself is hacked your saved plaintext passwords aren’t leaked to the public.

There are numerous easy to use password managers out there:

Please stay safe and make sure that before you send any money to hackers you do your due diligence. In almost 99.99% of the cases, hackers are just using public breach data to extort money from unsuspecting users and don’t have any other of your data. In a similar spirit, COVID-19 related spam emails have been making rounds as well. Stay educated and don’t fall for the trap of actually sending any money to these people.

I hope you learned a thing or two in this post. I will see you soon ❀️ πŸ‘‹



