Account Hacked, Send $2000 in Bitcoin
Hi everyone! π Someone I know recently got an email informing them that their account had been hacked. The subject of the email had their password and the email went like this:
πΈπ πππππ ππππ, xxxxxxxx, ππ π’πππ πππππ πππ.
πΈ πππππππ π’πππ ππππππππ πππππππππ πππ πππ πππ πππ‘π πΈπΊ πππππ, ππ πΈ π πππ πππππππππ’ ππππ ππππ π’ππ ππππ π’ππ ππππ πππ ππ πππππππππππππ πππ πππ ππππ ππ π’πππ ππππ.
π·ππππ, π’ππ ππ πππ ππππ ππ ππππππππππ’. π±ππ πΈ ππππ πππππ’πππππ ππππππππππ π’ππ. ππππ ππππππ ππ πππππππ ππππ, ππππππππππ ππππππππ πππππ π πππ πππ πππ πππππππ ππππππππ’ ππ π’πππ ππππππππ ππππ ππππππππ π·π½πΌ πππ’π.
πΈππππππππ, π’πππ ππππ ππππππππ πππππ, π ππππ ππππππ ππ ππ πππ πππππππ’ ππππππ π ππ’ πΈ ‘π πππππππππ ππππ ππππππππ πππππ ππ π’ππ.
ππππ πππ ππππππππ ππππ π’ππ π πππ ππ πππ ππππ ππππππππ π πππππππ, ππ’ πππ’π πππ π ππ πππππππππ ππππππ π’πππ ππππππππ ππ’ππππ π ππππ πππππ ππ πππππππππ π ππ’π-ππππππππ πππππ πππππππ ππ π’πππ ππππ ππππππππ ππππ’ ππ’ ππππππππππ π’πππ π ππ πππ. (π’ππ πππ π ππππππππππ’ πππππππ πππππ ππ’ πππ π ππ’ ππππ)
πΈ ππ π πππ ππππππ πππππππππ. πΈπ, πππππππ π’ππ πππππ πΈ ππ πππππππ ππππππ, ππππ πππππ’ πππππ πππ πΈ π πππ ππ ππππ ππππππ πππ πππππππππ ππππππππ’ ππ π·πΈ ππππππ π’ππ’ππ πππππππ π πππ.
πΈπ πππ’ ππ π’πππ ππππππ, ππ π ππππππ, ππππ, πππππππ (πΈ’π πππ ππππ! πΌπ’ πππππ πππ π πππ ππππππππ’ ππππππ πππ ππππππππ).
ππππ π’ππ ππ πππππππ ππ ππππ ππππ πππ’πππ’π ππ’ππ πππππ πππππ ππ? πΈ ππππππππ ππππ…
π±ππ, ππ ππππ πππ ππππ ππ ππ ππππ πππππ.
πΈ π ππππ ππππ ππ ππππ π’ππ π πππ ππππ, ππ ππππππππππ πππππ.
π±ππ’ $ πΈπΆπΆπΆ ππ πππππππ πππ ππππ ππππ ππ πππ πππππ πππππππ:
1LdJv9VGFMFdiTc4ckb*WZZNbwkPXG52bep [π²π°ππ΄ ππ΄π½ππΈππΈπ π΄ ππ ππππ’ πππ πππππ ππ, πππ ππππππ * ππππ ππ]
(πΈπ π’ππ πππ’π ππππππππππ πππ , ππππππ πππ ππ πππππππ πππππππ. π³π πππ π ππππ ππ’ ππππππππ ππππ)
πΈπ π’ππ ππππ ππππ ππππππππππ ‘ππππππππ’ (π ππ’ πππ’π π π ππππ ππ ππππ?). π°ππππ ππππ, πΈ π πππ ππ ππ ππ’ πππ πππππ ππππ πππππππ π’ππ πππππ. πΈ π πππ πππππ πππππ’πππππ πΈ ππππ ππ ππππππππ ππ π’ππ. πππ πππ’ πππππ’ ππ ππππππ π’πππ πππππππ πππ’ ππ πππ’ ππππ π πππ ππππππππππ’ ππ ππππππ.
πππ’ππ πππ π· πππ’ ππ ππ ππ. ππππ ππππ π πππ πππππ ππ ππππ π’ππ ππ πππππππ ππππ πππππ. πΈ ππππ ππ πππππππ πππππππ ππππ ππππ π πππ ππππππ ππ ππππ π’ππ πππ ππππ π-ππππ πππππππππ πππ’π πππ’ ππ ππππ’ πππππ.
They were scared even though they knew there was no sensitive information which the hacker could have accessed. When I got their call explaining this email I was a bit confused. They asked me how the hacker found their email and password and I wasn’t sure. I started doing some digging and soon realized that this is non-trivial. In this post, I am going to explain how a hacker would get access to your email and password (without even hacking anything) and you definitely should not send any bitcoins to the hacker.
How hackers got your email/password
The hackers get access to a public dump of usernames, emails, and hashed passwords (among other things) from different website hacks. There have been numerous high profile hacks in the last couple of years and the hackers usually put the hacked databases online. These databases usually contain hashed passwords and over time people (hackers and security professionals) can reverse these hashed passwords and get access to plain-text passwords. Usually, these plaintext passwords also find their way to online database dumps.
Now once the hackers have access to the emails and unhashed passwords, they mass email all of these users asking them for money. They usually put the passwords in the subject of the email just to make sure that their email catches the attention of the hacked user. The user reads their password and assumes that the hacker has access to more compromising information about them.
Over the last couple of years some of the high profile breaches are:
- 500px data breach in mid-2018 where details of 15 million users were leaked
- Tumblr suffered a data breach in 2013 which leaked 65 million accounts to the public
- Zynga (the online game developer) got hacked in 2019 leaking details of 173 million accounts
Have I Been Pawned?
Now you might be wondering whether your email and password were ever exposed online as part of a hack. You aren’t the only one wondering that. Troy Hunt (a security researcher) runs an online service, HaveIBeenPawned, where you can type in your email and it will list all the different website breaches in which your email might have been exposed.
Have I Been Pawned is a reliable and trustworthy service and you don’t have to enter your password anywhere. You just type in your email that’s it.
I searched for my email on Have I Been Pawned and found out that my details were leaked as part of 9 separate website breaches.
Please use password managers
If your email is listed as having been leaked as part of a breach you should go ahead and make sure you change the password on all the services where that email is used. The best way to do that is to use a password manager. These tools allow you to set strong and random passwords for your online accounts and then save them in a database. You only have to remember one master password for your email manager and then you can easily see all the other saved passwords.
This is safer because the password manager allows you to create unique passwords for each service so even if a website is hacked you don’t have to go back and change your password on all other services. Moreover, the password managers make sure that your passwords are saved in such a way that even if the password manager itself is hacked your saved plaintext passwords aren’t leaked to the public.
There are numerous easy to use password managers out there:
Please stay safe and make sure that before you send any money to hackers you do your due diligence. In almost 99.99% of the cases, hackers are just using public breach data to extort money from unsuspecting users and don’t have any other of your data. In a similar spirit, COVID-19 related spam emails have been making rounds as well. Stay educated and don’t fall for the trap of actually sending any money to these people.
I hope you learned a thing or two in this post. I will see you soon β€οΈ π
βοΈ Comments
Thank you!
Your comment has been submitted and will be published once it has been approved. 😊
OK