Majorgeeks.com Support Forum Pwned?

Discussion in 'The Lounge' started by nlorntson, Mar 2, 2016.

Thread Status:
Not open for further replies.
  1. Eldon

    Eldon Major Geek Extraordinaire

  2. Imandy Mann

    Imandy Mann MajorGeekolicious

    I just copy/paste things like that in the start button/ search the internet.
     
  3. l0l

    l0l Private E-2


    Your database was posted on a few hacking forums and in the hands of multiple other hackers, I obtained a copy to see if it was real about a week ago.

    Seeing it was real I passed it onto the people who can get the message of the breach out, If you would like me to pass on a copy of the breached data to you I can but I will send it in a secure way.

    As for your email not showing that was odd, I tried your email used here on Have I Been Pwned and it did show now. It's possible not all data had been loaded by that point though.
     
  4. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    Yeah - trying to work out an email to all users, but it's not as easy as you would think and still stay within guidelines. Which I think it sorta weird. It;s kinda like the law that limits that ability for normal people to buy sudphed thinking that will somehow that will reduce methlabs. If we try and blast out to the list to tell people, we'll be the ones to get in trouble - not the ones that have the list. Should be out soon but the wheel are moving slower than we like.
     
  5. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    Huh. I suppose that explains why the other site listed on the pwned website didn't email me to tell me my password to their forums was compromised...
     
    Kestrel13! likes this.
  6. Sgt. Tibbs

    Sgt. Tibbs Ultra Geek

    Just so you know, the security letter got dumped in my spam folder.
     
  7. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Unfortunately, with an email like that, I'd suspect that will happen to people. It came through fine in my account and based on the number of people logged on right now, it went into their inboxes as well. Hopefully, people check their spam accounts before deleting.
     
  8. sharpconnect

    sharpconnect Private E-2

    Did Major Geeks really suffer a data breach? Or is the email I received spam?
     
  9. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Yes, we did. This thread talks about it.
     
  10. hankjam

    hankjam Private E-2

    I only got the email today, 08-Mar-16 and have no idea what is going on...
    I would be grateful if someone could update me as to what happened and when.
     
  11. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    You just posted in the thread that explains what was going on. The email sent out also explains it.
     
  12. hankjam

    hankjam Private E-2

    So if it happened in Nov-15, why did I get the email today?
     
  13. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Because we did not know that it was breached back in November. Everyone received the email today.

    Please read this thread if you would like to get more info. It has all been covered.
     
    hankjam likes this.
  14. satrow

    satrow Major Geek Extraordinaire

    Came through fine here a little over an hour ago.

    For anyone who finds this in their spam folder, please ensure that you mark it as not spam and also white list it.

    (If you have emails from a previously subscribed list/site that you no longer want, don't mark them as spam, use the Unsubscribe link at the foot of the email - but don't do this for real spam!)
     
    Eldon, Mimsy, LauraR and 2 others like this.
  15. Imandy Mann

    Imandy Mann MajorGeekolicious

    satrow - good advice. That last sentence should be paid attention to.

    I got the descriptive notice in the inbox. Also had one previously for my password change. Even showed the ip the change was sent from. My ip changes due to wireless but it is within the range expected. MG goes to my inbox since I earlier saved a newsletter which adds the sender to approved list.

    as far as the concern- none of my accounts - with similar names and passwords- none- have had any unusual activity yet. I would be interested to see if any has had any as aresult of this.
     
  16. Anon-9aee479f8f

    Anon-9aee479f8f Anonymized

    None here.
     
    Imandy Mann likes this.
  17. Imandy Mann

    Imandy Mann MajorGeekolicious

    a few more members to log in and we may finally out-number the robots! Heh heh!!
     
  18. Toke

    Toke MajorGeek

    Ive just recieved this mail . is it genuine as I logged in using my usual password.
    https://gallery.mailchimp.com/11e02cf9dc4ef3eb0ab4606ef/images/mglogo.1.jpg
    Unfortunately, it has been brought to our attention that there may have been a data breach of our old 3rd party forum software (vBulletin 3.x) someplace around November of 2015.

    According to credible reports, a hacker was able to gain access and export a list which included; user name, registered email and encrypted passwords. Encrypted or not, as a rule you should assume the password is possible to decrypt and protect against it.

    As such we have instituted a policy that will force a password change on all accounts, rendering the old password useless. Our new forums software also allows for two-step authentication of user accounts, if you desire higher security.

    Unfortunately, many people use the same user/password combination at multiple places. So, you should take care to change your passwords on systems which did in fact use the same password you used at the MajorGeeks Forums.

    If you have any questions, please email me (jim@majorgeeks.com) directly.

    Our sincere apologies for the inconvenience.

    Jim and Tim.
     
  19. pendantry

    pendantry Private E-2

    My tuppence: whenever you get a message like this (from a place you recognise!) -- log in and change your password :)
     
  20. Sgt. Tibbs

    Sgt. Tibbs Ultra Geek

    I am utterly astounded that folks are posting in this thread, which explains from the very first post what happened, asking what happened.
     
    Mimsy and LauraR like this.
  21. pendantry

    pendantry Private E-2

    Butbutbuthottubbutbut... oh, you must be new to forums ;)
     
  22. Sgt. Tibbs

    Sgt. Tibbs Ultra Geek

    LOL! No, not at all. I just don't get how they even knew to comment on this thread in particular without reading it.
     
  23. pendantry

    pendantry Private E-2

    ... butbutbutbut... oh, ok.

    I'm actually more surprised that the thread stayed on topic for so long. Post#13 is usually the point at which it goes waaaaaaaaaaaay offtopic. Here we are at Post#74 and it's still, ah, wait, no...

    Oops.
     
  24. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    Dang. I specifically put no links and used our normal email service to try and avoid that.
     
  25. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    This whole thread pretty much covers it. But to nutshell it, a service that monitors emails, https://haveibeenpwned.com/ was notified last week. Users of that service notified us and it took the weekend to pull together a clean list to be mailed out. It is not nearly as easy to email a large group of people legitimately as you would think. The November date may or may not be accurate. That is simply the report. We haven't seen the data or what was reported or the list. We are just going by the report and the reputation of the service and those that reported the breach to us.
     
  26. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    The force password change seems to be working for the rest. Either way change your password. If anyone else hears of that change not working please contact me directly and we will effort a new plugin
     
  27. Sgt. Tibbs

    Sgt. Tibbs Ultra Geek

    It might just be Comcast. Mail from my own office has a 50/50 shot at being dumped in spam if it's sent to the general mailing list.
     
  28. ScaleCraft

    ScaleCraft Private E-2

    and yet...for the first time in a LONG time, I logged in, just to check on that e-mail....and used my old log in details with no prompt so far to update anything.
     
  29. ScaleCraft

    ScaleCraft Private E-2

    because..you go looking, hit "last page", and here you are. Easy.
     
  30. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    The email you received explains it all. Just change your password here :)

     
  31. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    It seems a few are having issues. It could be because of security software, ad blockers or something we're unaware of. You can to your control panel and change your password there.

     
  32. joffa

    joffa Major Geek's Official Birthday Announcer

    Just like to mention I haven't received the email and I have checked spam logs in case of deletion.
    I also checked my other mail accounts, spam folders and infected folders as I sometimes forward mail to my mail server. I have received newsletter emails from MGs without any issues so :confused:

    Hmmm..... maybe it is just a slow trip all the way to Australia lol :rolleyes:

    BTW when I changed my password it took a couple of shots to log back in..... it might have been a typo but I didn't think so o_O any way it is all good now and MGs remembers me :cool:

    Edit: I also checked my MG contact details and all is correct
     
    Kestrel13! and Major Attitude like this.
  33. Mimsy

    Mimsy Superior Imperial Queen of the MG Games Forum

    I go away for a work day and the thread doubles in size... :rolleyes: :p

    I got the alert email into my inbox, by the way. And I do greatly appreciate that it was sent out in a mobile-friendly format, which made it very easy to read on my phone.
     
    Major Attitude likes this.
  34. Eldon

    Eldon Major Geek Extraordinaire

    Same here.
     
  35. l0l

    l0l Private E-2

    I sent an email to jim {@} majorgeeks.com regarding the data. The email's different to my user email here though.
     
  36. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    DavidGP likes this.
  37. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    Trying to test the force pop up - maybe find a better plugin for it. Forced password changes are not natively supported with xenforo.
     
    DavidGP and Mimsy like this.
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds