4 ms·
1.9M Bell customer email addresses stolen by 'anonymous hacker'
- beex 9y agoNot being facetious: what is the worst that can be done with stolen email addresses? Spam?
- spike021 9y agoPhishing is a start.
- ar0 9y agoTargeted phishing. After all you know that all of these people are Bell customers and some of them will have used email addresses they haven't used anywhere else, so they will expect emails from Bell and might not expect phishing to these email addresses.
- ronnier 9y agoCorrelate them with other dumped email/passwords lists and try to log in and find other info to eventually scam/phish/fraud people?
- throwwit 9y agoKinda funny the 'relevant ads' program was worse in my opinion. http://www.cbc.ca/news/canada/windsor/bell-faces-750m-lawsuit-over-allegedly-selling-customer-data-1.3037545 http://www.cbc.ca/news/canada/windsor/bell-faces-750m-lawsui...
- uw_rob 9y agoI'm not sure if it is the worst, but one issue is bruteforcing valid premium logins on sites.
- mythrwy 9y agoPaste them in website popups that ask for email addresses to be put on a subscription list.
- deleted 9y ago[deleted]
- soyiuz 9y agoPerhaps I have security breach fatigue, but I am somewhat fed up with the usual "emails stolen" headline. An address and a name are by definition publicly available records. You can steal them simply by walking down the street and taking down mailbox names (or requesting these records from the city hall). Of course the fact that these names are Bell's customers gives someone one more bit of information, but again not necessarily private information. My name is on the doorbell buzzer in a densely populated area, which is also served by a single phone company. Once again, the information is kind of public by default. Perhaps what we need is a more thorough discussion about boundaries between public and private activities. For example, shopping seems to fall into the gray zone between these ideas. I do not usually have the expectation of privacy when I shop. Should I then be surprised that my local mart shares my shopping details with third parties? On the other end of the spectrum we hold onto truly private information like security tokens or private keys (both real and virtual) with much more zeal. Those we do not share with random strangers, much less large corporate entities. And when we do, as when I give my house keys to a cleaning company, we sign a legally binding agreement which mentions things like "bonds and insurance" against potential damages or breaches of security. I am happy to accept either one of those realities, depending on the situation. But let's at least understand where we stand before the outrage.
- enraged_camel 9y ago>>Perhaps I have security breach fatigue, but I am somewhat fed up with the usual "emails stolen" headline. An address and a name are by definition publicly available records. You can steal them simply by walking down the street and taking down mailbox names (or requesting these records from the city hall). I may be able to find out your email address, but that's not the same thing as knowing that you have an account on some specific website. If I know the latter, that opens you to phishing and social engineering attacks. I can send you highly targeted emails from a spoofed address and get you to click a link or open a file attachment and install malware on your system.
- turnip1979 9y agoExactly. We got a mail from our car insurance provider saying they did not receive payment and asked to send the payment to some random address. This could be social engineering or it could be genuine. We are careful so we will contact the company directly and not use the provided information. But I doubt most people are so prudent.
- problems 9y agoOriginal posting: https://pastebin.com/zHffB8rA https://pastebin.com/zHffB8rA This contains a bit more data than they were suggesting and a tar file for a .mozilla directory, possibly containing some saved passwords? It appears to include b1* usernames and maybe passwords (Used for Bell PPPoE credentials), might be enough to steal someone's bandwidth or make it look like someone else downloaded something rather illegal.
- criddell 9y agoBell says they were stolen by a hacker, I say they were lost because of negligence.
- NationLider 9y agoTo see if you've been affected, use haveibeenpwned! It seems that I have.