6 ms·
Social engineering GoDaddy (2021)
- IYasha 4y agoSo THAT'S why google doesn't have human tech support!
- EGreg 4y ago
- trafnar 4y agoReminds me of this story “How I lost my $50,000 Twitter username” from 2014. https://medium.com/@N/how-i-lost-my-50-000-twitter-username-24eb09e026dd https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...
- hombre_fatal 4y agoAlso, "Amazon's customer support backdoor" (2016). https://medium.com/@espringe/amazon-s-customer-service-backdoor-be375b3428c4 https://medium.com/@espringe/amazon-s-customer-service-backd... The screenshots of the attack/transcript make my stomach hurt.
- pbear2k21 4y agoOops - The title was meant to say 2007. However GoDaddy still suffers from social engineering attacks, e.g. https://www.zdnet.com/article/godaddy-staff-fall-prey-to-social-engineering-scams-in-cryptocurrency-exchange-attack-wave/ https://www.zdnet.com/article/godaddy-staff-fall-prey-to-soc...
- sethammons 4y agoWow, I wonder if that is what happened to my company's domain a decade ago. We lost control of our domain due to social engineering at GoDaddy. It was really, really tense as we worked to get control back. We got lucky and we able to retrieve the domain later that day.
- confident_inept 4y agoThis stuff is still incredibly easy to do to this day. I was the general manager of a retail office store chain and we would frequently have calls come in forging fake complaints but asking for the district or regional manager's first and/or last name. The attacker would then call another store in the region claiming to be "Mr. Head Manager". Most associates knew or had seen the names (they were required to be posted in the break room) but often times never met the people in question. The attacker got associates and other shift/associate managers to do everything from giving up secure information on the registers to ring up gift cards. It was happening two to three times a week in our district at times despite weekly training and conference calls on the subject. Some people are just born to be duped.
- swatcoder 4y ago> Some people are just born to be duped Nah, all people are born to be duped. Nobody can be vigilant all the time. There's a point where you have to let down your guard and trust that there's no monster ready to pounce on you from the shadows. Vigilance has its own costs that often work against the tasks at hand, and can really fry your body if held high for too long. As GM you may have been especially vigilant about this issue because you saw yourself as the steward of your store(s), but those associates weren't in the same position and were bound to be more lax on net. It doesn't sound like these social engineering attacks tanked the company, so whatever dynamic existed between everyone seemed to work adequately.
- formerkrogemp 4y agoIt doesn't hurt that retail stores in the US pay dirt and shit for wages.
- personjerry 4y agoIsn't this fraud?
- hyperhopper 4y agoWho was defrauded? Not the old domain owner, he just got a legit email and decided to sell. Maybe they committed some other crime against GoDaddy, but I'm not a lawyer and I'm not sure what. They impersonated a call center manager, but I'm not sure if that's against the law. After that the employee willingly told them things.
- dylan604 4y ago>Maybe they committed some other crime against GoDaddy As a non-sequiter, I'd say GoDaddy is a crime against humanity
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- EGreg 4y ago
- deleted 4y ago[deleted]
- biermic 4y agoI also have heard of such a story. A friend of mine did something similar a long time ago. Someone posted malicious stuff on his website, which showed up when googling my friends name. This costed him quite some business. He knew the email address of the website owner, and the provider where the website was hosted. So he registered the same email address under a different free email hosting provider. Then he sent the website hoster an e-mail where he told them about a new email address and if they could change it. With that he could reset the password and delete the website.
- deleted 4y ago[deleted]
- iamricks 4y agoI've mentioned this before[1], we once had a domain stolen because somebody called GoDaddy and was able to get the 2FA code removed with a phone call and they had some leaked email credentials for the account. We had to call GoDaddy and cancel the domain transfer, they would give us no information on how it happened. [1]: https://news.ycombinator.com/item?id=29308613 https://news.ycombinator.com/item?id=29308613
- jherico 4y agoMy take is "don't use the same channel for internal coms as for customer coms". That way training could make it clear: * Supervisor communication will always come through Slack, or email or some other mechanism. * Never trust that the identity of anyone on the phone is someone internal unless you initiated the call.
- malfist 4y agoThat works until someone gets their slack compromised
- throwaway892238 4y agoMost companies can be SE'd. Think of a company that controls whatever you consider the most sensitive internet infrastructure - them too. Whatever you imagine is secure is probably not, because somewhere a human is in control of it.