Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. My baby cousin called me in tears because all her accounts have been compromised.

My baby cousin called me in tears because all her accounts have been compromised.

Scheduled Pinned Locked Moved Uncategorized
9 Posts 6 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • 0xabad1dea@infosec.exchange0 This user is from outside of this forum
    0xabad1dea@infosec.exchange0 This user is from outside of this forum
    0xabad1dea@infosec.exchange
    wrote last edited by
    #1

    My baby cousin called me in tears because all her accounts have been compromised. We went over possible infection vectors (the “try my game” DM scam etc) and nothing stood out. But then she wondered if they’d gotten a foothold through the Canvas ransom somehow.

    Has anyone else heard of students getting their personal accounts popped very recently in a way that might be tied to the Canvas incident?

    rootwyrm@weird.autosR shadow53@floss.socialS smlx@fosstodon.orgS bigk@infosec.exchangeB inkomtech@infosec.exchangeI 5 Replies Last reply
    0
    • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

      My baby cousin called me in tears because all her accounts have been compromised. We went over possible infection vectors (the “try my game” DM scam etc) and nothing stood out. But then she wondered if they’d gotten a foothold through the Canvas ransom somehow.

      Has anyone else heard of students getting their personal accounts popped very recently in a way that might be tied to the Canvas incident?

      rootwyrm@weird.autosR This user is from outside of this forum
      rootwyrm@weird.autosR This user is from outside of this forum
      rootwyrm@weird.autos
      wrote last edited by
      #2

      @0xabad1dea I'm guessing that she used a common password for the impacted stuff?

      0xabad1dea@infosec.exchange0 1 Reply Last reply
      0
      • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

        My baby cousin called me in tears because all her accounts have been compromised. We went over possible infection vectors (the “try my game” DM scam etc) and nothing stood out. But then she wondered if they’d gotten a foothold through the Canvas ransom somehow.

        Has anyone else heard of students getting their personal accounts popped very recently in a way that might be tied to the Canvas incident?

        shadow53@floss.socialS This user is from outside of this forum
        shadow53@floss.socialS This user is from outside of this forum
        shadow53@floss.social
        wrote last edited by
        #3

        @0xabad1dea Not specifically. Did she use the same password for Canvas and these other services? Or Canvas and the email associated with those services?

        1 Reply Last reply
        0
        • rootwyrm@weird.autosR rootwyrm@weird.autos

          @0xabad1dea I'm guessing that she used a common password for the impacted stuff?

          0xabad1dea@infosec.exchange0 This user is from outside of this forum
          0xabad1dea@infosec.exchange0 This user is from outside of this forum
          0xabad1dea@infosec.exchange
          wrote last edited by
          #4

          @rootwyrm she insists no. which implies malware got directly onto her desktop, but it's not clear how. (I cannot check her computer at this time.)

          rootwyrm@weird.autosR 1 Reply Last reply
          0
          • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

            My baby cousin called me in tears because all her accounts have been compromised. We went over possible infection vectors (the “try my game” DM scam etc) and nothing stood out. But then she wondered if they’d gotten a foothold through the Canvas ransom somehow.

            Has anyone else heard of students getting their personal accounts popped very recently in a way that might be tied to the Canvas incident?

            smlx@fosstodon.orgS This user is from outside of this forum
            smlx@fosstodon.orgS This user is from outside of this forum
            smlx@fosstodon.org
            wrote last edited by
            #5

            @0xabad1dea browser extension?

            1 Reply Last reply
            0
            • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

              @rootwyrm she insists no. which implies malware got directly onto her desktop, but it's not clear how. (I cannot check her computer at this time.)

              rootwyrm@weird.autosR This user is from outside of this forum
              rootwyrm@weird.autosR This user is from outside of this forum
              rootwyrm@weird.autos
              wrote last edited by
              #6

              @0xabad1dea okay, that definitely adds a wrinkle. I'm not familiar with Instructure's crap, but I believe Canvas is web based. I wonder if it was malicious JS with a token stealer.

              1 Reply Last reply
              0
              • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                My baby cousin called me in tears because all her accounts have been compromised. We went over possible infection vectors (the “try my game” DM scam etc) and nothing stood out. But then she wondered if they’d gotten a foothold through the Canvas ransom somehow.

                Has anyone else heard of students getting their personal accounts popped very recently in a way that might be tied to the Canvas incident?

                bigk@infosec.exchangeB This user is from outside of this forum
                bigk@infosec.exchangeB This user is from outside of this forum
                bigk@infosec.exchange
                wrote last edited by
                #7

                @0xabad1dea I have heard that some students received phishing emails in relation to the Canvas hack. I don’t know if it was just opportunistic or directly related to the Canvas hack.

                1 Reply Last reply
                0
                • 0xabad1dea@infosec.exchange0 0xabad1dea@infosec.exchange

                  My baby cousin called me in tears because all her accounts have been compromised. We went over possible infection vectors (the “try my game” DM scam etc) and nothing stood out. But then she wondered if they’d gotten a foothold through the Canvas ransom somehow.

                  Has anyone else heard of students getting their personal accounts popped very recently in a way that might be tied to the Canvas incident?

                  inkomtech@infosec.exchangeI This user is from outside of this forum
                  inkomtech@infosec.exchangeI This user is from outside of this forum
                  inkomtech@infosec.exchange
                  wrote last edited by
                  #8

                  @0xabad1dea first, is there a chance cousin was scammed by a faked ‘you’ve been compromised’ message?

                  Worst tangles I’ve seen folks get into (in the last year or two) have been losing their social media account(s). Worse, the fraudsters parlay lockouts done by platforms into really scaring folks.

                  0xabad1dea@infosec.exchange0 1 Reply Last reply
                  0
                  • inkomtech@infosec.exchangeI inkomtech@infosec.exchange

                    @0xabad1dea first, is there a chance cousin was scammed by a faked ‘you’ve been compromised’ message?

                    Worst tangles I’ve seen folks get into (in the last year or two) have been losing their social media account(s). Worse, the fraudsters parlay lockouts done by platforms into really scaring folks.

                    0xabad1dea@infosec.exchange0 This user is from outside of this forum
                    0xabad1dea@infosec.exchange0 This user is from outside of this forum
                    0xabad1dea@infosec.exchange
                    wrote last edited by
                    #9

                    @InkomTech it's definitely not a fake scare, because this all began when *we* called *her* because "she" was DM'ing us on Discord about exciting investment opportunities. She called us back in tears when it was clear it wasn't just her discord, but everything.

                    1 Reply Last reply
                    1
                    0
                    • R relay@relay.infosec.exchange shared this topic
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                    • Login

                    • Login or register to search.
                    • First post
                      Last post
                    0
                    • Categories
                    • Recent
                    • Tags
                    • Popular
                    • World
                    • Users
                    • Groups