Need some help preventing email scams..

egrus

New Member
So some background first...
I have a domain that I manage using a ZoneEdit free account, and I mainly use this for email forwarding
I have *@mydomain forwarded to my GMail

Lately, I've been getting a lot of messages that appear to be coming from myself, saying stuff like "I have your password, it's [whatever], send me bitcoin now!"

The passwords they are sending me and the addresses they are sending them to are from very old accounts I had on some vBulletin forums that almost certainly got hacked and ended up on TOR, and a few years ago, I went through an awakening, switched to a password manager (1Password), and changed all my active accounts to randomly generated passwords, enabled 2FA where possible, and deleted / deactivated any accounts I no longer wanted

I'm not concerned at all that they have these old passwords, but what I am concerned about is how they're able to spoof their email as if it's coming from me

I'm a somewhat technical person, but not too technical when it comes to the inner workings of email, dns, etc.
Can someone explain how they're able to spoof the address so easily, and is there anything I can do to prevent this?

What about SPF, would that be a viable solution?
Thanks in advance.
 
Last edited:

sandy

Administrator
Staff member
Hi there

these "hackers" work by getting access to a password and then harass the user. This is an old tactic, has been around for years. They're just targeting us now.

Quite a few other providers have been hit the last few weeks as well...

Please change any associated passwords and of course delete this email. Nothing on our side has been "Hacked" and they are using a clever trick to mask the sender.

A good site on this issue: https://haveibeenpwned.com/

thanks
sandy



thanks and take care
 

egrus

New Member
Thanks for the response, Sandy -- yeah, I'm familiar with that, there are a few other sites on TOR where you can check recent dumps, etc.
But what I really want to know is --
How are they able to spoof the emails and make it look like it's coming from my own email at my domain, and how do I stop them from doing this, like specifically?
I'm way more concerned about (and interested in learning about) that than I am that they have 5 year old passwords that I stopped using and have 2FA etc enabled on now.
 

egrus

New Member
They've stopped since Monday night
Wonder why? I've been looking into SPF but it seems that even that wouldn't have stopped it, at least from my understanding
 

sandy

Administrator
Staff member
I believe our admins have made some internal changes as well to help combat these as well.

thanks
sandy
 

egrus

New Member
Well that's awesome, thank you.
If anyone on your side has time, I'd still be interested in learning how they were doing it, and what you folks did to mitigate it, the technical aspects, maybe have someone write up a quick blog post or something, if at all possible. If not, thats cool too, time isn't free unfortunately.
Have a nice one :)
-Nick
 
Top