WHMCS CEO Matt Posted May 26, 2012 WHMCS CEO Share Posted May 26, 2012 they do though seem to use WHMCS... license pull I think Already been done. We appreciate everyone forwarding us a copy of the spam emails they are receiving - but please can I ask that you don't forward either of the 2 mentioned here anymore as we have enough copies of it! We have already passed them on to both the FBI and UK E-Crime Unit, along with the name & address details held for the licenses of both sites. Matt 0 Quote Link to comment Share on other sites More sharing options...
makaira Posted May 26, 2012 Share Posted May 26, 2012 Matt I take it this link on your site http://www.whmcs.com/appstore/340/HiPay-Payment-Gateway-for-WHMCS.html will be removed as he has obvioulsy used data stolen in your recent attack. I received his spam today. Does anyone know is Hipay is legit, it looks legit but these days you never know. Makaira 0 Quote Link to comment Share on other sites More sharing options...
easyhosting Posted May 26, 2012 Share Posted May 26, 2012 Just checked and both are still using WHMCS although they are no longer authorised too 0 Quote Link to comment Share on other sites More sharing options...
gupi Posted May 26, 2012 Share Posted May 26, 2012 How about also reporting them to mywot.com ? my 2c 0 Quote Link to comment Share on other sites More sharing options...
easyhosting Posted May 26, 2012 Share Posted May 26, 2012 How about also reporting them to mywot.com ? my 2c mywot is not a reliable service as it is run and used only by liars and cheats 0 Quote Link to comment Share on other sites More sharing options...
Nexxterra Posted May 26, 2012 Share Posted May 26, 2012 Hey people, this is just the beginning! Go to your WHMCS account and change your email address. You are going to get way more spam, your email address is now public. I have always used specific spam email addresses, so most of what I get is crap, but I glance over for anything from a site I recognize. ALSO, remember, spam is NOT email you do not want, if it if formatted properly with a way to remove you from the list, it is NOT considered spam to those that matter, like spamcop, email providers, etc. 0 Quote Link to comment Share on other sites More sharing options...
easyhosting Posted May 26, 2012 Share Posted May 26, 2012 spam is NOT email you do not want, if it if formatted properly with a way to remove you from the list, it is NOT considered spam to those that matter, like spamcop, email providers, etc. what christmas cracker did you get this from Spam is exactly email you do not want, just because it has a unsubscribe link at the end does not make it less spam, as spammers sometimes place these links in and what they do if you use it is to inform the spammer that they have hit a llive/active email so they can sell this email to other spammers. If it is spam then i NEVER use any links even if it says unsubscribe here, i always report to Spamcop and the IP supplier and have had no problems doing this. 0 Quote Link to comment Share on other sites More sharing options...
PhilB Posted May 26, 2012 Author Share Posted May 26, 2012 Unsolicited Commercial Email ~= spam. If I didn't ask for it, it's spammy. If I have no way to unsubscribe, doubly so - that doesn't mean that mailing lists I *can* unsubscribe from aren't spam. 0 Quote Link to comment Share on other sites More sharing options...
easyhosting Posted May 26, 2012 Share Posted May 26, 2012 the 2 that have been sending SPAM using info they got from the leaked DB have been dealt with, they have been reported to their DC and spamcop and they have had their WHMCS licences revoked. 0 Quote Link to comment Share on other sites More sharing options...
panacheweb Posted May 26, 2012 Share Posted May 26, 2012 I got an invite from a FB person called information madness. I have reported them to facebook stating they are using data from the whmcs.com hack. I am not posting links to their profile, as that will create unneeded attention and may have the opposite effect. 0 Quote Link to comment Share on other sites More sharing options...
easyhosting Posted May 26, 2012 Share Posted May 26, 2012 I got an invite from a FB person called information madness. I have reported them to facebook stating they are using data from the whmcs.com hack. I am not posting links to their profile, as that will create unneeded attention and may have the opposite effect. If this person states his website on his FB page, check to see if they actually use WHMCS and if they do report them to Matt. 0 Quote Link to comment Share on other sites More sharing options...
gromett Posted May 26, 2012 Share Posted May 26, 2012 Why are people calling it a leaked DB? It was not Leaked it was stolen.. A leak is usually a minor escape. This was an all out theft. I have only received these two spams so far... 0 Quote Link to comment Share on other sites More sharing options...
Peter M Dodge Posted May 27, 2012 Share Posted May 27, 2012 From my mail log: whmcsadd@zadok.hostdistrict.com May 25, 2012 11:52:23 PM petermdodge@vtelectronics.net 1SY83D-000CcD-Ei Could not complete sender verify 0 Quote Link to comment Share on other sites More sharing options...
PhilB Posted May 27, 2012 Author Share Posted May 27, 2012 Why are people calling it a leaked DB? It was not Leaked it was stolen.. A leak is usually a minor escape. This was an all out theft. We're discussing semantics here, but the original act of obtaining the data was the theft. The subsequent release of that data cannot also be theft - it's already been stolen. At that point it is both stolen and leaked - but only the act of leaking it brought it into the public domain (and into the hands of spammers). I think it's pretty accepted that "leak" isn't a term limited to small amounts of data (see the US diplomatic cable "leak", or just wikileaks in general). 0 Quote Link to comment Share on other sites More sharing options...
Nexxterra Posted May 27, 2012 Share Posted May 27, 2012 what christmas cracker did you get this from Spam is exactly email you do not want, just because it has a unsubscribe link at the end does not make it less spam, as spammers sometimes place these links in and what they do if you use it is to inform the spammer that they have hit a llive/active email so they can sell this email to other spammers. If it is spam then i NEVER use any links even if it says unsubscribe here, i always report to Spamcop and the IP supplier and have had no problems doing this. I got this from the legislation that your email or upline provider have to follow, you can report anyone for any reason you want. it does not mean that any action will be taken. As for the possession of the files, if something is considered stolen, any one in possession of said item is committing a crime. this is true in many countries, what may not apply in some countries is data or files may or may not be properly classified as an item that can be stolen yet. 0 Quote Link to comment Share on other sites More sharing options...
Digitalized Media Posted May 27, 2012 Share Posted May 27, 2012 My phone has been ringing off the hook with a ton of new numbers, almost entirely business to business calls in regards to hosting add-ons, billing systems and security - and my info was NOT leaked. I think there is just some clever marketing people out there. 0 Quote Link to comment Share on other sites More sharing options...
Peter M Dodge Posted May 27, 2012 Share Posted May 27, 2012 I got this from the legislation that your email or upline provider have to follow, you can report anyone for any reason you want. it does not mean that any action will be taken.As for the possession of the files, if something is considered stolen, any one in possession of said item is committing a crime. this is true in many countries, what may not apply in some countries is data or files may or may not be properly classified as an item that can be stolen yet. In Canada any unsolicited phone or email message for a business purpose is spam, and you can be subject to significant fees if you solicit from a phone number on the national "Do Not Call" list. 0 Quote Link to comment Share on other sites More sharing options...
easyhosting Posted May 27, 2012 Share Posted May 27, 2012 In Canada any unsolicited phone or email message for a business purpose is spam, and you can be subject to significant fees if you solicit from a phone number on the national "Do Not Call" list. This is the same in the UK and also in the USA where they have the CAN-SPAM Act of 2003 0 Quote Link to comment Share on other sites More sharing options...
Hervek Posted May 27, 2012 Share Posted May 27, 2012 Hi and scuze for poor english . Yes it was spam ... but i have a question ( lol just a little question ) Where is it possible to have à module for payement by Hipay ? If you have an answer, a solution , Thanks 0 Quote Link to comment Share on other sites More sharing options...
bear Posted May 27, 2012 Share Posted May 27, 2012 Why are people calling it a leaked DB? It was not Leaked it was stolen.. It was stolen, then leaked. Leak means to release publicly, regardless of to what extent. Interesting thing to note, those that pirate software cite that it's not theft since they leave the original in tact that others can access. In this case, it's theft, even though they left the original... 0 Quote Link to comment Share on other sites More sharing options...
easyhosting Posted May 27, 2012 Share Posted May 27, 2012 and Matts seems to be taking action against WHMCS members who have been spamming using this data by revoking their licences 0 Quote Link to comment Share on other sites More sharing options...
Jbro Posted May 27, 2012 Share Posted May 27, 2012 Mother blah blah spammers Shame on you $^#$^#^@ 0 Quote Link to comment Share on other sites More sharing options...
Peter M Dodge Posted May 28, 2012 Share Posted May 28, 2012 and Matts seems to be taking action against WHMCS members who have been spamming using this data by revoking their licences Well, he should, you're basically trying to have your cake and eat it too, by using data stolen from the people you get your billing soft from. It would be like robbing the bank, and then going to the same bank and legitimately expecting them to deposit the money in your account. 0 Quote Link to comment Share on other sites More sharing options...
gromett Posted May 28, 2012 Share Posted May 28, 2012 We're discussing semantics here, but the original act of obtaining the data was the theft. The subsequent release of that data cannot also be theft - it's already been stolen. At that point it is both stolen and leaked - but only the act of leaking it brought it into the public domain (and into the hands of spammers). I think it's pretty accepted that "leak" isn't a term limited to small amounts of data (see the US diplomatic cable "leak", or just wikileaks in general). Agreed it is semantics... However, The data was stolen, it doesn't matter how many hands it passes through it remains stolen data not leaked data. Leaked has connotations of accidental or minor. The word stolen more accurately represents the truth here. Leaked data to me infers that it was someone inside the organisation who released data by accident or deliberately but covertly. Such as government leaks etc. I am angry about what these criminals have done and the word stolen carries more weight than leaked. Using leaked seems to take some of the impact away. For example which of the following more accurately relays your anger over the current situation? AJ Online Services used leaked data to send emails to..... AJ Online Services used stolen data to send email to..... Just my opinion tho 0 Quote Link to comment Share on other sites More sharing options...
easyhosting Posted May 28, 2012 Share Posted May 28, 2012 Agreed it is semantics... However, The data was stolen, it doesn't matter how many hands it passes through it remains stolen data not leaked data. Leaked has connotations of accidental or minor. The word stolen more accurately represents the truth here. Leaked data to me infers that it was someone inside the organisation who released data by accident or deliberately but covertly. Such as government leaks etc. I am angry about what these criminals have done and the word stolen carries more weight than leaked. Using leaked seems to take some of the impact away. For example which of the following more accurately relays your anger over the current situation? AJ Online Services used leaked data to send emails to..... AJ Online Services used stolen data to send email to..... Just my opinion tho well it looks like the upstream provider for frogost.com has taken action and taken their siite down 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.