• Welcome to the Off-Topic/Schweb's Lounge

    In addition to the Mac-Forums Community Guidelines, there are a few things you should pay attention to while in The Lounge.

    Lounge Rules
    • If your post belongs in a different forum, please post it there.
    • While this area is for off-topic conversations, that doesn't mean that every conversation will be permitted. The moderators will, at their sole discretion, close or delete any threads which do not serve a beneficial purpose to the community.

    Understand that while The Lounge is here as a place to relax and discuss random topics, that doesn't mean we will allow any topic. Topics which are inflammatory, hurtful, or otherwise clash with our Mac-Forums Community Guidelines will be removed.

hundreds of paypal user names/emails

Joined
Apr 10, 2007
Messages
313
Reaction score
7
Points
18
Hello, I got an email from paypal about my account today, instead of the message they were trying to send I got a document with 2 or 3 pages of emails /usernames. I have attempted to contact them but they have not responded. This seems to me like a pretty serious security issue and I want to make people aware of it, what should I do?
 
Joined
Oct 16, 2006
Messages
665
Reaction score
46
Points
28
Location
Birmingham (S), UK
Your Mac's Specs
20" iMac Intel Core Duo 2 (Standard)
Blackmail them and get some Money out of it.

No personally I wouldn't give it to the Company, I'd report it to the Information Commissioner (or equivalent body, depending on where you life) to ensure its taken seriously and not covered up.

These ineffective Security by companies has gone to far. Then to reinforce the Idea, I'd also pass the information onto Spammers.

I can smell the Legal Action, already.
 

bobtomay

,
Retired Staff
Joined
Dec 22, 2006
Messages
26,561
Reaction score
677
Points
113
Location
Texas, where else?
Your Mac's Specs
15" MBP '06 2.33 C2D 4GB 10.7; 13" MBA '14 1.8 i7 8GB 10.11; 21" iMac '13 2.9 i5 8GB 10.11; 6S
My guess is that what you received was not from Paypal at all, but from a spammer trying to entice people to come and verify their user name and password. The document you got was more than likely a mistake made by the spammer in the attachment he put into the e-mail.

I would notify Paypal directly - not throught that e-mail - and let them know what you received. Paypal has been doing much to try and combat this type of prolific spam aimed at it's users. I get on average 2 of these a week at my workplace e-mail even through the filters in place.
 
OP
J
Joined
Apr 10, 2007
Messages
313
Reaction score
7
Points
18
Hello, I tried to post it here but there are too many characters, 36000 or so. The email did not ask for any of my personal info, all that was in it was the user names and or emails.
 

bobtomay

,
Retired Staff
Joined
Dec 22, 2006
Messages
26,561
Reaction score
677
Points
113
Location
Texas, where else?
Your Mac's Specs
15" MBP '06 2.33 C2D 4GB 10.7; 13" MBA '14 1.8 i7 8GB 10.11; 21" iMac '13 2.9 i5 8GB 10.11; 6S
Still, I think this is a stupid spammers mistake and would contact Paypal. At least they could verify whether these are genuine accounts and info or not and take appropriate action.

There's really not much else you can do besides delete and forget it.
 
Joined
Jul 18, 2006
Messages
2,180
Reaction score
92
Points
48
Location
Florida
Still, I think this is a stupid spammers mistake and would contact Paypal. At least they could verify whether these are genuine accounts and info or not and take appropriate action.

There's really not much else you can do besides delete and forget it.

I, for one, would like to know the outcome of this (I use PayPal a lot). Would be interested in knowing if, in fact, this is a legitimate list or not.
 
OP
J
Joined
Apr 10, 2007
Messages
313
Reaction score
7
Points
18
Bingo!!--it is a scam. The tipoff is this line:

Received: from server1.ddf.com.br ([67.15.60.8])

Here is the result of a whois search:

mherring@1[grub]$ whois server1.ddf.com.br

% Copyright (c) Nic.br
% The use of the data below is only permitted as described in
% full by the terms of use (http://registro.br/termo/en.html),
% being prohibited its distribution, comercialization or
% reproduction, in particular, to use it for advertising or
% any similar purpose.
% 2007-06-10 10:55:39 (BRT -03:00)

% Query rate limit exceeded. Reduced information.
% Use https://registro.br/cgi-bin/avail/ for domain availability.

domain: ddf.com.br
owner: Daniel de Melo Franqueira ME (682010)

% Security and mail abuse issues should also be addressed to
% cert.br, http://www.cert.br/, respectivelly to [email protected]
% and [email protected]
%
% whois.registro.br accepts only direct match queries. Types
% of queries are: domain (.br), ticket, provider, ID, CIDR
% block, IP and ASN.

Going to registro.br confirms that they are in fact in Brazil.

I would definitely pass this on to Paypal (use an address for them that
you know to be good)
 
M

MacHeadCase

Guest
Hah! It made no sense and now you do have proof! Cool! If ever I need a detective, I'm gonna hire you and Browny fer sure! :D
 
Joined
Mar 22, 2007
Messages
1,463
Reaction score
67
Points
48
Location
UK
Your Mac's Specs
Lenovo Z560 Hackintosh -:- '06 iMac -:- iPod Touch 2ndGen
You should be able to email it to [email protected]. That's where I send all the phishing emails I get. And I wouldn't post it here, whether you can or not. The owners of the addresses won't thank you for placing their emails on the web for all to see.
 
Joined
Jul 18, 2006
Messages
2,180
Reaction score
92
Points
48
Location
Florida
I agree with MHC - going to add you to my "detectives" list. Wow - great job! It is also a relief to know someone did not crack the real list. Great job jakeroberts!!! :D
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top