Español Français Deutsch Italiano Nederlands Svenska Dansk Japanese Chinese (Simplified) Russian
 
AVForums.com twitter AVForums is a member of CEDIA. THX certified reviewer.  Click for more information. AVForums reviewers are ISF Certified.  Click for more information.
 
The UK's biggest and best home entertainment electronics forums  
4 million visitors each month


Forums Register Blogs Information Social Groups Search Today's Posts Mark Forums Read
Go Back   AVForums.com > Lifestyle Topics > General Chat

Latest AVForums Movie Reviews
Gray Lady Down - Original Motion Picture Soundtrack CD ReviewUp Blu-ray ReviewLéon Blu-ray ReviewNear Dark Blu-ray ReviewLogan's Run Blu-ray Review
Taking of Pelham 1 2 3, The Blu-ray ReviewStar Trek Blu-ray ReviewUFC 100: Lesnar vs. Mir (2009) Blu-ray ReviewThe New York Ripper Blu-ray ReviewHeat Blu-ray Review


Reply
 
Thread Tools Display Modes
Old 05-05-2006, 9:39 PM   #1 (permalink)
New Member
 
Join Date: Mar 2005
Location: Coventry
Posts: 4
Thanks: Gave 0, Got 0
Empire direct hacked or just complete scoundrels?

I use a different email address when ever i sign up to anything which technically doesn't exist but gets forwarded to a central one. The reason for doing this is so i can find who has sold my address/is spamming me. Then I can deal with it and block that address.

I have such an address for my empire direct account. It's never had mail sent from it and it's only ever been typed into the empire direct site. Their privacy policy states that they don't sell or pass on your details:

"EmpireDirect.co.uk takes your privacy rights as a customer seriously. This policy outlines the data we collect from our visitors and how we use it.

Any personal information provided to EmpireDirect.co.uk is used solely by Empire Direct plc, The Clock Buildings, Roundhay Rd, Leeds, LS8 2SH. "


So, interested was I when I got a phishing email this evening sent to the address. This means either:

a) empire direct have been hacked and account details stolen - potentially along with passwords and credit card info
b) empire direct sell your account details

Has anyone else who has bought AV stuff from them gotten phishing emails today? The one i got was a fake Natwest one.

Last edited by flid; 05-05-2006 at 9:41 PM.
flid is offline   Reply With Quote
Old 05-05-2006, 9:46 PM   #2 (permalink)
Ex Member
 
Join Date: Nov 2004
Posts: 7,557
Thanks: Gave 69, Got 316
Would it be possible that someone has picked an e-mail address at random, and has come up with one of your addresses ?

I have had spammers using my domain in the "from" field of their spam, but the prefixes in front of my domain name are not ones that I ever use.
Nick_UK is offline   Reply With Quote
Old 05-05-2006, 10:36 PM   #3 (permalink)
New Member
 
Join Date: Mar 2005
Location: Coventry
Posts: 4
Thanks: Gave 0, Got 0
well, i can't deny that it is physically possible, however if that is the case then i'm buying lottery tickets for tomorrow's draw :D
flid is offline   Reply With Quote
Old 05-05-2006, 10:43 PM   #4 (permalink)
Senior Member
 
Lawrenzini's Avatar
 
Join Date: Feb 2006
Posts: 1,810
Thanks: Gave 235, Got 373
did the phishing email relate to empire direct, or was it just a standard one?
__________________


Lawrenzini is offline   Reply With Quote
Old 06-05-2006, 7:36 AM   #5 (permalink)
Ex Member
 
Join Date: Nov 2004
Posts: 7,557
Thanks: Gave 69, Got 316
What spammers often do is to send out blank emails to thousands of random e-mail addresses, and the ones that don't "bounce" can then be counted as live. I thought it was a great idea to have a four-letter domain (so people could remember it easier), but the downside is that it doesn't take many random tries to come up with it.
Nick_UK is offline   Reply With Quote
Old 06-05-2006, 6:51 PM   #6 (permalink)
lisa burrell
Guest
 
Posts: n/a
[I use a different email address when ever i sign up to anything which technically doesn't exist but gets forwarded to a central one

if you need another.(email). if you run out go to www.cyberrights.com for email its anon and part of hushmail
  Reply With Quote
Old 09-05-2006, 8:54 AM   #7 (permalink)
New Member
 
Join Date: Mar 2005
Location: Coventry
Posts: 4
Thanks: Gave 0, Got 0
As I said the chances of anyone guessing by brute force the email address in question is less than me winning the lottery this weekend. I have my own mail server and a domain that I just use for email. I have a wildcard set so all email @ automatically routes to one address, then I can specify individual addresses to be blocked or routed elsewhere. It's a very efficient way of dealing with spam, provided that your friends aren't complete dumbasses and don't type your personal address into greeting cards sites. The phishing email was a 'natwest' one - nothing to do with empiredirect.
flid is offline   Reply With Quote
Old 09-05-2006, 9:26 AM   #8 (permalink)
Ex Member
 
Join Date: Nov 2004
Posts: 7,557
Thanks: Gave 69, Got 316
Is your "official" e-mail address on a web page somewhere ?
Nick_UK is offline   Reply With Quote
Old 24-05-2006, 8:27 AM   #9 (permalink)
New Member
 
Join Date: Mar 2005
Location: Coventry
Posts: 4
Thanks: Gave 0, Got 0
'official' ?

Quote:
Originally Posted by flid
It's never had mail sent from it and it's only ever been typed into the empire direct site.
the only possible explanation for this is that either empire direct were hacked or someone from the company has sold everyone's details
flid is offline   Reply With Quote
Old 24-05-2006, 8:48 AM   #10 (permalink)
Member
 
PmSonic's Avatar
 
Join Date: Sep 2005
Location: Edinburgh
Posts: 339
Thanks: Gave 125, Got 59
Quote:
Originally Posted by flid
'official' ?



the only possible explanation for this is that either empire direct were hacked or someone from the company has sold everyone's details
I disagree, comments made earlier bu Nick_UK suggest that hackers dont need to be sold / steal email addresses to send out span or phishing emails.

I can back this up by using my work email address as an example.

- I've only ever sent internal emails,
- the address isnt published on any of our litrature or on the website,
- i've never used it to register for anything online,
- we're a really small company & i work very closely with the network team so can vouch for the above statements.

Yet, i recieve spam, phishing attacks on a (fairly) regular basis. Oh, yes and its 8 letter .com domain name.
__________________
Canon 350D, 18-55mm Kit lens, Sigma 70-300mm f/4-5.6 APO DG Macro., Sigma 10-20mm.

Website: CarolinebyDesign
Flickr: http://www.flickr.com/photos/paulshand/
PmSonic is offline   Reply With Quote
Old 24-05-2006, 9:01 AM   #11 (permalink)
Senior Member
 
Steve_P's Avatar
 
Join Date: Jul 2004
Posts: 1,040
Thanks: Gave 67, Got 70
There is a 3rd option but I'm guessing it's a remote possibility as you sound pretty IT savvy... Could your own PC have been compromised as opposed to Empire Direct's info server?

S.
__________________
TV: Panasonic TH-37PE30B 5.1: Sony SA-PSD5 DVD: Panasonic DMR-E500H Digibox: Samsung 2100C Virgin
PC: Philips 11NB5800 (Vista Ultimate) Console: PS3 (UK,60Gb) ICE: JVC KD-AVX33 Mobile: Nokia N82 Black

Member of the AVForums Folding@Home Team
Steve_P is offline   Reply With Quote
Old 24-05-2006, 9:05 AM   #12 (permalink)
Super Moderator
 
Ian J's Avatar
 
Join Date: Aug 2001
Location: Midlands
Posts: 14,937
Thanks: Gave 1,457, Got 2,439
Blog Entries: 2
I set my wife up with an NTL email address a couple of years that has never been used by us at all - either for sending emails or for registering details anywhere and she still gets spam
__________________
Ian

Opinions expressed by myself are not necessarily those of AV Forums
Ian J is offline   Reply With Quote
Old 24-05-2006, 9:17 AM   #13 (permalink)
Senior Member
 
Join Date: Aug 2003
Location: Southampton
Posts: 1,472
Thanks: Gave 179, Got 202
There was an article which I read somewhere regarding phishing (may have been PC Pro) which stated that the most common method of 'phishing' was to use randomly generated email addresses. Those email domains with common 'tags' such as 'family' or 'home' or common names in the title 'smith', 'jones', etc are likely to get hit by 'phishing' emails more often.
Our standard email account was quite quiet on the spam front until a few months ago and it now seems to have gone ballistic!
I find the standard junk filter in outlook picks 90% of spam and phishing emails.
IE7 Beta 2 also has a 'phishing website' filter as well.
__________________
www.flickr.com/photos/simonr_uk It's a work in progress!

My kit: Nikon D90, Nikon 18-105 VR, Nikon 35mm F1.8 AF-S, Nikon 70-300 VR, Tokina 12-24 F4 II
Strobe is offline   Reply With Quote
Old 04-08-2006, 5:52 PM   #14 (permalink)
New Member
 
Join Date: Aug 2006
Posts: 0
Thanks: Gave 0, Got 0
Flid,

You are not alone.
I do exactly the same as you with regard to using unique email addresses, (we must have been separated at birth )
Since 26th July I have had 6 phishing attempts directed at my empiredirect address. I have not had any such attempts on any other address and since you've had them as well it really looks like somebody is getting these addresses from empiredirect somehow. Also, if people were making up random addresses I would expect to have got a lot of others directed at my domain as would you.
Did you contact empiredirect themselves about this? If so did you get any response? I just hope our CC details are safe with them!
umbongo is offline   Reply With Quote
Old 04-08-2006, 6:15 PM   #15 (permalink)
Moderator
 
IronGiant's Avatar
 
Join Date: Jun 2003
Location: Oxford UK
Posts: 3,568
Thanks: Gave 581, Got 1,554


Dave
IronGiant is offline   Reply With Quote



Bookmarks

Tags
complete, direct, empire, hacked, scoundrels
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


All times are GMT. The time now is 3:19 PM.

AV Forums
Optimised for Firefox.
RSS Feed
AVForums.com is owned and operated by M2N Limited.
Copyright © 2000-2009 M2N E. & O. E.
Global Gold
Web Hosting