🚀💳 Trustee Plus - більше ніж криптогаманець з європейською платіжною карткою. Спробуй 👉

The creator of the data leak site HaveIBeenPwned was caught in a phishing email. How a hacker managed to catch a cybersecurity expert in his mistake

The attackers managed to outsmart Troy Hunt, the creator of the website HaveIBeenPwned, who clicked on a malicious link in an email due to exhaustion after a trip. He assures that the data of millions of HaveIBeenPwned users was not affected by his mistake.

Leave a comment
The creator of the data leak site HaveIBeenPwned was caught in a phishing email. How a hacker managed to catch a cybersecurity expert in his mistake

The attackers managed to outsmart Troy Hunt, the creator of the website HaveIBeenPwned, who clicked on a malicious link in an email due to exhaustion after a trip. He assures that the data of millions of HaveIBeenPwned users was not affected by his mistake.

HaveIBeenPwned is a website that allows users to check if their personal information has been compromised in a data breach. The site is widely recognized as a valuable resource for protecting security and privacy.

The project was created by security expert Troy Hunt on December 4, 2013. As of June 2019, the HaveIBeenPwned website was visited by over 160,000 users daily. It also has nearly 3 million active email subscribers and contains records of nearly 8 billion accounts.

«You know when you feel really jet-lagged and tired and the cogs in your head are turning a little slower? That’s exactly what happened to me, and it just came to light that a Mailchimp phishing attack stole my credentials, logged into my account, and exported the mailing list for this blog», — Troy Hunt recently reported on his personal website.

According to him, the attacker only managed to obtain data from users who subscribed to his personal blog, not the HaveIBeenPwned website.

«I am extremely disappointed to have been caught up in this, and I apologize to everyone on this list», — he said.

Hunt later revealed that the attack affected about 16,000 email addresses. It was carried out through a phishing email that purported to come from his email provider, Mailchimp. The phishing email claimed that Mailchimp had received a spam complaint and had been forced to limit the «sending rights» of Hunt’s account, which was linked to his personal blog.

Troy Hunt clicked on a phishing link in an email, which forced him to enter his credentials and a one-time password on a hacker-controlled login page. But he quickly realized something was wrong when the login process «froze.»

Screenshot of the phishing email that Troy Hunt fell for

Hunt changed the password to his real Mailchimp account, but it was too late: the hacker had hacked his account and exported his mailing list, suggesting the entire attack was automated. The expert added that 7,535 users who unsubscribed from his blog were also trapped in the hack because Mailchimp was unable to delete their emails.

Although the Australian expert had received and repelled «a gazillion similar phishing attacks,» he explained that this particular phishing email caught him off guard as he was exhausted from his trip to London.

«Fatigue was a major factor. I wasn’t paying enough attention and didn’t think through what I was doing. The attacker couldn’t have known (I have no reason to suspect that the attack was directed at me), but we all have moments of weakness, and if a phishing attack took advantage of that moment, well, there we have it», — Troy Hunt explained.

Read the country's main IT news in our Telegram
Read the country’s main IT news in our Telegram
On the topic
Read the country’s main IT news in our Telegram
Hackers are using Signal to send phishing links to defense industry employees and representatives of the Defense Forces. What to avoid
Hackers are using Signal to send phishing links to defense industry employees and representatives of the Defense Forces. What to avoid
On the topic
Hackers are using Signal to send phishing links to defense industry employees and representatives of the Defense Forces. What to avoid
Scammers pretend to support PayPal in phishing emails: “Confirm your address for MacBook M4 Max delivery.” How this scheme works
Scammers pretend to support PayPal in phishing emails: «Confirm your address for MacBook M4 Max delivery.» How this scheme works
On the topic
Scammers pretend to support PayPal in phishing emails: «Confirm your address for MacBook M4 Max delivery». How this scheme works
In Ukraine, criminals who place phishing QR codes in public places have become more active again: here are some tips on how to protect your money from scammers
In Ukraine, criminals are again active in placing phishing QR codes in public places: here are some tips on how to protect your money from scammers
On the topic
In Ukraine, criminals are again active in placing phishing QR codes in public places: here are some tips on how to protect your money from scammers
Підключай Megogo зі знижками за акційними тарифами.

від 99 гривень на місяць

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.