Has cytomic.com been hacked
- KVRAF
- 5256 posts since 16 May, 2002 from Brisbane , Australia
Just got emails that my account email and password have been changed. My login credentials are no longer recognized.
Last edited by morelia on Tue Sep 10, 2024 6:52 am, edited 1 time in total.
Intel Core i7 8700K, 16gb, Windows 10 Pro, Focusrite Scarlet 6i6
- Banned
- 197 posts since 22 Aug, 2023
are you able to login since ?
**dark music for dark lovers**
- KVRAF
- Topic Starter
- 5256 posts since 16 May, 2002 from Brisbane , Australia
No, I am not.
Intel Core i7 8700K, 16gb, Windows 10 Pro, Focusrite Scarlet 6i6
- Banned
- 197 posts since 22 Aug, 2023
..if you 're using the same password for all the other account you have , you must change it.
i have just done a very simple check on cytomic website ,the CMS used is very easy to find.
i think if the website has been hacked it would be really easy to find who did it and recover your account.
I'm not working for cytomic but from what i know if the CMS was not updated it can be a serious treath
Keep the mail you receveid et try to contact the cytomic guy explaining the situation.
i have just done a very simple check on cytomic website ,the CMS used is very easy to find.
i think if the website has been hacked it would be really easy to find who did it and recover your account.
I'm not working for cytomic but from what i know if the CMS was not updated it can be a serious treath
Keep the mail you receveid et try to contact the cytomic guy explaining the situation.
**dark music for dark lovers**
- Beware the Quoth
- 35434 posts since 4 Sep, 2001 from R'lyeh Oceanic Amusement Park and Funfair
Andy has an account at KVR, PM him.
An idiot on Set Theory:
"In some cases there is an object called red that contains everything that is red. In much the same way a pot is a plate."
"In some cases there is an object called red that contains everything that is red. In much the same way a pot is a plate."
-
- KVRAF
- 6375 posts since 8 Jun, 2009
I didn't get an email from Cytomic about a changed password (well, I did just now as I just beefed mine up a bit).
The email says contact support if this happens: and that's your best bet other than a PM here to Andy.
And I'd suggest checking what other sites you've used that password on because this sounds more like someone hacked one of your accounts elsewhere and is trying out that password at other places that has that email or account name.
The email says contact support if this happens: and that's your best bet other than a PM here to Andy.
And I'd suggest checking what other sites you've used that password on because this sounds more like someone hacked one of your accounts elsewhere and is trying out that password at other places that has that email or account name.
- Banned
- 197 posts since 22 Aug, 2023
I think you re right , but i would recommend to everybody to change their password if the database has been stole ,he could be the first to notice someone stole his account.Gamma-UT wrote: Tue Sep 10, 2024 9:00 am I didn't get an email from Cytomic about a changed password (well, I did just now as I just beefed mine up a bit).
The email says contact support if this happens: and that's your best bet other than a PM here to Andy.
And I'd suggest checking what other sites you've used that password on because this sounds more like someone hacked one of your accounts elsewhere and is trying out that password at other places that has that email or account name.
**dark music for dark lovers**
-
- KVRAF
- 6375 posts since 8 Jun, 2009
Good point.gelly-vapor wrote: Tue Sep 10, 2024 9:23 am I think you re right , but i would recommend to everybody to change their password if the database has been stole ,he could be the first to notice someone stole his account.
- Banned
- 197 posts since 22 Aug, 2023
If Andy agree i could perform a pentest for free.[just pm me]
**dark music for dark lovers**
- KVRAF
- Topic Starter
- 5256 posts since 16 May, 2002 from Brisbane , Australia
It's a very unique password. I emailed Andy within minutes of confirming the emails were correct, and that someone has my account. Just posted here to see how widespread it might be.
From support:
Thanks for letting me know promptly about this. No harm done since they haven't authorised anything.
From support:
Thanks for letting me know promptly about this. No harm done since they haven't authorised anything.
Intel Core i7 8700K, 16gb, Windows 10 Pro, Focusrite Scarlet 6i6
- Banned
- 197 posts since 22 Aug, 2023
good ending for youmorelia wrote: Tue Sep 10, 2024 7:26 pm It's a very unique password. I emailed Andy within minutes of confirming the emails were correct, and that someone has my account. Just posted here to see how widespread it might be.
From support:
Thanks for letting me know promptly about this. No harm done since they haven't authorised anything.
**dark music for dark lovers**
- KVRAF
- 2819 posts since 3 Dec, 2008
Only one person has reported to me that their Cytomic web account login was changed. Anyone can enter an email into our webpage and get a password reset link sent to their email account, so if someone's email account is compromised, then so is their Cytomic web account, since we don't use 2FA. I recommend you change your email account password and enable 2FA on that as soon as possible.morelia wrote: Tue Sep 10, 2024 7:26 pm It's a very unique password. I emailed Andy within minutes of confirming the emails were correct, and that someone has my account. Just posted here to see how widespread it might be.
From support:
Thanks for letting me know promptly about this. No harm done since they haven't authorised anything.
PS: I'll report back here if there are any other reports of un-authorised account access, but this is the only one thus far, and the cause is still unknown. I'm using siteground to host my webpage, and they have security checks all the time which are all clear.
The Glue, The Drop, The Scream - www.cytomic.com
- KVRAF
- 2819 posts since 3 Dec, 2008
Did you receive the password reset email first? If someone has access to your email account login they can then use that link to login to your account, then change the password, and then change the email on the account - which will prevent you from changing the password.morelia wrote: Tue Sep 10, 2024 6:32 am Just got emails that my account email and password have been changed. My login credentials are no longer recognized.
The Glue, The Drop, The Scream - www.cytomic.com
- KVRAF
- Topic Starter
- 5256 posts since 16 May, 2002 from Brisbane , Australia
I can barely get into my email with the multifactor authorisation process. I can't fathom that someone has access to my email. I'm no expert in these matters though.andy-cytomic wrote: Wed Sep 11, 2024 1:51 pmDid you receive the password reset email first? If someone has access to your email account login they can then use that link to login to your account, then change the password, and then change the email on the account - which will prevent you from changing the password.morelia wrote: Tue Sep 10, 2024 6:32 am Just got emails that my account email and password have been changed. My login credentials are no longer recognized.
Yes, the password email first and the email change less than a minute after.
Intel Core i7 8700K, 16gb, Windows 10 Pro, Focusrite Scarlet 6i6
-
- KVRAF
- 5200 posts since 17 Aug, 2004
If that is the case then I suggest you change your email password and all passwords that you have at any endpoint. And no this time I am not making fun of the situation or being sarcastic (contrary to my usual posting). Believe it or not, I am running a business that deals with e-commerce sites and I fix security errors for companies.morelia wrote: Thu Sep 12, 2024 7:56 pm
Yes, the password email first and the email change less than a minute after.
It sounds as if someone had or still has access to your email inbox. It is not the cytomic website causing problems. If it was, this problem would be much more widespread and we would see more people reporting the same thing.
Because the password email came first into your inbox this means someone "knew" in advance what to enter on the Cytomic website when utilizing the standard password reset function (this exists on pretty much any WordPress website) in order to wait for the email to arrive in your inbox and then.
More likely someone accessed your email inbox and then went looking for "orders" so that they can obtain your purchasing data from your history. That is what these people do when they enter your mailbox they are trying to see the history of your purchases and obtain details. Someone was able to find that you ordered at cytomic so then he/she tried and successfully finished the password reset. My guess is that they wanted to see your cytomic account in order to either find even more data on you or to sell your plugin to someone else and get some money that way.
I wholeheartedly suggest you in the future to use something like Bitwarden - free, open source (unbiased security audits) and it also has a nice password creator for you. You just have to keep one super duper tedious password.
Also, you can check your mailbox here but the list is not updated daily:
https://haveibeenpwned.com/
https://haveibeenpwned.com/Passwords
Good luck.