@inerati@livgorton Hi @inerati,
If you have time, I'd be happy to review the issues you're facing. Feel free to share them with me via DM or email just let me know what works best for you.
@sysarmy@nerdearla We apologize for the inconvenience caused by this service disruption and appreciate your patience
The incident has been resolved since.
We had publish a post mortem regarding the incident
https://t.co/Na9upFnXw7
@runixo We apologize for the inconvenience caused by this service disruption and appreciate your patience
The incident has been resolved since.
We had publish a post mortem regarding the incident, and monitor the platform continuously.
https://t.co/Na9upFnXw7
Ce problème n'est pas lié au serveur de messagerie. Une fonctionnalité, destinée aux organisateurs d'événements pour confirmer les inscriptions, est détournée à des fins malveillantes. Cela arrive fréquemment, en particulier sur d'autres plateformes permettant l'envoi d'emails. C'est cependant la première fois qu'une personne paie un abonnement de plusieurs milliers d'euros pour envoyer du spam. Nous renforçons donc les contrôles.
Bonjour,
Nous avons identifié une personne ayant créé un faux événement en souscrivant au plan Starter, dans le but d'envoyer un email de SPAM lié à Coinbase. Actuellement, nous sommes particulièrement ciblés par ce type d'attaques, malgré les mesures de vérification d'identité (KYC) que nous avons mises en place. Nous renforçons nos contrôles pour limiter ces abus.
@FIP_Crypto We had change few rules too as prevention of further similar attack. Let me know if you received similar things but as mentioned we didn't spot new activity over this on our side
@FIP_Crypto We didn't spot new sending since we lock the original account. I check and ~6 email was failed because of queued mechanism (Too old) in our email provider. We cleaned that too. Seem more a residual from the previous attempt than new email.
@0xgunboats@Swapcard FYI, we didn't see further sending or attempt since few days.
It's related to an event organiser that re-used the same password from another platform or weak-password, we had disabled their account and features.
Thanks for your report.
@0xgunboats@Swapcard Hi
We spot a credential stuffing attack, i confirm it's not related to our services and our security. They targeting a originally legitimate account for sending this. We took proper action disabling the account sending such email and ensuring of no further one
@Mail_Gun@marcaureleb@Swapcard Despite we already forcing customers/users to use complexe password, using MFA, prevent weak and most common password; limit attempt...; it's seem still not enough ! Working on adding more things👌
@FIP_Crypto Just to be cristal clear on this; it's related to an event organiser that re-used the same password from another platform or weak-password, we had disabled their account and features so we prevent further email sending like this.
@WeROneLiving@Swapcard Obviously not pleasant, sorry for this. We stopped it, as soon we spotted it.
It's related to an event organiser that re-used the same password from another platform or weak-password, we had disabled their account and features.
@Mail_Gun@marcaureleb@Swapcard We did it @Mail_Gun , just to be cristal clear on this,
It's related to an event organiser that re-used the same password from another platform or weak-password, we had disabled their account and features.
@marcaureleb@Mail_Gun@Swapcard Hi,
We spot a credential stuffing attack, i confirm it's not related to our services and our security. They targeting a originally legitimate account with emailing feature enabled.
We took proper action disabling the account sending such email and ensuring of no further one.