|
Title: Dwolla E-mails Post by: BGL on July 18, 2011, 06:42:03 PM So who got em?
############################### ############################### Dwolla July 18, 2011 | Published by DWOLLA. Good afternoon Dwolla user! It's come to our attention that one of the merchants whom you have done business with has had some security issues. While we have not seen anything like this effecting Dwolla users directly, we suggest taking a moment to change your password to alleviate any concerns. To reset your password simply follow these steps: 1. Login here 2. Click Settings 3. Click Change Password If you have any questions at all please do not hesitate to respond to this e-mail. Thank you for your time. - Dwolla Team 2 facebooktwitterblog You are receiving this newsletter because you have signed up for a Dwolla account, an invitation, or have direct communication with one of our employees. Dwolla Corp. 1312 Locust, Suite 204. Des Moines IA 50309 Support@dwolla.org - Phone. 515.462.0047 Sent to <removed> Unsubscribe | Update Profile | Forward to a Friend Sent to <removed> — why did I get this? unsubscribe from this list | update subscription preferences Dwolla · 206 6th Ave. E. · Suite 1104 · Des Moines, IA 50309 ############################### ############################### Title: Re: Dwolla E-mails Post by: hawks5999 on July 18, 2011, 06:42:42 PM me
Title: Re: Dwolla E-mails Post by: phorensic on July 18, 2011, 06:45:02 PM I got this e-mail too. Dwolla does business with many other types of industries, not just bitcoin. So, did a bitcoin related site get hacked or did some other obscure website get hacked?
Title: Re: Dwolla E-mails Post by: enmaku on July 18, 2011, 06:45:09 PM I got one.
Oh, and only in Iowa would they actually name a street after a crop-destroying pest: Quote Dwolla Corp. 1312 Locust, Suite 204. Des Moines IA 50309 Title: Re: Dwolla E-mails Post by: AtlasONo on July 18, 2011, 06:48:32 PM I
"effecting" Title: Re: Dwolla E-mails Post by: BookofNick on July 18, 2011, 06:49:47 PM They might figure that some people use the same password for both Dwolla and Mt Gox. It's probably just a precaution.
Title: Re: Dwolla E-mails Post by: edd on July 18, 2011, 06:51:27 PM Quote You are receiving this newsletter because you have signed up for a Dwolla account, an invitation, or have direct communication with one of our employees. I'm sure everyone who has even a remote chance of being affected got one of these emails. I doubt it's related to bitcoin at all. Title: Re: Dwolla E-mails Post by: hmblm1245 on July 18, 2011, 06:52:47 PM I as well
Title: Re: Dwolla E-mails Post by: phorensic on July 18, 2011, 06:55:04 PM They might figure that some people use the same password for both Dwolla and Mt Gox. It's probably just a precaution. Aren't they a little behind on this news though??Title: Re: Dwolla E-mails Post by: nexticeage on July 18, 2011, 07:11:07 PM I got one and I've only ever used Dwolla for Mt. Gox.
Title: Re: Dwolla E-mails Post by: phorensic on July 18, 2011, 07:17:15 PM Edit: I'm stupid, "one of the merchants whom you have done business with" Title: Re: Dwolla E-mails Post by: ErgoOne on July 18, 2011, 07:20:08 PM I have a Dwolla account which I used to transfer money to Mt. Gox a couple of weeks ago. I have not got one of these emails. So it's likely that this is not related to Mt. Gox, or is related only to those who initiated transfers to Mt. Gox before the accounts were re-verified.
Title: Re: Dwolla E-mails Post by: optionstalker on July 18, 2011, 07:38:24 PM I received this email too. I've only ever used Dwolla for Mt. Gox and exchangebitcoins.com.
Title: Re: Dwolla E-mails Post by: Stephen Gornick on July 18, 2011, 07:49:25 PM They might figure that some people use the same password for both Dwolla and Mt Gox. It's probably just a precaution. I'm curious as to what prompted this. I do notice that their "reset PIN" page - http://www.dwolla.com/error.aspx?aspxerrorpath=/forgot_pin.aspx Title: Re: Dwolla E-mails Post by: opticbit on July 18, 2011, 07:50:53 PM Got one.
Title: Re: Dwolla E-mails Post by: KMBTC11 on July 18, 2011, 07:57:01 PM I got one and I've only ever used Dwolla for Mt. Gox. Same here. I got the email and have only used it with MtGox and my bank. Title: Re: Dwolla E-mails Post by: geek-trader on July 18, 2011, 07:57:50 PM I got one, and realized my existing Dwolla password was horribly weak, so I changed to something much better.
Title: Re: Dwolla E-mails Post by: error on July 18, 2011, 08:11:58 PM Ha. I changed my password, and the new password they emailed me doesn't work. Good job!
Title: Re: Dwolla E-mails Post by: haploid23 on July 18, 2011, 08:16:54 PM i got the email too, but i already changed my password to a much stronger one ever since the mtgox database leak
Title: Re: Dwolla E-mails Post by: zybron on July 18, 2011, 08:20:25 PM I got the same email and realized that the 'Login here' link doesn't point to dwolla.com or dwolla.org. It may be on the up-and-up, but certainly looks like a phishing email. Be careful.
Title: Re: Dwolla E-mails Post by: jimrandomh on July 18, 2011, 08:24:39 PM Definitely phishing. If you reset your password by following the link in this email, change it again if you can, then check your history and notify Dwolla immediately. Do not ever follow links from emails that supposedly lead to financial institutions.
Title: Re: Dwolla E-mails Post by: error on July 18, 2011, 08:26:08 PM Definitely phishing. If you reset your password by following the link in this email, change it again if you can, then check your history and notify Dwolla immediately. Do not ever follow links from emails that supposedly lead to financial institutions. Some people got a phishing email, maybe. The one I got was legit. The link redirected to https://www.dwolla.com/default.aspx. Not that I used it, but I did check it. Title: Re: Dwolla E-mails Post by: jimrandomh on July 18, 2011, 08:29:45 PM Actually, hmm - I just checked where the link actually went, and it was a 302 redirect that does land at a Dwolla https page. So maybe it was legit. I still don't recommend following links like that; if you do reset your password, you should do so by typing https://www.dwolla.com into the address bar directly.
Title: Re: Dwolla E-mails Post by: dacoinminster on July 18, 2011, 09:33:10 PM I assumed it was phishing and actually reported it to their phishing report email address. It seemed impossible that it was really from Dwolla since the URL in the email was not pointing to dwolla.com
I can't imagine why they would set up a redirect like that. Maybe the phishing attempt was reported to the hosting company and they neutralized it by redirecting to the dwolla site? Title: Re: Dwolla E-mails Post by: error on July 18, 2011, 09:34:08 PM I assumed it was phishing and actually reported it to their phishing report email address. It seemed impossible that it was really from Dwolla since the URL in the email was not pointing to dwolla.com I can't imagine why they would set up a redirect like that. Maybe the phishing attempt was reported to the hosting company and they neutralized it by redirecting to the dwolla site? Nope, they mass mailed everyone via MailChimp instead of directly. Title: Re: Dwolla E-mails Post by: Jered Kenna (TradeHill) on July 18, 2011, 11:30:34 PM They might figure that some people use the same password for both Dwolla and Mt Gox. It's probably just a precaution. We were able to identify and catch two dwolla hackers last week. The hackers had used the leaked Mt.Gox passwords. Title: Re: Dwolla E-mails Post by: TKE406 on July 19, 2011, 02:06:30 AM The e-mail was sent via "mail3.uk1.mcsv.co.uk "
So... definitely suspicious Title: Re: Dwolla E-mails Post by: error on July 19, 2011, 03:11:39 AM The e-mail was sent via "mail3.uk1.mcsv.co.uk " So... definitely suspicious Didn't you look it up? [Querying whois.nic.uk] [whois.nic.uk] Domain name: mcsv.co.uk Registrant: MailChimp.com Registrant type: Unknown Registrant's address: 512 Means St. Suite 404 Atlanta GA 30 318 United States Registered through: GoDaddy.com, Inc. URL: http://www.godaddy.com Registrar: Key-Systems GmbH [Tag = KEY-SYSTEMS-DE] URL: http://www.Key-Systems.net Relevant dates: Registered on: 08-Mar-2010 Renewal date: 08-Mar-2012 Last updated: 02-Jun-2010 Registration status: Registered until renewal date. Name servers: udns1.ultradns.net udns2.ultradns.net WHOIS lookup made at 04:11:06 19-Jul-2011 -- This WHOIS information is provided for free by Nominet UK the central registry for .uk domain names. This information and the .uk WHOIS are: Copyright Nominet UK 1996 - 2011. You may not access the .uk WHOIS or use any data from it except as permitted by the terms of use available in full at http://www.nominet.org.uk/whois, which includes restrictions on: (A) use of the data for advertising, or its repackaging, recompilation, redistribution or reuse (B) obscuring, removing or hiding any or all of this notice and (C) exceeding query rate or volume limits. The data is provided on an 'as-is' basis and may lag behind the register. Access may be withdrawn or restricted at any time. Title: Re: Dwolla E-mails Post by: Denicen on July 19, 2011, 05:44:58 AM I got this email from dwolla. My email linked to mtgox was not the same as the one that I had linked to dwolla, so that made me think that it probably wasn't a phishing attempt.
It still looks really suspect though. Title: Re: Dwolla E-mails Post by: error on July 19, 2011, 05:48:58 AM I sent a support ticket to dwolla and they sorted out my password issue. Turns out you can't copy/paste your new password from their email because some goofy formatting information gets inserted as well. Oh, and the email from MailChimp was legitimate, if ill-advised.
Title: Re: Dwolla E-mails Post by: DrKennethNoisewater on July 19, 2011, 07:18:51 AM I got it.
Title: Re: Dwolla E-mails Post by: MagicalTux on July 19, 2011, 08:55:00 AM I got it too
Title: Re: Dwolla E-mails Post by: geek-trader on July 19, 2011, 04:42:41 PM I sent a support email to Dwolla and they confirmed they did indeed send that email.
Title: Re: Dwolla E-mails Post by: gnaget on July 19, 2011, 04:43:32 PM I "effecting" Stop being so pedantic... (first thing I noticed too) |