Bitcoin Forum
May 05, 2024, 10:20:01 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: campbx phishing attack?  (Read 3391 times)
inBitweTrust (OP)
Hero Member
*****
Offline Offline

Activity: 658
Merit: 501



View Profile
December 19, 2013, 02:36:19 PM
 #1

One of my friends just got an email which looks like a phishing attack. Please don't follow its instructions or go to the domain in the email unless you know how to do this securely. Did anybody else just get this?

Support <amacknnia@job4u.com>


Hello,
Following a hack our domain name (campbx. Com) we ask you no more on this url you connect Now please you connect you only on http://campbx.eu

Thank you to immediatly checked the balance of your account, contact us if you suspect withdrawal was made last last 6 hours



Support CampBX


here is the domain whois...

Registrant:
   NOT DISCLOSED!
   Visit www.eurid.eu for webbased whois.

Reseller:

Technical:
   Name:   Klaba Octave
   Organisation:   OVH
   Language:   fr
   Phone:   +33.899701761
   Fax:   +33.320200958
   Email:   support@ovh.com

Registrar:
   Name:    OVH SAS
   Website: www.ovh.com/

Name servers:
   dns200.anycast.me
   ns200.anycast.me

1714947601
Hero Member
*
Offline Offline

Posts: 1714947601

View Profile Personal Message (Offline)

Ignore
1714947601
Reply with quote  #2

1714947601
Report to moderator
1714947601
Hero Member
*
Offline Offline

Posts: 1714947601

View Profile Personal Message (Offline)

Ignore
1714947601
Reply with quote  #2

1714947601
Report to moderator
1714947601
Hero Member
*
Offline Offline

Posts: 1714947601

View Profile Personal Message (Offline)

Ignore
1714947601
Reply with quote  #2

1714947601
Report to moderator
There are several different types of Bitcoin clients. The most secure are full nodes like Bitcoin Core, but full nodes are more resource-heavy, and they must do a lengthy initial syncing process. As a result, lightweight clients with somewhat less security are commonly used.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714947601
Hero Member
*
Offline Offline

Posts: 1714947601

View Profile Personal Message (Offline)

Ignore
1714947601
Reply with quote  #2

1714947601
Report to moderator
1714947601
Hero Member
*
Offline Offline

Posts: 1714947601

View Profile Personal Message (Offline)

Ignore
1714947601
Reply with quote  #2

1714947601
Report to moderator
1714947601
Hero Member
*
Offline Offline

Posts: 1714947601

View Profile Personal Message (Offline)

Ignore
1714947601
Reply with quote  #2

1714947601
Report to moderator
Keefe
Hero Member
*****
Offline Offline

Activity: 681
Merit: 500


View Profile
December 19, 2013, 03:34:09 PM
 #2

Someone I know got this also. Did CampBX's email list get leaked?

David Rabahy
Hero Member
*****
Offline Offline

Activity: 709
Merit: 501



View Profile
December 19, 2013, 03:54:46 PM
 #3

I just got the following; from a suspect domain, not address to me appropriately, terrible syntax and grammar -> phishing.

-----Original Message-----
From: Dzach [mailto:amacodisuf@contractor.com]
Sent: Thursday, December 19, 2013 10:42 AM
To: Administrator
Cc: AOL Users; Webmaster
Subject: CampBX security update

Hello,
Following a hack our domain name (campbx. Com) we ask you no more on this url you connect Now please you connect you only on http://campbx.eu

Thank you to immediatly checked the balance of your account, contact us if you suspect withdrawal was made last last 6 hours

Support CampBX
sharted
Full Member
***
Offline Offline

Activity: 210
Merit: 101



View Profile
December 19, 2013, 03:59:43 PM
 #4

Yeah just got the same one:

Mrsjunegordon <amacsuju@london.com>
   
3:55 PM (1 minute ago)
      
to Postmaster
Why is this message in Spam? It's similar to messages that were detected by our spam filters.  Learn more
Hello,
Following a hack our domain name (campbx. Com) we ask you no more on this
url you connect
Now please you connect you only on http://campbx.eu

Thank you to immediatly checked the balance of your account,
contact us if you suspect withdrawal was made last last 6 hours



Support CampBX

notice the cambc. Com, obviously a complete retard with the intellect of a goldfish.

Edit: I used the "report phishing" option in Gmail and I suggest others do the same so the user gets shut down quicker

TransAtlantic
Full Member
***
Offline Offline

Activity: 138
Merit: 100


View Profile
December 19, 2013, 04:03:14 PM
 #5

I also have received that email.  

It was coming from "amacojxy@contractor.com", which looks very suspicious to me.  (It all looks like a phishing attack.)

From the email header:

Return-path: <amacojxy@contractor.com>
Received: from [37.218.165.55] (port=10935 helo=contractor.com)

contractor.com  is a domain name registered through GoDaddy in 1999, and hosted at GoDaddy - it doesn't look to be related to CampBX

The IP address the email came from (37.218.165.55) is from Kyrgyzstan.

So that's clearly a phishing attempt.


However, there is an important twist to this plot:

I have received that email to an email address which I used _only_ for CampBX.  (I use distinct email addresses for distinct services/companies, e.g.  "campbx-myusername@mydomain.com"  I do that to track the sources of spam, and to block a specific email address when I start receiving spam through it.)
Only me and CampBX knew that this email address existed.

So CampBX customer's email list _was_ compromised.

It would be great to have a reply or a statement from CampBX regarding that.
Anyone?
Jcw188
Hero Member
*****
Offline Offline

Activity: 546
Merit: 500


Carpe Diem


View Profile
December 19, 2013, 05:22:32 PM
 #6

I also have received that email.  

It was coming from "amacojxy@contractor.com", which looks very suspicious to me.  (It all looks like a phishing attack.)

From the email header:

Return-path: <amacojxy@contractor.com>
Received: from [37.218.165.55] (port=10935 helo=contractor.com)

contractor.com  is a domain name registered through GoDaddy in 1999, and hosted at GoDaddy - it doesn't look to be related to CampBX

The IP address the email came from (37.218.165.55) is from Kyrgyzstan.

So that's clearly a phishing attempt.


However, there is an important twist to this plot:

I have received that email to an email address which I used _only_ for CampBX.  (I use distinct email addresses for distinct services/companies, e.g.  "campbx-myusername@mydomain.com"  I do that to track the sources of spam, and to block a specific email address when I start receiving spam through it.)
Only me and CampBX knew that this email address existed.

So CampBX customer's email list _was_ compromised.

It would be great to have a reply or a statement from CampBX regarding that.
Anyone?

Wow.  I recently stopped using campbx because SOMETHING is going on there, with all the delays in funding and withdrawals.  Now this.  And frankly, I wouldn't expect CampBX to address this until they feel like it, maybe in a few days after dumb people start complaining that their accts were drained.



████▄██████████▄
███▄████████████
▄███▀
████
████
████
▀███▄
███▀████████████
████▀██████████▀


▄██████████▄
████████████
███████████▀███▄
████████████████
████████████████
████████████████
▀███▄███████████
████████████████
████▀██████████▀


▄██▄█████████▄██▄
▀████▄█████▄████▀
▀████▄▄████▀
███████████
▄███▀█████▀███▄
█████████████████
█████████████████
█████████████████
▀███████████████▀


▄███████████████▄
█████████████████
████▀███▀██████▀
███████▄█████▀
████▄▄██████████▄
▀▀██████▀███████
▄██████▄███▄████
█████▀██████████
▀██▀███▀████████▀


████▄███████████
████████████████
▄███▀███████████
███████████████
██████████████
████████████████
███████████▄███▀
████████████
▀██████████▀
████████
██
██
██
██
██
██
██
██




██
██
██
██
██

██
██
██
████████
|
.
Listed
on
BINANCE
KUCOIN
Gate.io
|
mollison
Full Member
***
Offline Offline

Activity: 157
Merit: 100



View Profile
December 19, 2013, 05:43:16 PM
 #7

I got it too.

I am really glad that CampBX never had any bank account info, unlike Coinbase.

Looking forward to hearing more info about this as it is revealed, particularly a response from CampBX.
mollison
Full Member
***
Offline Offline

Activity: 157
Merit: 100



View Profile
December 19, 2013, 05:49:15 PM
 #8

I submitted a high-priority ticket to their Helpdesk system and linked them to this thread.

I, for one, will not be logging in to CampBX until/unless they provide more information.

Don't get me wrong, they have been a great service in the past for me, no problems ever.
not.you
Legendary
*
Offline Offline

Activity: 1726
Merit: 1018


View Profile
December 19, 2013, 06:25:18 PM
 #9



However, there is an important twist to this plot:

I have received that email to an email address which I used _only_ for CampBX.  (I use distinct email addresses for distinct services/companies, e.g.  "campbx-myusername@mydomain.com"  I do that to track the sources of spam, and to block a specific email address when I start receiving spam through it.)
Only me and CampBX knew that this email address existed.

So CampBX customer's email list _was_ compromised.

It would be great to have a reply or a statement from CampBX regarding that.
Anyone?

The thick plottens!

I hope this doesn't mean I won't get my BTC back from that black hole.

Edit: found the same email in my spam folder
toastedPotRoast
Newbie
*
Offline Offline

Activity: 13
Merit: 0


View Profile
December 19, 2013, 07:07:58 PM
 #10

Got one too! Except from a different email address.

Sent from Daniel ayoder <amacomvexyx@europe.com>


Quote
Hello,
Following a hack our domain name (campbx. Com) we ask you no more on this
url you connect
Now please you connect you only on http://campbx.eu

Thank you to immediatly checked the balance of your account,
contact us if you suspect withdrawal was made last last 6 hours



Support CampBX

Jcw188
Hero Member
*****
Offline Offline

Activity: 546
Merit: 500


Carpe Diem


View Profile
December 19, 2013, 07:24:53 PM
 #11

Thank God I got my funds out of there recently.  I can just see those jerks saying "oh you were hacked, sorry your funds are gone."  I mean, why no response yet from CampBX?  I'm sure they've received hundreds of complaints.



████▄██████████▄
███▄████████████
▄███▀
████
████
████
▀███▄
███▀████████████
████▀██████████▀


▄██████████▄
████████████
███████████▀███▄
████████████████
████████████████
████████████████
▀███▄███████████
████████████████
████▀██████████▀


▄██▄█████████▄██▄
▀████▄█████▄████▀
▀████▄▄████▀
███████████
▄███▀█████▀███▄
█████████████████
█████████████████
█████████████████
▀███████████████▀


▄███████████████▄
█████████████████
████▀███▀██████▀
███████▄█████▀
████▄▄██████████▄
▀▀██████▀███████
▄██████▄███▄████
█████▀██████████
▀██▀███▀████████▀


████▄███████████
████████████████
▄███▀███████████
███████████████
██████████████
████████████████
███████████▄███▀
████████████
▀██████████▀
████████
██
██
██
██
██
██
██
██




██
██
██
██
██

██
██
██
████████
|
.
Listed
on
BINANCE
KUCOIN
Gate.io
|
bittulip
Newbie
*
Offline Offline

Activity: 11
Merit: 0


View Profile
December 20, 2013, 01:23:21 AM
 #12


However, there is an important twist to this plot:

I have received that email to an email address which I used _only_ for CampBX.  (I use distinct email addresses for distinct services/companies, e.g.  "campbx-myusername@mydomain.com"  I do that to track the sources of spam, and to block a specific email address when I start receiving spam through it.)
Only me and CampBX knew that this email address existed.

So CampBX customer's email list _was_ compromised.



I can confirm this. I also use a unique email with CampBX, and I got the phishing email too.  Customer data is compromised.
Ridicuss
Sr. Member
****
Offline Offline

Activity: 336
Merit: 250



View Profile
December 20, 2013, 01:43:06 AM
 #13

I did not get anything like this today. Maybe they just haven't worked their way to my e-mail addy yet.

Man, I wish I could change my avatar!
quone17
Full Member
***
Offline Offline

Activity: 224
Merit: 104


View Profile WWW
December 20, 2013, 04:51:35 AM
 #14


However, there is an important twist to this plot:

I have received that email to an email address which I used _only_ for CampBX.  (I use distinct email addresses for distinct services/companies, e.g.  "campbx-myusername@mydomain.com"  I do that to track the sources of spam, and to block a specific email address when I start receiving spam through it.)
Only me and CampBX knew that this email address existed.

So CampBX customer's email list _was_ compromised.



I can confirm this. I also use a unique email with CampBX, and I got the phishing email too.  Customer data is compromised.

This is unbelievable. Customer data compromised and campbx doesn't say anything?  Wtf. Anyone have a response from campbx yet?

Bitcoin Exchange Guide- List of the Top Bitcoin Exchanges, Find Places to Buy, Sell and Trade Bitcoins.
mollison
Full Member
***
Offline Offline

Activity: 157
Merit: 100



View Profile
December 20, 2013, 07:39:51 AM
 #15

This is unbelievable. Customer data compromised and campbx doesn't say anything?  Wtf. Anyone have a response from campbx yet?

Yes. Got one about 2 hours ago. See text below.

Quote
Please do not reply or share your login details to any other trading platforms other than https://campbx.com (and https://testnet.campbx.com) to protect your funds. You may see emails generated from phishing websites like campbx.be and cambx.eu. We are trying to investigate for the same.

So no specifics but we can infer that they're aware of and acknowledge that phishing is going on.
mufa23
Legendary
*
Offline Offline

Activity: 1022
Merit: 1001


I'd fight Gandhi.


View Profile
December 20, 2013, 07:45:34 AM
 #16

Have any of you guys that got the phising email (which I assume is pretty much everyone?) ever used their helpdesk/ticket system? I'm curious if emails were leaked from the campbx.kayako.com

Positive rep with: pekv2, AzN1337c0d3r, Vince Torres, underworld07, Chimsley, omegaaf, Bogart, Gleason, SuperTramp, John K. and guitarplinker
not.you
Legendary
*
Offline Offline

Activity: 1726
Merit: 1018


View Profile
December 20, 2013, 01:10:29 PM
 #17

Have any of you guys that got the phising email (which I assume is pretty much everyone?) ever used their helpdesk/ticket system? I'm curious if emails were leaked from the campbx.kayako.com

Yes on both for me.
sumantso
Legendary
*
Offline Offline

Activity: 1050
Merit: 1000



View Profile
December 20, 2013, 01:42:50 PM
 #18

Someone I know got this also. Did CampBX's email list get leaked?

I don't think its campx list. I received the mail too and I never went to that site.

Maybe they are mailing to BTCtalk list?

TransAtlantic
Full Member
***
Offline Offline

Activity: 138
Merit: 100


View Profile
December 20, 2013, 04:42:12 PM
 #19

After informing CampBX that their customer's data has been compromised, I received that useless reply from CampBX's support:

Quote
Dear XXXX,
Please do not reply or share your login details to any other trading platforms other than https://campbx.com (and https://testnet.campbx.com) to protect your funds. You may see emails generated from phishing websites like campbx.be and cambx.eu. We are trying to investigate for the same.

Thank you,
CampBX Support

*** Please check the correct domain of CampBX Bitcoin Trading Platform(https://campbx.com) before login into the CampBX to protect your funds from various phishing websites.


It is unfortunate that, instead of acknowledging that they might have had an issue, and be plainly transparent about it, their support simply answers ready-made replies that fail to address the critical issue at hand, and seem to deny that there is any serious issue.

As if telling me to be careful where I login would be a solution to the fact that they have leaked my data to fraudsters/scammers!!
bittulip
Newbie
*
Offline Offline

Activity: 11
Merit: 0


View Profile
December 20, 2013, 05:00:07 PM
 #20

Have any of you guys that got the phising email (which I assume is pretty much everyone?) ever used their helpdesk/ticket system? I'm curious if emails were leaked from the campbx.kayako.com

I received the phishing email and I never used the help desk system.  And I never used that particular email address on any site but campbx.com.

edit: Now that I think of it, Dwolla would know what email address I used with campbx, since I used them to transfer money there.  But I haven't heard anything about Dwolla being compromised.
Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!