Bitcoin Forum
May 06, 2024, 12:26:09 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [Warning] New Phishing email "MTGox Security Update Notification"  (Read 1180 times)
ataranlen (OP)
Hero Member
*****
Offline Offline

Activity: 846
Merit: 1000


The One and Only


View Profile WWW
June 25, 2012, 09:57:39 PM
Last edit: July 05, 2012, 05:21:40 PM by ataranlen
 #1

Received a fairly obvious phishing email a few minutes ago.

DO NOT CLICK ANY LINKS IN THIS EMAIL!
DO NOT submit your information on any site this email links to!

Remember, If the address bar does not show MtGox.com, Do not enter your password!

If you did submit your information, change your MtGox password ASAP!
If you used the same password anywhere else- And you shouldn't have- but if you did, change those too!

https://i.imgur.com/yqBvH.png

I have forwarded this email and the full headers to abuse@hostgator.com

MineTexas.com Minecraft Server We accept Bitcoin and Dogecoin.
Deepbit on Facebook: http://www.facebook.com/pages/Deepbit/151108048294815
"Your bitcoin is secured in a way that is physically impossible for others to access, no matter for what reason, no matter how good the excuse, no matter a majority of miners, no matter what." -- Greg Maxwell
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714998369
Hero Member
*
Offline Offline

Posts: 1714998369

View Profile Personal Message (Offline)

Ignore
1714998369
Reply with quote  #2

1714998369
Report to moderator
alexmat
Full Member
***
Offline Offline

Activity: 210
Merit: 100



View Profile
June 25, 2012, 09:59:43 PM
 #2

Received it as well. Forwarded to Mt. Gox support.
phorensic
Hero Member
*****
Offline Offline

Activity: 630
Merit: 500



View Profile
June 25, 2012, 10:13:16 PM
 #3

Yep I just got this e-mail.  Looks pretty legit until you see the link at the bottom goes to a totally different domain.  Nice try kids.
Gladamas
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


Bitcoin today is what the internet was in 1998.


View Profile
June 25, 2012, 10:14:46 PM
 #4

Wow. They didn't even try to make the domain look like MtGox.

1GLADMZ5tL4HkS6BAWPfJLeZJCDHAd9Fr3 - LQ6Zx8v7fHVBiDX5Lmhbp6oEDB7dUFjANu
GPG 0xF219D5BB3C467E12 - Litecoin Forum
sethsethseth
Sr. Member
****
Offline Offline

Activity: 257
Merit: 250


Not trusting third parties with my private keys


View Profile
June 25, 2012, 10:27:11 PM
 #5

Just got this one.  How has gmail not flagged it already....

SealsWithClubs poker room has  over 400 players online. Buy in from .01 to 60btc.      BTCSportsMatch lets you bet sports with vig free lines!  Best kept secret in bitcoin....          LocalBitcoins.com is very user-friendly now for bank transfers.  You don't have to live close to trade when in the same currency area.           
Electrum client is awesome. Try it. And please stop sending bitcoins to sites run by security newbies, or don't complain when you lose everything.
zvs
Legendary
*
Offline Offline

Activity: 1680
Merit: 1000


https://web.archive.org/web/*/nogleg.com


View Profile WWW
June 25, 2012, 10:30:33 PM
 #6

i reported it to that place in italy, where the server it directs you to is hosted at
eleuthria
Legendary
*
Offline Offline

Activity: 1750
Merit: 1007



View Profile
June 25, 2012, 10:30:53 PM
 #7

Was going to post this as well.  It's an EXTREMELY OBVIOUS phishing email even without the links.

Looks like somebody found that old DB leak from last year, since it hit the email that I used only at Gox.

RIP BTC Guild, April 2011 - June 2015
zvs
Legendary
*
Offline Offline

Activity: 1680
Merit: 1000


https://web.archive.org/web/*/nogleg.com


View Profile WWW
June 25, 2012, 10:32:09 PM
 #8

Was going to post this as well.  It's an EXTREMELY OBVIOUS phishing email even without the links.

Looks like somebody found that old DB leak from last year, since it hit the email that I used only at Gox.
i used my "main" email address on gox... still get phishing emails from that.. =((

Quote
How has gmail not flagged it already....

it got through hotmail junk filter too

bizarre
ninjarobot
Hero Member
*****
Offline Offline

Activity: 761
Merit: 500


Mine Silent, Mine Deep


View Profile
June 25, 2012, 10:33:35 PM
 #9

Yup, just received that email 10 minutes ago. Thanks for the heads-up! :)

It could be either from the MtGox db, or the perhaps Bitcoinica db that was recently compromised?

If you received it in your gmail account, please report this email as phishing (more > report phishing).
Rassah
Legendary
*
Offline Offline

Activity: 1680
Merit: 1035



View Profile WWW
June 25, 2012, 11:05:37 PM
 #10

Received, and replied with bogus password info. GGave then my real email, since they obviously already have that. I think filling their database with garbage and making them waste time finding out what works is more productive and satisfying than just deleting the email.
Gladamas
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


Bitcoin today is what the internet was in 1998.


View Profile
June 25, 2012, 11:11:45 PM
 #11

Oftentimes when I receive a suspicious email I enter the incorrect password just to see if it accepts it or not. The more sneaky phishers will say that the password is incorrect the first time and then accept it the next time you enter it in.

1GLADMZ5tL4HkS6BAWPfJLeZJCDHAd9Fr3 - LQ6Zx8v7fHVBiDX5Lmhbp6oEDB7dUFjANu
GPG 0xF219D5BB3C467E12 - Litecoin Forum
rjk
Sr. Member
****
Offline Offline

Activity: 448
Merit: 250


1ngldh


View Profile
June 25, 2012, 11:31:11 PM
 #12

Strange, it shows SPF as Hardfail, and still let it through? Usually softfail will let it through and mark it as spam, but hardfail should delete it immediately.

Mining Rig Extraordinaire - the Trenton BPX6806 18-slot PCIe backplane [PICS] Dead project is dead, all hail the coming of the mighty ASIC!
Nubarius
Sr. Member
****
Offline Offline

Activity: 310
Merit: 253


View Profile
June 26, 2012, 07:31:23 AM
 #13

Yahoo! Mail didn't flag it as spam either. If the URL link had been anything resembling a legit one I might have fallen for this.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!