Go Back  FlyerTalk Forums > Miles&Points > Airlines and Mileage Programs > British Airways | Executive Club
Reload this Page >

And so it begins — blackmail attempt following BA data theft

Community
Wiki Posts
Search

And so it begins — blackmail attempt following BA data theft

Thread Tools
 
Search this Thread
 
Old Sep 28, 2018, 9:33 am
  #91  
 
Join Date: Feb 2009
Location: YYC
Programs: BA bronze, Aeroplan peon
Posts: 4,746
Originally Posted by T8191
hmmm ... a couple of well-pwned passwords. I can see a busy weekend trying to reassign new stuff I can actually remember!
I keep a handwritten sheet of paper in my desk at home with all the passwords written down. I figure my house is much less likely to be broken into than computer traffic being intercepted, and my handwriting is a second layer of security! That, plus it would take someone quite a while to actually find that single sheet of paper in my desk!
oxtailsoup and T8191 like this.
Jagboi is offline  
Old Sep 28, 2018, 9:58 am
  #92  
FlyerTalk Evangelist
 
Join Date: Mar 2010
Location: JER
Programs: BA Gold/OWE, several MUCCI, and assorted Pensions!
Posts: 32,145
Jagboi, I use the same system, with the relevant document filed in an irrelevant location But having dragged it out yesterday, I find I have been dreadfully remiss in keeping it up to date! Indeed, it needs dozens more sites/passwords adding!!

I tend to rely on my Mac remembering passwords for me, so at least that one-click arrangement hopefully defeats key-trackers.
T8191 is offline  
Old Sep 28, 2018, 10:11 am
  #93  
 
Join Date: Apr 2002
Location: NYC
Posts: 9,122
A variation of this email is sent to millions. They may have an old password but they can't do anything with it. They are only hoping for a small % of suckers to make the payment. Best advice is to completely ignore.
erik123 is offline  
Old Sep 28, 2018, 10:13 am
  #94  
 
Join Date: Feb 2009
Location: YYC
Programs: BA bronze, Aeroplan peon
Posts: 4,746
Originally Posted by T8191
I tend to rely on my Mac remembering passwords for me, so at least that one-click arrangement hopefully defeats key-trackers.
I always keep the paper up to date, as I never know when a crash will take down the stored passwords locking me out. Probably a belt and braces approach, but it gives me comfort.
Jagboi is offline  
Old Sep 28, 2018, 10:15 am
  #95  
FlyerTalk Evangelist
 
Join Date: Mar 2010
Location: JER
Programs: BA Gold/OWE, several MUCCI, and assorted Pensions!
Posts: 32,145
Originally Posted by Jagboi
I always keep the paper up to date, as I never know when a crash will take down the stored passwords locking me out. Probably a belt and braces approach, but it gives me comfort.
The Apple Time Capsule gives me confidence to be able to restore everything to a blank Mac. Took a few hours the last time I bought a new one, though!
T8191 is offline  
Old Sep 28, 2018, 11:05 am
  #96  
 
Join Date: Nov 2004
Programs: BA GGL, LH FTL
Posts: 3,578
Thank you for this thread!

I just checked my spam folder and have received several sextortion emails for old passwords. LinkedIn and MySpace seem to be most popular.

Great fun. I feel temptation to respond and haggle them down a bit.
LCY8737 is offline  
Old Sep 28, 2018, 11:13 am
  #97  
 
Join Date: Jan 2007
Location: Canary Wharf, London
Programs: MyWaitrose, IC Spire Ambassador, Hilton Diamond & BAEC Gold
Posts: 2,685
I use Dashlane for my passwords, seems ok.

Oh, and 50 million facebook accounts now compromised. It is happening everywhere.
chistery is offline  
Old Sep 28, 2018, 11:14 am
  #98  
FlyerTalk Evangelist
 
Join Date: Mar 2010
Location: JER
Programs: BA Gold/OWE, several MUCCI, and assorted Pensions!
Posts: 32,145
My only interface with LinkedIn was in the guise of a charity Bear with his own .gmail address .... Good luck with blackmailing Teddy .
T8191 is offline  
Old Sep 28, 2018, 11:24 am
  #99  
 
Join Date: Nov 2004
Programs: BA GGL, LH FTL
Posts: 3,578
Originally Posted by T8191
My only interface with LinkedIn was in the guise of a charity Bear with his own .gmail address .... Good luck with blackmailing Teddy .
What happened to Teddy? I seem to recall he was travelling an awful lot?
LCY8737 is offline  
Old Sep 28, 2018, 11:34 am
  #100  
 
Join Date: Jun 2010
Location: London
Programs: Mucci Blue, BAEC Gold, Blockbuster Video card
Posts: 1,378
Originally Posted by T8191
My only interface with LinkedIn was in the guise of a charity Bear with his own .gmail address .... Good luck with blackmailing Teddy .
"Dear Mr T8191, we have caught you on webcam looking at 'bear_necessities.com/bear_ladies'...... please send bitcoins now or we will expose you as a bad, bad bear........."
T8191 likes this.
Pascoe is offline  
Old Sep 28, 2018, 11:39 am
  #101  
 
Join Date: Dec 2009
Location: under the flight path near Windsor
Posts: 108
Originally Posted by Passmethesickbag
Yes.
Yes, this is the problem.
This type of scam has been around for ages but, if like me, you have unique passwords for each site, you can tell which site they got the info from.
imho, BA are not remotely taking this seriously enough.
Even the stress and worry of getting an email like that is serious.
BA also appear to place zero value on the imposition of time to fix things.
Frankly, they're out of date on customer experience.
MadnessOfCrowds is offline  
Old Sep 28, 2018, 11:54 am
  #102  
 
Join Date: Sep 2015
Programs: LH SEN; BA Gold
Posts: 8,405
Originally Posted by MadnessOfCrowds
BA are not remotely taking this seriously enough.
Even the stress and worry of getting an email like that is serious.
Good IT costs money, money that could be (and currently is being) spent on one or two major IT problems per year.

Originally Posted by Pascoe
"Dear Mr T8191, we have caught you on webcam looking at 'bear_necessities.com/bear_ladies'...... please send bitcoins now or we will expose you as a bad, bad bear........."
"Sorry, I only have bearcoins"
WorldLux is offline  
Old Sep 28, 2018, 11:55 am
  #103  
FlyerTalk Evangelist
 
Join Date: Aug 2002
Location: London
Programs: Mucci. Nothing else matters.
Posts: 38,644
Originally Posted by chistery
Oh, and 50 million facebook accounts now compromised.
Are you serious? 50 million? BA's IT penny--pinching has so much more to answer for than what we knew before!
Globaliser is offline  
Old Sep 28, 2018, 12:00 pm
  #104  
FlyerTalk Evangelist
 
Join Date: Mar 2010
Location: JER
Programs: BA Gold/OWE, several MUCCI, and assorted Pensions!
Posts: 32,145
Originally Posted by LCY8737


What happened to Teddy? I seem to recall he was travelling an awful lot?
That side of the Charity, Holidays4Heroes has closed down, as The Bears travels really didn’t justify the effort involved in terms of donations. But their adventures are still there on the website under “News and Updates”, and highlighted on “The Bears/Travel Map.”
T8191 is offline  
Old Sep 29, 2018, 8:26 am
  #105  
 
Join Date: Mar 2018
Programs: BAEC Silver, IHG Ambassador
Posts: 168
Off-topic from the OP, but a caution for all those using and\or recommending LastPass or similar that automate almost all password management functions that there have been a number of security issues where the password manager, usually via browser extensions, can be persuaded to give up passwords when a malicious site has been visited. See the LastPass security incidents listed on WikiPedia: https://en.wikipedia.org/wiki/LastPass#Security_issues for more info.

While I do highly recommend using a Password Manager, I'm very wary of any that store the passwords on their site, however they may be encrypted, and also any tools or browser extensions that automate the entering of passwords into websites without my express manual intervention.

Personally I use PasswordSafe, and replicate the (encrypted) database via Google Drive. I do accept that there is some risk using the system clipboard to transfer a password from the application into a browser (potentially any application could read the clipboard), but closing the password database does clear the clipboard.
ExAbz is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.