NonSports Forum

Net54baseball.com
Welcome to Net54baseball.com. These forums are devoted to both Pre- and Post- war baseball cards and vintage memorabilia, as well as other sports. There is a separate section for Buying, Selling and Trading - the B/S/T area!! If you write anything concerning a person or company your full name needs to be in your post or obtainable from it. . Contact the moderator at leon@net54baseball.com should you have any questions or concerns. When you click on links to eBay on this site and make a purchase, this can result in this site earning a commission. Affiliate programs and affiliations include, but are not limited to, the eBay Partner Network. Enjoy!
Net54baseball.com
Net54baseball.com
ebay GSB
T206s on eBay
Babe Ruth Cards on eBay
t206 Ty Cobb on eBay
Ty Cobb Cards on eBay
Lou Gehrig Cards on eBay
Baseball T201-T217 on eBay
Baseball E90-E107 on eBay
T205 Cards on eBay
Baseball Postcards on eBay
Goudey Cards on eBay
Baseball Memorabilia on eBay
Baseball Exhibit Cards on eBay
Baseball Strip Cards on eBay
Baseball Baking Cards on eBay
Sporting News Cards on eBay
Play Ball Cards on eBay
Joe DiMaggio Cards on eBay
Mickey Mantle Cards on eBay
Bowman 1951-1955 on eBay
Football Cards on eBay

Go Back   Net54baseball.com Forums > Net54baseball Main Forum - WWII & Older Baseball Cards > Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions

Reply
 
Thread Tools Display Modes
  #1  
Old 12-19-2020, 07:11 PM
todeen's Avatar
todeen todeen is offline
Tim Odeen
Member
 
Join Date: Jul 2013
Posts: 3,306
Default

Quote:
Originally Posted by Shoeless Moe View Post
C'mon Bob don't pay the ransom! Go out and get Liam Neeson & Harrison Ford, they'll deal with the hackers the right way.
One of the top posts of 2020!

Sent from my SAMSUNG-SM-G930A using Tapatalk
__________________
Barry Larkin, Joey Votto, Tris Speaker, 1930-45 Cincinnati Reds, T206 Cincinnati
Successful deals with: Banksfan14, Brianp-beme, Bumpus Jones, Dacubfan (x5), Dstrawberryfan39, Ed_Hutchinson, Fballguy, fusorcruiser (x2), GoCalBears, Gorditadog, Luke, MikeKam, Moosedog, Nineunder71, Powdered H20, PSU, Ronniehatesjazz, Roarfrom34, Sebie43, Seven, and Wondo
Reply With Quote
  #2  
Old 12-19-2020, 07:24 PM
Mark17's Avatar
Mark17 Mark17 is offline
M@rk S@tterstr0m
Member
 
Join Date: Aug 2011
Location: Minnesota
Posts: 2,233
Default

This affects a lot of AH I deal with, so I'm wondering what personal info was exposed if any, like payment method info.
Reply With Quote
  #3  
Old 12-19-2020, 07:36 PM
Aquarian Sports Cards Aquarian Sports Cards is offline
Scott Russell
Member
 
Join Date: Jun 2016
Location: Pennsylvania
Posts: 7,063
Default

Since they've taken control of Simple's servers I think it would be smart to assume data has been compromised.
__________________
Check out https://www.thecollectorconnection.com Always looking for consignments 717.327.8915 We sell your less expensive pre-war cards individually instead of in bulk lots to make YOU the most money possible!

and Facebook: https://www.facebook.com/thecollectorconnectionauctions
Reply With Quote
  #4  
Old 12-20-2020, 05:13 AM
sb1 sb1 is offline
Member
 
Join Date: Apr 2009
Posts: 3,231
Default

There is little personal data at risk for most of AH's affected.

When you register, you provide your name, address, email and phone. No financial info or any kind(credit card or bank account info) nor SS #.

AH's taking Paypal and Credit cards might have another issue, if they have data on their server, more likely it's on the payment processors side and quite secure.

I think the jist here was to hold Simple hostage and not gain benefit from the users info, otherwise they would have stayed quiet and milked the data for a long time.
Reply With Quote
  #5  
Old 12-20-2020, 09:34 AM
Aquarian Sports Cards Aquarian Sports Cards is offline
Scott Russell
Member
 
Join Date: Jun 2016
Location: Pennsylvania
Posts: 7,063
Default

I understand what you're saying Scott, my point was to err on the side of caution, not that anything definitively happened.
__________________
Check out https://www.thecollectorconnection.com Always looking for consignments 717.327.8915 We sell your less expensive pre-war cards individually instead of in bulk lots to make YOU the most money possible!

and Facebook: https://www.facebook.com/thecollectorconnectionauctions
Reply With Quote
  #6  
Old 12-20-2020, 09:57 AM
Throttlesteer Throttlesteer is offline
Anson
Member
 
Join Date: Jan 2018
Posts: 830
Default

MeiGray is part of this as well.

Additionally, if user IDs are tied to their personal information and large purchases, this could help further identify "high value" targets. Don't cast off PII so easily.
__________________
An$on Lyt!e

Last edited by Throttlesteer; 12-20-2020 at 10:10 AM.
Reply With Quote
  #7  
Old 12-20-2020, 10:13 AM
drcy's Avatar
drcy drcy is offline
David Ru.dd Cycl.eback
 
Join Date: Jul 2013
Posts: 3,486
Default

I think Scott's assessment makes sense. If they were stealing personal financial information, they wouldn't say anything. They would try to be completely covert about that.


Quote:
Originally Posted by sb1 View Post
There is little personal data at risk for most of AH's affected.

When you register, you provide your name, address, email and phone. No financial info or any kind(credit card or bank account info) nor SS #.

AH's taking Paypal and Credit cards might have another issue, if they have data on their server, more likely it's on the payment processors side and quite secure.

I think the jist here was to hold Simple hostage and not gain benefit from the users info, otherwise they would have stayed quiet and milked the data for a long time.
Reply With Quote
  #8  
Old 12-20-2020, 11:25 AM
Golfguy Golfguy is offline
member
 
Join Date: Nov 2011
Posts: 1
Default

Well if it's ransomware it means someone has control of their servers. That means they have control of ALL info. So if they keep credit card info on file, it's in there. I don't believe they encrypt passwords, so there's that too. If you use the same passwords for important things such as credit cards, banking, etc., you might want to make some changes. I know some are joking on this thread, but this is serious. ALL of SA customers (auction houses) have been compromised.
Reply With Quote
  #9  
Old 12-20-2020, 11:54 AM
Mark17's Avatar
Mark17 Mark17 is offline
M@rk S@tterstr0m
Member
 
Join Date: Aug 2011
Location: Minnesota
Posts: 2,233
Default

Quote:
Originally Posted by Golfguy View Post
Well if it's ransomware it means someone has control of their servers. That means they have control of ALL info. So if they keep credit card info on file, it's in there. I don't believe they encrypt passwords, so there's that too. If you use the same passwords for important things such as credit cards, banking, etc., you might want to make some changes. I know some are joking on this thread, but this is serious. ALL of SA customers (auction houses) have been compromised.
I'm also wondering if info related to sales tax exemption for resellers might be on those servers. Application for tax exemption might include SSN.
Reply With Quote
  #10  
Old 12-21-2020, 06:14 AM
toledo_mudhen's Avatar
toledo_mudhen toledo_mudhen is offline
Lonnie Nagel
Member
 
Join Date: Jun 2010
Location: Clinton, Missouri
Posts: 1,484
Default

Quote:
Originally Posted by Golfguy View Post
Well if it's ransomware it means someone has control of their servers. That means they have control of ALL info. So if they keep credit card info on file, it's in there. I don't believe they encrypt passwords, so there's that too. If you use the same passwords for important things such as credit cards, banking, etc., you might want to make some changes. I know some are joking on this thread, but this is serious. ALL of SA customers (auction houses) have been compromised.
Up until recently - Ransomware HAS NOT also attempted to steal the data. Best "guesstimates" currently put it at a 1 in 10 chance that the attackers are interested in stealing data.

I m involved with Information Security as a profession and in my experience - the attackers are really only interested in getting paid (usually thru Bitcoin as it is almost impossible to trace). Additionally, In almost ALL cases - once the payment is made the victim WILL receive instructions on how to recover their data.

In my opinion - there are many more $$ and much less chance of getting caught by doing what they do best - extorting cash from their victims.

https://blog.emsisoft.com/en/36569/t...an-one-in-ten/

A well designed security posture can nearly eliminate Ransomware Breach but can get quite expensive and smaller companies struggle with trying to provide adequate security against ALL Internet perils.
__________________
Lonnie Nagel
T206 : 225/520 : 43%
Reply With Quote
  #11  
Old 12-20-2020, 02:44 PM
Aquarian Sports Cards Aquarian Sports Cards is offline
Scott Russell
Member
 
Join Date: Jun 2016
Location: Pennsylvania
Posts: 7,063
Default

Quote:
Originally Posted by drcy View Post
I think Scott's assessment makes sense. If they were stealing personal financial information, they wouldn't say anything. They would try to be completely covert about that.
Except that most of the time the guys who steal the info aren't stealing it to use it but rather to sell it.
__________________
Check out https://www.thecollectorconnection.com Always looking for consignments 717.327.8915 We sell your less expensive pre-war cards individually instead of in bulk lots to make YOU the most money possible!

and Facebook: https://www.facebook.com/thecollectorconnectionauctions
Reply With Quote
  #12  
Old 12-20-2020, 03:01 PM
oldjudge's Avatar
oldjudge oldjudge is offline
j'a'y mi.ll.e.r
 
Join Date: May 2009
Location: The Bronx
Posts: 5,772
Default

What auctions use simple auctions?
“the threat actors do not work on weekends”—really? This is a nine to five job? Better hope that they have not taken off for a Christmas vacation.
Once you pay a ransom to unlock your site what is to prevent these people from not turning it back on and simply asking for more money? What can you do to safeguard your site from ransom ware and why wasn’t it done before?

Last edited by oldjudge; 12-20-2020 at 03:09 PM.
Reply With Quote
  #13  
Old 12-20-2020, 03:02 PM
Mark17's Avatar
Mark17 Mark17 is offline
M@rk S@tterstr0m
Member
 
Join Date: Aug 2011
Location: Minnesota
Posts: 2,233
Default

Quote:
Originally Posted by Aquarian Sports Cards View Post
Except that most of the time the guys who steal the info aren't stealing it to use it but rather to sell it.
Right. These are thieves. They have a primary target and probably a secondary one as well. A car thief might be after the McLaren, but if there's a briefcase with money on the front seat, he'll take that too.
Reply With Quote
Reply




Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Sterling Auctions Neal Modern Baseball Cards Forum (1980-Present) 1 11-14-2017 01:57 PM
Sterling Auctions Lot #144 Yoda Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 0 11-06-2015 10:56 AM
Sterling Auctions Kingcobb Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 12 10-20-2015 11:21 PM
Sterling Auctions? EvilKing00 Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 35 03-28-2013 01:48 PM
Baggers Auctions and Sterling Sports Auctions ending tonight... Leon Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions 3 07-21-2011 10:55 PM


All times are GMT -6. The time now is 10:38 PM.


ebay GSB