![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
|
|
#1
|
||||
|
||||
![]() Quote:
![]() Sent from my SAMSUNG-SM-G930A using Tapatalk
__________________
Barry Larkin, Joey Votto, Tris Speaker, 1930-45 Cincinnati Reds, T206 Cincinnati Successful deals with: Banksfan14, Brianp-beme, Bumpus Jones, Dacubfan (x5), Dstrawberryfan39, Ed_Hutchinson, Fballguy, fusorcruiser (x2), GoCalBears, Gorditadog, Luke, MikeKam, Moosedog, Nineunder71, Powdered H20, PSU, Ronniehatesjazz, Roarfrom34, Sebie43, Seven, and Wondo |
#2
|
||||
|
||||
![]()
This affects a lot of AH I deal with, so I'm wondering what personal info was exposed if any, like payment method info.
|
#3
|
|||
|
|||
![]()
Since they've taken control of Simple's servers I think it would be smart to assume data has been compromised.
__________________
Check out https://www.thecollectorconnection.com Always looking for consignments 717.327.8915 We sell your less expensive pre-war cards individually instead of in bulk lots to make YOU the most money possible! and Facebook: https://www.facebook.com/thecollectorconnectionauctions |
#4
|
|||
|
|||
![]()
There is little personal data at risk for most of AH's affected.
When you register, you provide your name, address, email and phone. No financial info or any kind(credit card or bank account info) nor SS #. AH's taking Paypal and Credit cards might have another issue, if they have data on their server, more likely it's on the payment processors side and quite secure. I think the jist here was to hold Simple hostage and not gain benefit from the users info, otherwise they would have stayed quiet and milked the data for a long time. |
#5
|
|||
|
|||
![]()
I understand what you're saying Scott, my point was to err on the side of caution, not that anything definitively happened.
__________________
Check out https://www.thecollectorconnection.com Always looking for consignments 717.327.8915 We sell your less expensive pre-war cards individually instead of in bulk lots to make YOU the most money possible! and Facebook: https://www.facebook.com/thecollectorconnectionauctions |
#6
|
|||
|
|||
![]()
MeiGray is part of this as well.
Additionally, if user IDs are tied to their personal information and large purchases, this could help further identify "high value" targets. Don't cast off PII so easily.
__________________
An$on Lyt!e Last edited by Throttlesteer; 12-20-2020 at 10:10 AM. |
#7
|
||||
|
||||
![]()
I think Scott's assessment makes sense. If they were stealing personal financial information, they wouldn't say anything. They would try to be completely covert about that.
Quote:
|
#8
|
|||
|
|||
![]()
Well if it's ransomware it means someone has control of their servers. That means they have control of ALL info. So if they keep credit card info on file, it's in there. I don't believe they encrypt passwords, so there's that too. If you use the same passwords for important things such as credit cards, banking, etc., you might want to make some changes. I know some are joking on this thread, but this is serious. ALL of SA customers (auction houses) have been compromised.
|
#9
|
||||
|
||||
![]() Quote:
|
#10
|
||||
|
||||
![]() Quote:
I m involved with Information Security as a profession and in my experience - the attackers are really only interested in getting paid (usually thru Bitcoin as it is almost impossible to trace). Additionally, In almost ALL cases - once the payment is made the victim WILL receive instructions on how to recover their data. In my opinion - there are many more $$ and much less chance of getting caught by doing what they do best - extorting cash from their victims. https://blog.emsisoft.com/en/36569/t...an-one-in-ten/ A well designed security posture can nearly eliminate Ransomware Breach but can get quite expensive and smaller companies struggle with trying to provide adequate security against ALL Internet perils.
__________________
Lonnie Nagel T206 : 225/520 : 43% |
#11
|
|||
|
|||
![]()
Except that most of the time the guys who steal the info aren't stealing it to use it but rather to sell it.
__________________
Check out https://www.thecollectorconnection.com Always looking for consignments 717.327.8915 We sell your less expensive pre-war cards individually instead of in bulk lots to make YOU the most money possible! and Facebook: https://www.facebook.com/thecollectorconnectionauctions |
#12
|
||||
|
||||
![]()
What auctions use simple auctions?
“the threat actors do not work on weekends”—really? This is a nine to five job? Better hope that they have not taken off for a Christmas vacation. Once you pay a ransom to unlock your site what is to prevent these people from not turning it back on and simply asking for more money? What can you do to safeguard your site from ransom ware and why wasn’t it done before? Last edited by oldjudge; 12-20-2020 at 03:09 PM. |
#13
|
||||
|
||||
![]()
Right. These are thieves. They have a primary target and probably a secondary one as well. A car thief might be after the McLaren, but if there's a briefcase with money on the front seat, he'll take that too.
|
![]() |
|
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Sterling Auctions | Neal | Modern Baseball Cards Forum (1980-Present) | 1 | 11-14-2017 01:57 PM |
Sterling Auctions Lot #144 | Yoda | Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions | 0 | 11-06-2015 10:56 AM |
Sterling Auctions | Kingcobb | Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions | 12 | 10-20-2015 11:21 PM |
Sterling Auctions? | EvilKing00 | Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions | 35 | 03-28-2013 01:48 PM |
Baggers Auctions and Sterling Sports Auctions ending tonight... | Leon | Net54baseball Vintage (WWII & Older) Baseball Cards & New Member Introductions | 3 | 07-21-2011 10:55 PM |