PDA

View Full Version : Patrol4X4.com Data Breach



TPC
17th August 2016, 12:29 PM
Did anybody else receive this email?

Bit pi$$ed off if they knew this happened in June they are only just letting people know.

Sick of W@nkers that hack websites and steal peoples info.




Notice of Data Breach
You may have heard reports recently about a security issue involving VerticalScope. We would like to make sure you have the facts about what happened, what information was involved, and the steps we are taking to help protect you. VerticalScope owns and operates a number of community websites. You are receiving this email because you are a registered user of the following community website(s) involved in the data breach:
www.patrol4x4.com
What Happened?
On June 13, 2016, we became aware that February 2016 data stolen from VerticalScope was being made available online.
What Information Was Involved?
Community member usernames, email addresses, hashed passwords, community userIDS, community website, and the IP address the username originally registered with.
What We Are Doing
We have invalidated passwords of all VerticalScope user accounts. We have posted a site security notification on each site updating users on the potential risk to certain accounts, the password reset and steps we are implementing to improve security. We have implemented stronger password rules (passwords now require a minimum of 10+ characters and a mixture of upper- and lower-case letters, numbers and symbols) along with automated account password expiries to encourage more frequent password changes. We will remind our users to use good password practices (not using the same password for multiple online accounts and using unique strong passwords). We are in the process of implementing additional safeguards to detect, alert and mitigate any future brute force attempts, and have notified our third party vendors that interact with our various forum API's of the February breach to allow their own security teams to investigate. We are continuing our investigation and will be collecting information to provide to the appropriate law enforcement authorities.
VerticalScope is taking steps to strengthen account security. We were already using encrypted passwords and salted hashes to store passwords, and our new password controls are intended to further strengthen user security. We are taking steps to investigate and test new encryption and security technologies to further protect our users.
What You Can Do
To keep your account as safe as possible, we recommend that you regularly change your VerticalScope community password, and that you use a unique password for each of your online accounts. Using the same password for multiple online accounts significantly increases your chances of being compromised. Even though the passwords stolen in February were hashed, we recommend that if you were using (or are currently using) your VerticalScope community password across multiple online accounts, that you change your password for such other online accounts. We encourage you to regularly review your accounts and report any suspicious or unrecognized activity immediately.
For More Information
If you have any questions, please feel free to contact our Community Management team by email at cmsupport@verticalscope.com or on the website that you frequent. A support thread has been created on each website, and our support teams are on there to help you through the process and answer any questions you may have. A Notice of Data Breach is also available on community websites involved in the data breach.

This email was sent by VerticalScope Inc., 111 Peter Street, Suite 700, Toronto, ON, M5V2H1. If you have any questions regarding the communications you receive from us, please contact us.

4bye4
17th August 2016, 12:42 PM
Yes mate I Did about three weeks ago. I spent some time changing passwords and uopgrading all my devices but, I think in the end the notification is a hoax. I forgot to upgrade one of my devices password and it still worked just fine. I then changed everything back to the original login details and they all worked just fine again. i then logged onto the forum amd changed to a new password on the change password page. As I say I wonder if it is not just a hoax itself. i would recomend you do anything through the forum and not on any of the contained links.

Ben-e-boy
17th August 2016, 01:00 PM
I got the email back when it happened. It was the company that owns the forum had a breach. Other forums were affected too

TPC
17th August 2016, 01:42 PM
Yes mate I Did about three weeks ago. I spent some time changing passwords and uopgrading all my devices but, I think in the end the notification is a hoax. I forgot to upgrade one of my devices password and it still worked just fine. I then changed everything back to the original login details and they all worked just fine again. i then logged onto the forum amd changed to a new password on the change password page. As I say I wonder if it is not just a hoax itself. i would recomend you do anything through the forum and not on any of the contained links.

It is not a hoax as they have the same message on their website.
My password no longer works on the site, not sure if I will bother getting back on.

the evil twin
17th August 2016, 01:54 PM
I got the first notification ages ago and Ben-e-boy is correct in that it was several Forums.

The upside is that locking out 'old' passwords at least cleans out all the deadwood.