Account compromised, being used to send scam messages.

Hi there,

I hope this is the right place for this post, I'm not sure where else it would go, sorry if incorrect.

As per the subject, somehow, someone, gained access to my account and has been using it to send out a lot of messages to other Etsy accounts which appear to be some kind of scam. They also changed the language setting to Russian.

I have contacted Etsy, changed my password, set an announcement on my shop page and made an auto reply explaining what has happened. I don't know if the auto reply will go out though as Etsy have restricted my account's messaging, which I'm glad of.

I have seen some posts about people recieving messages like the ones sent from my account, just wondering if anyone has experienced what has happened to me and to let people know about it.

It might be a coincidence but I only recently started up my shop again and paid my first bill today. I am fairly certain though that the PC I use to access Etsy is not compromised as I only recently wiped and reinstalled my OS, I will probably now do it again though just to be safe.

My apologies to anyone who this has affected. If you ever recieve messages asking for any personal information including your email address, especially unusual links, report them and do not reply; as far as I understand there is no reason for anyone on Etsy to require such information.

Advice, corrections, admonishments all welcome. x

 

Translate to English There was a problem fetching the translation.
1 Like
7 Replies

Re: Account compromised, being used to send scam messages.

Advice - turn on two factor authentication! The added step logging in is a pain but it means no one can hijack your account

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...
bradgoodell
Community Maker

Re: Account compromised, being used to send scam messages.

The scammers have gotten more sophisticated.  I've heard from another seller who was surprised to receive "I need your email address to check out messages" from established accounts.  I'm really sorry to hear your shop was used for nefarious purposes.  

And now I'm wondering about some shops who are getting their messages suspended for spamming when they claim to not have sent any messages?  Could that be why?  It would be easy to delete the messages from the first account so the shop owner doesn't see them immediately.  It would also explain why some accounts are left open rather than disappearing like what happens when a scammer opens a new account to spam/scam.

Anyway, here is a link to my scam thread.  I'm getting depressed here.

https://community.etsy.com/t5/Managing-Your-Shop/How-to-Spot-a-Scam-No-a-Buyer-Doesn-t-Need-Your-Ema...

Translate to English There was a problem fetching the translation.
0 Likes
Reply
Loading...
bradgoodell
Community Maker

Re: Account compromised, being used to send scam messages.

@FabioMcMustache  Now the scam messages are coming from legit shops?  This is the 2nd time I've heard this in 2 days.

Please have Etsy investigate, and warn sellers. 

Translate to English There was a problem fetching the translation.
4 Likes
Reply
Loading...

Dot.: Account compromised, being used to send scam messages.

I had the same problem just a minute ago. I had two factor authentication on, i dont have a clue how they got access to my account.

Translate to English There was a problem fetching the translation.
0 Likes
Reply
Loading...

Dot.: Account compromised, being used to send scam messages.

and I also paid my first bill today.

 

Translate to English There was a problem fetching the translation.
0 Likes
TheFlowingFire
Inspiration Seeker

Re: Account compromised, being used to send scam messages.

Hi! This happened to me yesterday. I am using a different account to reply here as my shop has been suspended (it sucks for me, but I'm glad no further damage is being done)

Same exact thing. Language changed to russian, sending scam messages. I has 2FA on and they bypassed it.

I found that a few of my gmail accounts had been compromised, with logins from russia. I advise you to check your emails immediately for suspicious logins, log them out if you find any, and change passwords. Possibly from a different device. This can spread so much further than your etsy account. I spent all day locking them out of accounts and securing things yesterday. I also performed a factory reset of my laptop, in case this was done with malware, which I think it was, possibly through session/cookie hijacking, as it bypasses 2FA.

I don't remember clicking on anything suspicious, but who knows. I might have without knowing, otherwise there is no explanation.

Still waiting for a reply from etsy to reinstate my account now. I was able to talk to them on the phone yesterday, they escalated my issue and I received an email later asking me for some security questions. I made sure the email sending them was legit, and answered. Just waiting now, crossing my fingers. Very scary stuff.

Translate to English There was a problem fetching the translation.
0 Likes
Reply
Loading...

Re: Account compromised, being used to send scam messages.

There was a massive mother of all data breaches with over 26 billion accounts affected at the start of this year over multiple organisations including, Myspace, Twitter, FB, LinkedIn, Canva and Adobe to name but a few.

The following links are to two sites where you can run your email and phone no's through them to check if you are one of those affected.

Have I Been Pwned: Check if your email has been compromised in a data breach

Personal Data Leak Checker: Your Email & Data - Breached? | CyberNews

Translate to English There was a problem fetching the translation.
0 Likes
Reply
Loading...
Reply
You must log in to join this conversation.
Remember that posts are subject to Etsy's Community Policy.