Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

Greetings!

As it was impossible to get a response from Etsys help team, I'm coming here to hopefully bring more light to this issue - unless you consider help to be the same general basic copy-paste prewritten email.

There is a serious fault with Etsys security systems. There is a scammer who is able to dictate the fate of a stores listings and move them to "sold orders" without ever actually paying for them nor having them go to "verifying payment" tab under orders. He is able to dictate the fate of the order enough, to just straight up move it to the "sold orders". (And also bring them back from there at his own free will!!)

Now I know of 5 other sellers in the same niche who've had to deal with him and due to etsys unwillingness to even pay attention to it, nothing is being done against him.

I've got screenshots of him moving the listings around, I've got screenshots of the private emails he sends where he tries to blackmail you into giving him something for free in return for leaving you alone and I've now managed to get his own personal real life identity and data after playing along with his blackmailing offers.

Would someone care enough to look into this issue finally, this is a serious concern in the overall Etsys safety - he is also able to get private email data!!


Right now I feel like I was attacked for no particular reason. I get harassed by a scammer, I try to report him to Etsy to look for a solution and all I get in return is getting my store suspended in some weird turn of events?

Translate to English There was a problem fetching the translation.
4 Likes
25 Replies

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

I am not able to post pictures here, I wonder if linking to imgur is allowed for further proof?

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

If this is indeed accurate, it makes one question if this is an employee. And I really can't believe someone that is doing something illegal is going to provide you with his/her true identity. Report this to your local authorities and the FBI (if you live in the US). You will need to provide all of your proof to them.

Translate to English There was a problem fetching the translation.
3 Likes
Reply
Loading...

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

It sounds like you've been hacked, not Etsy. I would run Malware etc checks on all your devices. 

 

Translate to English There was a problem fetching the translation.
7 Likes
Reply
Loading...

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

@JeanPhilippeTimepiec Forums is other sellers, not Etsy Support, including this section, although Forum Moderators occasionally post to regarding sitewide issues or to refer an issue to Etsy Support. You cannot post images here, and it would do you no good even if you could. You need to get help from Etsy on the issue, by communicating directly with Support.

I agree that it sounds like you (your device) was hacked. You need to take whatever steps you can to recover from the hack, as it affects much more than just your Etsy shop.

Translate to English There was a problem fetching the translation.
0 Likes
Reply
Loading...

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

Well then lets not consider this as an etsy support ticket, more of a asking whether anyone else from other sellers has also heard of a similar problem.


PS!: The problem is not on my end, or of my account being hacked. He is able to somehow dictate it all from elsewhere - somesort of a etsy backdoor.

If he was accesing it from my side, he could only move the listings to "not active" listings, there is no way for a seller to move them under "sold orders" + I have the authenticator app turnt on + there would be some sort of a IP from other log in. And the biggest smoking gun for why he isn't doing it from hacking to my account is that no extra fees occur - if he was reactivating the listings from my account, there would be the 0.20 cent fee added on top

Translate to English There was a problem fetching the translation.
4 Likes
Reply
Loading...

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

And theres multiple stores who are affected by his listings manipulation. What are the chances of 5 other stores in the same niche occurring similar problems and getting hacked, EVEN if you manage to argue against all the other reasons I provided

Translate to English There was a problem fetching the translation.
3 Likes

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

If etsy thinks you have been hacked, they suspend you account, until they can find out what is happening

Translate to English There was a problem fetching the translation.
0 Likes
Reply
Loading...

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

What if they sent an email saying I'm permanently suspended. They dont even seem to care about the proof I could provide

Translate to English There was a problem fetching the translation.
0 Likes

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

I haven't heard of anyone being permanently suspended for being hacked, however

if you are permanently suspended, you can appeal

https://help.etsy.com/hc/en-gb/articles/6298920789271-How-to-File-an-Appeal-for-a-Permanently-Suspen...

 

Translate to English There was a problem fetching the translation.
0 Likes

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

This happened to me about 6 months ago.

 Everyone in my family from my husband down to my kids are Software Engineers including one in cyber security.

They  came into my account using an old email address that I had on Etsy.     It was not just one person,  but a group.        

Etsy was very helpful.   Try contacting Etsy support.

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

Only Etsy can move an item to "sold". 
This will happen on a legit sale. An item going to "sold" will also occur when a payment is pending approval. Etsy wants the item to be held for the potential buyer. How long it takes to finally approve a sale varies. 
If the sale is finally declined, the listing will be returned to the shop's active listings & there will be no relisting charge.

Yes, the OP & other shops may be being subjected to an individual who has acquired stolen credit card info. & is constantly trying to purchase items they personally want. Hopefully Etsy does not hold this against the OP &/or other shops being subjected to their illegal activities.

Then there are hackers. How they do get into a shop's account may vary. Why they hack the account can be for a variety of dishonest reasons. Once they have access to the account they can wreak havoc.

The OP has hopefully thoroughly scanned any & all devices they use to access their Etsy shop for virus/malware.
The OP should report their shop to Etsy as being hacked. Include all the data they have to back up their statement. Then they will need to be patient since Etsy does not seem to handle these issues as quickly as most would like them to. 

From Etsy: https://help.etsy.com/hc/en-us/articles/115015654008-What-to-Do-if-You-Suspect-Fraud-in-Your-Etsy-Ac...

 

 

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

The thing is, the listings instantly go under "sold". In the case of a real purchase/or a fraudulent purchase, even if for a couple of minutes, they will still appear as "payment verification".

 

What I've found out is that he is some sort of a software developer and is able to somehow get past the verification part or even completely skip the "ordering" part. He is able to move it under sold without ANY indication of ever placing the order (eg. no name or address or anything, when you check at orders)

Translate to English There was a problem fetching the translation.
2 Likes

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

@JeanPhilippeTimepiec 

I have never seen any orders go to "payment verification"

mine go straight to sold

but no address is really odd

Translate to English There was a problem fetching the translation.
1 Like

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

3 Likes

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

Another wave of the same thing happening, my store was of course banned by Etsy instead of getting help. But the fact that now 4-5 other big sellers are also again being targeted by the same trick/scam clearly shows it a problem on Etsys end

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...
CircaWatchLabs
Inspiration Seeker

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

We experienced the same recently. We will be contacting legal authorities and Etsy via the better business bureau as this hacker can actually be traced via Etsy's internal systems. 

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

You don't even have a shop though...

Translate to English There was a problem fetching the translation.
0 Likes

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

@CircaWatchLabs    You have no shop so there is nothing.  Chances are it is malware on your computer.  Etsy is not at fault here.  It sounds like your computer has been compromised from another source.  Get your computer checked, run malware and notify the authorities.  

Translate to English There was a problem fetching the translation.
1 Like

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

@CircaWatchLabs Your shop announcement says you're taking a short break.  Why do you think your shop was hacked?   It could be that Etsy removed your listings for a few reasons.   Listing Seiko watches as handmade, even if you modified them, would be considered counterfeit according to Etsy's rules.  The difference between where your shop is located and where the watches were being shipped from could've also raised some flags.

Translate to English There was a problem fetching the translation.
3 Likes
CircaWatchLabs
Inspiration Seeker

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

I appreciate the attempt at an articulated response but actually we did not say our shop was hacked. We had already contacted Etsy with regards to all these mentioned areas, and there are plenty of Seiko mod shops on Etsy. The Shop had 0 violations so unfortunately your assumptions are incorrect. And actually the hacker is able to compromise Etsy's checkout system by purchasing multiple items with some sort of script generator that is using cards that aren't charged. Then they reverse it and the listings are back up almost instantaenoulsy. They even sent an email to us with blackmail just like OP so I hardly think it is malware from our end. There is something going on with other stores too this is a targeted attack though Etsy's system, which has been compromised. It's as simple as that. Some advanced developer is using exploiting Etsy which is not that hard to imagine as Cyber crime is always happening. Thank you for your input.

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...
GieseDeseiGns
Conversation Maker

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

There are plenty of mod Seiko shops on Etsy, yes and plenty of Disney or Taylor Swift too, just referring to what is listed does not make it legal to sell. Etsy is for Handmade by you or a listed member of your shop, or exclusively designed by a production partner for you only, (which Seiko would not be), vintage (if they are 20 years old) and supplies to make other things.

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

I feel for you and the other sellers that experience this - but what exactly is this hacker accomplishing by moving listings to sold. If you don't get a payment and you cancel they never get anything. Are they a competitor getting rid of competing listings? Are they hoping you send the item? If they send you private messages blackmailing you ... then I'd involve the police as well as Etsy.

I do hope that you're able to get to the bottom of the issue. 

If it's Etsy, Etsy support is probably the only way to get help for this. 

 

 

 

 

 

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

sounds like your login credentials have been hacked (or someone knew them?) and have been able to log on as you. the good news?  since you’re suspended, etsy might be taking care of it so shut the hacker down. follow up on your original email support to get back online. when you’re sure you’re good, change your password and setup 2fa. 

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...

Re: Weakness in Etsy backdoor/security has been compromised by a hacker/scammer

@JeanPhilippeTimepiec 

If you are in the USA, the FBI would be very interested. They have a department called Cyber Crime and I am pretty sure your problem fits in it. If not, the blackmail sure does. They are in the phone book, give them a call. You can also find them online. Good luck

Translate to English There was a problem fetching the translation.
1 Like
Reply
Loading...
Reply
You must log in to join this conversation.
Remember that posts are subject to Etsy's Community Policy.