CRIME Ubid Hacked...?

From: Robert Johnston (bob@private)
Date: Fri Sep 13 2002 - 10:30:53 PDT

  • Next message: Robert Johnston: "RE: CRIME Ubid Hacked...?"

    I just got an e-mail from Bid read below...
    
    -----START-----
    
    Dear uBid Customer,
      
    It has come to our attention that within the past few days an email
    requesting uBid user IDs and passwords has been sent to some of our
    users.  THIS IS A FRAUDULENT EMAIL THAT WAS NOT SENT FROM UBID -- PLEASE
    DO NOT PROVIDE YOUR LOGIN AND PASSWORD.
    
    If you received the email, and provided your login and password as
    requested on the bogus website, please reply to this email immediately.
    We will disable your account as soon as we receive notification from you
    to prevent future access to your personal information.  A customer care
    representative will contact you if your account has any activity on it,
    such as open auctions, recent orders, etc. for instructions on how to
    transition to a new account.  If your account does not have recent
    activity, simply create a new user login and password.  To protect
    yourself and your personal information, we urge you to contact your
    credit card company if you did provide your login and password to the
    bogus website to prevent any unauthorized purchases.
    
    In the future, please keep the following safety tips in mind:
    
     	uBid will never ask you to provide credit card information or
    your password through an unsecured email transmission.  Please report
    such requests immediately to fraudprevention@private
     	All email correspondence from uBid is sent from an address that
    ends in @ubid.com, @ubid.ymc1.net, or @ubid.p0.com.  If you receive an
    email that claims to have been sent from uBid but does not end in these
    addresses, please feel to call 1-888-900-8243 during regular business
    hours for verification.
     	Use common sense when completing transactions with sellers on
    the Consumer Exchange -- do not wire money or send cash to complete the
    transaction.  Look at the seller's ratings before bidding on an auction,
    and exercise caution if you choose to bid on items that claim to be
    shipped from outside the US.  In addition, if something sounds too good
    to be true, it probably is.  Please visit our Help pages at
    http://www.ubid.com/help/topic62.asp for more safe-buying tips on the
    Consumer Exchange.
     	You may view uBid's complete Privacy and Security policy at
    http://www.ubid.com/help/topic5.asp.  Please keep in mind that uBid's
    Help pages contain accurate information regarding all of uBid's policies
    and procedures -- if you ever have questions about any of our policies,
    please start here: http://www.ubid.com/help/
    
    Thank you for taking the time to review this email as we work together
    to build a safer place to shop and sell on uBid.
    
    
    uBid Customer Care
    
    
    ----- END -----
    
    The actual message in question that was sent out...
    
    
    ----- START -----
    
    Hello datajockey:
    
    This concerns the credit card you have on file for billing purposes for
    your eBay account E5809119001-USD.
    
    Your credit card declined on eBay's latest attempt to charge your
    balance due.  According to the decline information from your card
    issuer, this particular credit card account is no longer accepting any
    billing attempt.  We have now removed this card from your eBay account,
    and will not make any further attempt to bill your balance to this
    credit card number.
    
    You are still responsible for making a payment - you can user any of the
    alternative payment methods, using the links below.  You can also use
    the bottom link to place a different credit card on file for billing.
    Please be sure to supply a credit card number that is open and active.
    
    Please do not reply to this notice as you will not receive a response.
    
    To make a payment now go to:
    http://cgi3.ebay.com/aw-cgi/eBayISAPI.dll?PayCouponShow
    
    Place a different credit card on file for billing purposes
    https://arribada.ebay.com/saw-cgi/eBayISAPI.dll?PlaceCCInfo
    
    View your account balances
    http://cgi3.ebay.com/ws/eBayISAPI.dll?ViewAccountStatus
    
    Thank you!
    eBay Customer Accounts Department
       
    
    ----- END -----
    
    I tried e-mailing their customer support to find out what is going on
    and got blown off. When I called, the cubicle dweller had no idea what
    to do.  I got their corp number and I get lost in the auto attendant.  I
    must be doing something wrong.  I take care of my customers and am
    struggling, they blow people off, compromise sensitive information and
    are thriving.  Am I missing something?
    
    I suspect some credit card information has been compromised as well.
    
    Comments?
    
    
    Robert Johnston
    Datajockeys, LLC
    Hillsboro, OR
    



    This archive was generated by hypermail 2b30 : Fri Sep 13 2002 - 11:28:04 PDT