Reply
Honored Resident
Nicolette Lefevre
Posts: 30

Client-Data leaks from LL !!!

I just got two spam-emails to email-addresses that I use for my SL-accounts. One of these email-addresses I ONLY used with that SL-account and for nothing else. So nobody but LL should know that address.

Yet not only did a spammer got to know that address (nicole9h47c4@[somedomain.de]), the spam-mail was also personally addressing me with my RL first name.

Nobody but LL (aside from me myself) should possibly have that email-address and first-name information!

LL, you are leaking your clients' data!!! Either somebody stole that data from you or you yourself sold it to the spammer. Either way: STOP THAT! Or I will stop giving you my money. Which in May alone amounted to about 1500 US$.

And what also disturbs me a lot is that out my 8 SL-accounts (each with a different email-address), the two which got their email-addresses spammed are the ones for which I spend the most money. And the spam-mails were for an online-casino. Coincidence? Maybe. But maybe not...

 

-- Nicolette Lefevre

(who has already changed her SL-passwords and starts to read up on OpenSim now)

 

Posts: 647
Topics: 17
Registered: 04-04-2010

Re: Client-Data leaks from LL !!!

[ Edited ]

Reply to Nicolette Lefevre - view message

Are you sure?  Spammers mail millions of addresses at a time.  Some of the addresses they mail aren't actual email addresses at all, it's like a  guessing game, but some of the addresses will turn out to be actual people's email addresses.  They hit enough of those to make it worthwhile to them, i guess. 

AFAIK, you can't stop the spammers sending to you;  you can only make use of the filter tools provided by your mail client. .  

As an example, i started up a Live Journal for my cat some years back.  Cat had his own email address soley for Live Journal notifications (not a LiveJournal email address).   A couple of months down the line and cat's email account was being spammed mercilessly.  I was convinced that this couldn't happen, but it did.  Even with having our own mail server in the shed, it happened.

I wouldn't be so quick to blame LL if i were you.

 

Medhue Simoni
Posts: 2,665
Topics: 50
Registered: 02-25-2009

Re: Client-Data leaks from LL !!!

Reply to Nicolette Lefevre - view message

Actually, the email provider also knows your email address, and probably your full name.

Honored Resident
Nicolette Lefevre
Posts: 30

Re: Client-Data leaks from LL !!!

Reply to squashy Beeswing - view message

Yes, I am sure. Did you see the email-address that I mentioned? nicole9h47c4@[somedomain.de]. How is a spammer going to find that out by try-and-error? And how is that spammer going to know my RL first-name, which is NOT Nicole? :-)

And why are none of my other email-addresses spammed? I have dozens. I use a different email-address for every account that I create on any website.

I am 100% sure that LL is the ONLY possible source for my data.

 

Honored Resident
Nicolette Lefevre
Posts: 30

Re: Client-Data leaks from LL !!!

Reply to Medhue Simoni - view message


Medhue Simoni wrote:

Actually, the email provider also knows your email address, and probably your full name.


Doesn't apply here as I host the mail-server myself. And yes, I know how to keep the mail-server secure.

 

Posts: 311
Registered: 01-20-2009

Re: Client-Data leaks from LL !!!

Reply to Nicolette Lefevre - view message

I'll escalate but I can assure you we do not sell our customers email addresses.

Honored Resident
Nicolette Lefevre
Posts: 30

Re: Client-Data leaks from LL !!!

Reply to Blondin Linden - view message


Blondin Linden wrote:

I'll escalate but I can assure you we do not sell our customers email addresses.


Thanks for the quick response!

 

Randall Ahren
Posts: 1,653
Topics: 26
Blog Posts: 0
Registered: 04-18-2010

Re: Client-Data leaks from LL !!!

Reply to Nicolette Lefevre - view message

If there is a leak at LL's end, other residents should be getting spammed too. I also use the same system that you do and create a different email address for each site. It's pretty easy to tell who's leaking your info that way. As of yet, I haven't seen any spam from my LL email addresses.

Member
Kidd Krasner
Posts: 397

Re: Client-Data leaks from LL !!!

[ Edited ]

Reply to Nicolette Lefevre - view message

Just out of curiosity, do you have SL IMs from that account set to forward to email?   If so, I would assume you'd never deliberately reply via email to such an IM, but we all make mistakes.  I believe SL doesn't include your email when it forwards such a reply, but it's been a couple of years since I've done that.

It seems more likely that the address and info were stolen, rather than being deliberately sold (or given).  In theory, they could be stolen from anywhere in the chain.  Certainly a security breach on LL's systems is a possibility, as is one on your server, your mail client, and anywhere in between.  I accept that you know how to secure your mail server, I'm sure LL will say the same thing, and between, you, LL, and RSA, I would have bet on RSA (a world-renown security company) being the most secure - but they've been hacked.  SL's servers are presumably a much bigger target than yours, but I wouldn't bet anything anymore on where the leak might be.

Honored Resident
Nicolette Lefevre
Posts: 30

Re: Client-Data leaks from LL !!!

Reply to Randall Ahren - view message


Randall Ahren wrote:

If there is a leak at LL's end, other residents should be getting spammed too. I also use the same system that you do and create a different email address for each site. It's pretty easy to tell who's leaking your info that way. As of yet, I haven't seen any spam from my LL email addresses.


So far all spam-mails to these addresses have been in German. So they are at least targeted geographically. And only 2 of my 8 SL-accounts are affected.