eevBLAB #70 - EEVblog Impersonation WARNING!

preview_player
Показать описание
WARNING! to all companies out there to be aware of people impersonating big influential Youtubers in order to elicit confidential company information.

#Warning #Youtube #Scam

Support the EEVblog through Patreon!

Buy anything through that link and Dave gets a commission at no cost to you.

Donate With Bitcoin & Other Crypto Currencies!

Рекомендации по теме
Комментарии
Автор


UPDATE: Because people are inherently stupid (and my middle name is Sherlock Ohms), it didn't take me long to discover who impersonated me!
I have their real gmail address among other things, now what ever shall I do...
I'm willing to bet it's a crime in the state of Illinois.

UPDATE #2: An hour after I sent him an email, I'm now watching in real time as he tries to erase the evidence trail! Hilarious! I even have photo evidence tying him directly to it.

UPDATE #3: The impersonator replied: "I can assure you it was not me. This account was hacked recently.
Here is what I found: A user has just signed in to your Google Account from a new device. We are sending you this email to verify that it is you. Location : Australia


I had to reset password and all other info.

I apologize for any inconvenience." LMAO!

EEVblog
Автор

If the email contained "flapping in the breeze" or "winner winner chicken dinner" they'd definitely think it was real 😀

SimonCoates
Автор

As usual, the biggest threat to security exists between the keyboard and the chair

GeekIWG
Автор

That is the oldest trick in social engineering hacking.

SuperFinGuy
Автор

I've had phishing scammers set domains up to attempt to impersonate me and use public information to guess at what would be correct addresses. Even had me fooled/confused a while. And that was just a straight financial phish! Online impersonation can be way too easy, so good heads up, cheers!


Signed Dave Jones.

pdrg
Автор

People are still falling for email scams, wow! I treat every email I receive with suspicion.

Jedda
Автор

You know you made it when you get parodied by Weird Al or impersonated for your EE blog/services.

FurEngel
Автор

Hi Dave, you should update (or let someone else do it) your SPF record of eevblog.com, it's currently


*eevblog.com** text = "v=spf1 +a +mx ~all"*

Make sure your spf record gets changed to strict (-all instead of ~all)

martijnholland
Автор

Hmm the fact your real email got cc’d means someone along the way within that’s dealt with you might’ve thought something was odd, ....

gmcnewlook
Автор

Those suggesting digital signatures/PGP. It's a good technical solution, however how many people would actually know what it is, let alone how to verify it?

I mean, if an individual was foolish enough to send confidential information without even checking the from header, they sure aren't going to be checking digital signatures.

shaunclarke
Автор

"Because" - "my middle name is Sherlock Ohms" brilliant.

BoBjjjjs
Автор

Sorry to hear Dave. This is a great example of the need to use private/public keys in your emails and make sure the people you do business with know this. It allows the person receiving an email to verify the cryptographic key that you include, to verify that it really came from you. I'd look into getting a digital ID from your certificate authority (CA) and start signing your emails with them.

Subparanon
Автор

Surely the pixelated text in the email was a dead giveaway ;)

KX
Автор

One of the reasons why I think Gmail/Google Mail is just for private use.
I don't trust it when a professional uses it in his job.

numbersto
Автор

Dave, after you received the message in which the company included your valid email address, how did the situation unfold as you informed them that they've been deceived?

richardhead
Автор

Cool, good to know. I'm going to write Cholula as EEVblog and get their hot sauce recipe.

onjofilms
Автор

I'm Spartacus...






-Kirk Douglas. 9 December 1916 - 5 February 2020..RIP

SJRich
Автор

Don't use a "free" email for your business, and don't trust any "business" that uses a free email account! (Buying a domain and setting up an email account @your domain is easy, not expensive...and really the responsible thing to do!

fredygump
Автор

This happens in gaming too, people impersonating some popular youtube person asking for free games...

diatomsaus
Автор

Reminds me of when Linus was hacked. Thank you for spreading the word about this

matiastripaldi