• This Forum is for adults 18 years of age or over. By continuing to use this Forum you are confirming that you are 18 or older. No content shall be viewed by any person under 18 in California.

PLEASE READ Warning -- Do NOT Put Your eMail Address in ADs

Forum Boss

Administrator
Folks, we had an instance yesterday where a member's computer was hacked by a non-member. This message advises you to be VERY careful when dealing with ANY communications received from outside this Forum.

The member had posted a Classified Ad, and had posted his email address in that listing.

A scammer -- who was NOT a registered member of this Forum -- copied that email address, and then sent an email to the member (NOT using this Forum -- using a 3rd-party service).

That scammer's email said he had a question about a similar product, with an web link to click on. This was the SCAM!!

We believe the weblink in the email had malware that allowed tracking.

The member then went back to the Forum, logging in.

The link apparently included malware that captured passwords on the member's computer or phone. This was done by accessing the member's password list, or possibly tracking keystrokes as the member logged in again.

The bad guy then got into the member's account, and changed the email address and the password.

------------------------------

I was notified of the problem this morning. I immediately banned the IP that the scammer was using. I also changed the password on the account.

Guys, the lesson here:

1. NEVER EVER respond to a solicitation from someone who is NOT a registered member. I strongly suggest you only deal with Silver and Gold members as they had to be vetted for a payment, with a verified financial acocunt.

2. NEVER EVER click on an unidentified link in email from an unknown third party.

3. Run effective security (anti-virus) software on your computer.

4. Do NOT keep a variety of passwords on your phone.

5. Change your password for the Forum every few months. Write down the password via HARD COPY.

-----------------------------------
We believe the scam has been halted in progress -- the scammer was attempting to pose as a valid member with a 100% positive trading history.

But this also shows the importance of VERIFYING EVERY TRANSACTION EVERY Time.

-- Always insist on a VOICE Call -- VOICE, not just text, not just email. You MUST CALL and talk.
-- Always insist on Custom Photos -- Tell the seller to put the product on his car dashboard, or on top of a hat -- something completely different than what is on the displayed photos. If the seller is a scammer he cannot create a custom photo.
-- Do a search on the seller's email. If you do a lot of trading, you may want to subscribe to Spokeo.com . This can track email. If you see no person associated with the listed email, be very cautious.
 
Last edited:
I would also be concerned about folks either knowingly or unknowingly replying to other folks' classified ads using profile posts instead of private messages. They're putting addresses, email, phone numbers, and even tracking numbers in publicly viewable profile posts.
 
I would add that a Silver membership is still just $25.00 for 12 months. That is just $2.08 per month -- the price of a cup of coffee. For a SINGLE $500 sale on Gunbroker you will now pay $26.50 (see below) -- more than a year's worth of ads here. For this reason, I believe it is reasonable to question why a seller would NOT upgrade, at least to Silver. As noted, in order to upgrade, the member has to employ a valid checking or CC account.

1692976857735.png
 
Last edited:
Seems to me like a five minute investment in a P.M. can take care of a lot of this . If I don't get a response from the "member" , I consider it a , not worth my time effort . If I do get a timely response , we continue on from there .
 
I have a hunch that's not how it happened. It's extremely unlikely you would get malware from goign to a website unless they trick you into installing it, especially something like a keylogger or something that could crack a password keychain. My guess is that the hacker had a list of passwords and email accounts from a data breach of another (large) site, and the member was using the same email/password that was compromised. This is why people are always telling you not to reuse passwords.

But you never know. Be safe out there.

Edit: On second thought, I'm wrong - if that were the case, simply knowing the email would be enough. This one is a head scratcher based on the info given. 99% of the time this stuff is the result of social engineering- we as people are the weak link. Stay vigilent. With AI becoming more prevalent, scams are getting very convincing.
 
Last edited:
Guys, the lesson here:

1. NEVER EVER respond to a solicitation from someone who is NOT a registered member. I strongly suggest you only deal with Silver and Gold members as they had to be vetted for a payment, with a verified financial acocunt.

2. NEVER EVER click on ...

Yup.

Since the internet came along and electronic connections/communications became easy, I have made it a personal point to never directly contact someone until I've verified via other means that that someone is actually real and verifiable. (ie, If getting a call, contacting a known-good phone number for that company and asking for that person, to first see if the number given on the message matches and that person actually exists there. Verification via means other than merely the means given by the message/email.)

But with direct-contact made via PMs and whatnot, it can be hard to do such verification and validation. Which is why it's so vital to actually speak with the person, actually get photo verification of things (when considering buying something), and so forth.

Tough world, we live in. Wish we didn't all need to be so cautious. But, cautious and circumspect is good. Helps keep the butt out of the wringer, helps avoid getting accounts drained, etc.

It is what it is. Competition for scarce resources ... and the perp will do damned near anything to get it, including burning the unsuspecting to the ground. Unknowns need to be treated as such, circumspectly, until proven to be otherwise whenever possible.

Thanks, again, for the reminders to all.
 

Upgrades & Donations

This Forum's expenses are primarily paid by member contributions. You can upgrade your Forum membership in seconds. Gold and Silver members get unlimited FREE classifieds for one year. Gold members can upload custom avatars.


Click Upgrade Membership Button ABOVE to get Gold or Silver Status.

You can also donate any amount, large or small, with the button below. Include your Forum Name in the PayPal Notes field.


To DONATE by CHECK, or make a recurring donation, CLICK HERE to learn how.

Forum statistics

Threads
166,257
Messages
2,214,836
Members
79,496
Latest member
Bie
Back
Top