Ask HN: My Netflix got hacked – I found out who sold my credentials. What now?
So, my Netflix account got hacked. Some of the profiles in my account were removed so I lost quite a bit of information on where I was with certain series. Anyway, with a bit of 'research' I managed to track down who sold my login information (Name & address). What's the best thing to do with this information?
Ps. I live in The Netherlands. Person who sold my credentails lives in The Netherlands too.
56 comments
[ 2.7 ms ] story [ 125 ms ] threadhttp://www.justice.gov/criminal/cybercrime/reporting.html
and also your local police department.
If there are a series of incidents connected to the same event/person, it may get prioritized. You can also reach out to your local FBI field office http://www.fbi.gov/contact-us/field
It sucks, but it's a juice worth the squeeze problem.
I have been a 'victim' a few times ever since the LinkedIn and Adobe brecaches awhile ago. It even happened as early as 2 weeks back. It's becuause I'm a fool and use the same password multiple times. Now, I don't going forward.
The information has been indexed as of 5 days ago. Credited to "@LulZSecSecurity"
Other than losing your place in your various series, have you suffered any other loss or harm as a result of your account breach?
They'd want you to change your password to prevent it... but you're supplying them with a random name and address... pretty sure they aren't interested taking it on faith that that person is responsible and then attempting any intervention.
I would also be fearful of living in any city where Netflix theft is handled with any serious police resources.
And if you do get credentials, why are you then deleting accounts? Locking the person out is no use... they'll just cancel. Presumably you don't have 8 bucks a month to have your own... so you're better off not making any changes and just enjoying.
So confused.
They're sold to people at a discount relative to Netflix's standard pricing -- e.g. $20 (or BTC equivalent) for 1 year of service. The customers don't always understand that they're paying a thief/fence for stolen goods.
Based on some forums it appears that often stolen credit cards are used to buy redeemable codes. Those codes are then sold for far less... Basically washing the stolen CCs.
Hacking individual accounts seems much more difficult / less rewarding financially.
You can buy the accounts for $2 or you can pay $20 for unlimited accounts. They sell programs that you click a button and it just gives you another hacked account from their database.
Out of curiosity, how did you track him/her down?
The password could have probably been used for Dropbox , Evernote , and even mail(work and personal) - now making him completely vulnerable to a slew of attacks !
This is not as simple as changing password for netflix and walking away.
https://www.fiverr.com/search/gigs?utf8=%E2%9C%93&search_in=...
If you are a programmer - make sure no one logged into any of your AWS ( or any such public cloud accounts) and generated another pair of keys. You might not realize anything now , but the attack might come when you totally dont expect it. They might spin up instances and have a few 1000 $ swiped on your card. ( Amazon will still charge you in these scenarios )
This is not just a loss of your netflix password . It probably leaked a ton of information about you , your password pattern ! I bet you have the same password for atleast a few more services. You have to protect them .
I'd hold off contacting the EC3 if I were you.
This reminds me of a joke in a Simpson's episode, "I thumb through your magazines" https://www.tumblr.com/search/i%20thumb%20through%20your%20m...