Phished!!!!!
A warning to all. This is the text of an e-mail I sent to my brothers this morning. Read it. Heed it. Pray for me.
In short: yesterday morning, I activated Yahoo messenger, which I hardly ever use anymore. I received an offline message from a buddy of mine at church. The text of the message was a url for a geocities website. I clicked on the link, and was taken directly to (what I thought was) Yahoo Photos. Thinking Rob had put up some pictures from youth group for me to see, I blindly entered my Yahoo username and password into the fields. When I hit "enter", the site didn't do anything - it just stayed the same. I didn't think much of it, and went about my business. I spent much of yesterday morning online, entering grades. Since I'm leaving this morning (in about three hours) for a camping/leadership trip with my Student Council kids up by Mt. St. Helens (coming back Tuesday), I had to go out to the school to set up for my sub for Monday and Tuesday. While there, I tried to log on to my Yahoo mail, and found I couldn't. Well, this happens on occasion, and I thought nothing of it, until I got home and tried again. And again. And again. Each time, I got a "invalid userid/password" error message. After about an hour of doing the same thing over and over again and never getting a different result (true definition of insanity?) I finally began searching around the web, and was horrified. I found a web forum of people who had had their Yahoo accounts hijacked after visiting a bogus geocities site. In terror, I fired up my laptop, went into the history file, and went to the Geocities url I had been sent. Lo and behold, the site came up with a picture perfect Yahoo Photos page, without a Yahoo Photos url. I had been phished for my password, and now some cretin (probably in an internet cafe in eastern Europe or Nigeria) had all my personal info on my Yahoo account.
Now, I don't keep credit card numbers in e-mail messages, nor do I keep social security numbers, either, but I've also had that account since November of 1997, and there are literally thousands of e-mails that I've archived there, and who knows what kind of personal information about myself, my work, my wife, and my kids could be in some loser's hands now? I tell you, I'm just sick over this.
I woke up Katrina at 1 AM, nearly in hysterics, to tell her about this. She helped calm down, and I found a Yahoo customer service telephone number that I immediately called. They weren't open until this morning at 6, so I called back an hour ago. The first drone I spoke with asked me for my date of birth, name, and the answer to my "secret question" that I set up back in 1997, which was "what is my cat's name?" Apparently, the phishers had already changed one or another of those pieces of information, because the dude told me I was unable to verify my information. I asked him if it was possible that the people who stole my account might have changed this information, and he told me it was possible. He then said my account was being forwarded to account security, who would take between 3-5 business days to solve the problem.
At that point, I asked to speak with a supervisor. (I kept very calm and polite, though desperate-sounding, through all of this. Don't want to make techies mad - you'll never get anywhere then). The supervisor gave me the same rigamarole, and then I began offering information, something of which must have clicked, because he then told me that he'd need an alternate e-mail address so security could send me a new password once they get this all ironed out. It seemed like he was believing me at this point. (Granted, I'm glad they're very cautious - for all he knows, I could be the phisher). He wouldn't tell me what piece of information I gave him that "clicked," but I think it was one of my old e-mail addresses I used to have a decade ago that I rattled off to him (I have an obnoxious ability to remember useless information like that - came in handy here).
Hopefully, in the next day or two, all this will be resolved. In the meantime, I'm still sick over this - the sense of violation is almost on the level of someone breaking into my house. In a sense, that's what they did.


2 Comments:
dude... that seriously sucks... I hope it all does turn out ok... I know the feeling of loosing what seems like "everything" and the "invasion" it can feel like... I felt the "dred" come over me as you wrote... I pray for your piece of mind, sanity, and calmness as it all gets worked out...
May I also suggest geting a "real" email account... and eventually forwading the YAHOO account to that real one? You know one that is as seccure as the system it was built on... perphas a DOTmac account... hmm Macintosh hasn't been hacked in 25 years... Just a thought...
The Smith's
My Blog: OutOfTheSilent
My Vlog: OutOfTheSilent
My YouTube Videos
Just my 2 cents.. (im andy, andrina's brother. And A network Admin) While Mac's are more secure in many ways, like linux. Phishing affects all OS's exactly the same. Mainly because its not hacking.. its tricking you into giving them your information. So while linux is probley the most secure mainstream(if you can call it that) OS in the world.. it too is TOAST if i get tricked into giving someone the key to my account X. Well the good news is that They wont get you the same way twice. Sorry for your grief.
Post a Comment
<< Home