My Account @Surfermarly Got Just Hacked! Please Don't Open Any Posts Submitted By @Surfermarly!!!

in security •  6 years ago  (edited)

It's hard to set up this blog post, I wish I could turn back time.

My main account @surfermarly just got hacked and I have lost the control over it.

I'm going to tell you how it happened in order to prevent you from doing the very same mistake.

The user @eruda has developed a quite sophisticated way to make other users click on phishing links.

He comments on blog posts that include an image which looks like as if another user has commented below. In this case the account name exyle was displayed, even though the user/account @exyle has nothing to do with this scam (just check the reputation score which is wrong). The name was just used to provide a certain trustworthiness and make me believe I was clicking on the link provided by a friend.

I don't want it to sound like an excuse, but after yesterday's crash I thought Steemit.com was still not working completely stable, so it didn't surprise me too much that I was asked to log in to the site again (even though I had already done it a couple of minutes before).

After typing in my owner key and hitting the enter button I already realized that I was hacked since it said Password incorrect.

Now I've started the general recovery process and also sent an email to my contacts at Steemit, Inc, hoping that I'll be able to get the control over my account back soon.

@arcange wrote about this a couple of weeks back, but unfortunately I didn't read his post.

The user who temporarily controls the account @surfermarly is now using it to publish shit posts. It couldn't get worse... PLEASE don't open any of the submitted blog post by this account and especially DON'T CLICK ON ANY LINKS submitted by @surfermarly or @eruda.

It's weird to even write that.

Please also consider spreading the information over the blockchain, inform your friends on discord, steem.chat etc.

Last but not least, a HUGE shout out to the guys from the Steem Speak discord server: @exyle, @sircork, @jonny-clearwater and everybody else who has helped me to get the recovery process started and to spread the message!

Thanks for your support!!!

The real Marly -

Just posted this pic of the Steemit thermos jug I was given at Steemfest² in Lisbon in my Instagram account adding the phrase It's me... even though you might all know it's me posting from this account.

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

Aww @surfermarly im SO sorry to hear this!!!! That scam would be sooo easy to fall for and the hacker’s creativity just keeps getting more and more advanced. 😞

I really hope that you are able to recover your account soon! Let me know if there is anything I can do. ♥️

Thank you so much, Lea!
Lucky me, I was able to recover the account quickly through the general recovery process from Steemit, Inc.

I will need to be much more attentive in the future.
However, my biggest takeaway is that the community has really been amazing in that situation! I don't know if I have ever experienced something similar before. Truly awesome and beyond that!!! :-)

Thanks for being with me on my rollercoaster day, hehe

I'm actually SUPER impressed by how quickly you were able to recover your account! I've always wondered how much Steemit inc. was actually able to help if someone got your keys - and it is super encouraging to hear how helpful they were.

I'm so glad that this horrible, crazy situation turned into such a bright moment of love from the community. <3

Honestly I was super impressed, too. It's the advantage of setting up an account via Steemit. They have a really efficient security system!

Thanks for being with me, Lea!!! :-)

what did you have to do to recover your account? they make it sound like if you lose your keys it is all over.

It highly depends on where you created your account and how fast you (re)act. Steemit offers an official recovery process HERE. You may also want to consider the FAQ for more information on the procedure.

  ·  6 years ago (edited)

Hey @surfermarly, sorry to read your account has been hacked. I Hope you will be able to recover it quickly.

I already reported this scam last month and created a re-post for it to be resteemable: https://steemit.com/steemit/@arcange/phishing-attempts-are-running-and-use-fake-comments-with-images

Feel free to resteem the above post if you think this could help and prevent others from being hacked like you.

Unfortunately, my warning bot which can detect such phishing technique is down because of the recent HF20 crash (all my nodes are replaying) and therefore it will be late to issue warning to targeted users.

I wish you all the best and hope to see you again in Krakow.

Take care!

Ach sch***! Hoffe du kriegst deinen Account wieder!!!

Danke, ich habe ihn nun wieder :-)
Werde gleich dazu was posten...

Gott sei dank!
Schön zu hören!

Danke Dir!
Übrigens: Hammer Fotografie in Deinem Blog, musste ich direkt mal teilen :-)
Wo ist das entstanden, wenn ich fragen darf?

Danke dir 🙏🏼🦋🌸freut mich voll das es gefällt und danke für das teilen 🙃✨ist in Nordafrika...😇😉
Du bist doch in Portugal oder?

Gerne! Afrika, wow. Das steht auch noch auf meiner Liste :-)

Ich lebe auf den Kanarischen Inseln, aber Portugal mag ich auch sehr!

Aaah ich liebe die canaren! Auf fuerte hab ich bei Homegrown surfen angefangen.
Wenn ich da als yogini Ma n Job hätt würd ich auch sofort dahin!
Super Wahl haste getroffen 🙏🏼🦋🌸✨

Oh, ja Fuerte! Da kann man es auf jeden Fall auch sehr gut aushalten.
Klar, Jobs gibt es hier nicht so viele - aber vlt. können wir ja eines Tages alle von Steem leben :-)

I thought with the Master Password you can enter and time and just change all other passwords?

Thats step one. We've got her into the process now.

What is step two? Email?

account recovery processes via whatever one of the sites , wallets, or dapps a user registered with.

Sorry that it happened, but never use your password or owner key on Steemit (unless it's absolutely necessary)

  ·  6 years ago (edited)

This 100%.

Another method I would recommend though is to have the login page bookmarked so you would know that you are always on the correct site. Good thing is that the scammer didn't scam that much, but be more careful next time @surfermarly.

Sincerely,
@Mysteor

Bookmark?
I think that checking that you are on Steemit.com, when you login is much easier and safer.
But this is only my opinion.

  ·  6 years ago (edited)

Sure, but some people do have problems with attacks such as this one . . .

l vs I

or

0 vs O

or

rn vs m

or

b vs ḅ

Maybe you can see the difference, but not everybody is checking every letter and most people don't even look at the website name when the website looks how it should looks like. Bookmarking a site can totally help against this.

Sincerely,
@Mysteor

That - besides the fact that we have an AMAZING community on Steem - is my today's takeaway :-)

Look from where I'm posting, hehe
Just got it back!!

Hi there, @dreamsoftheocean !

We'd just thought that we would like to remind you that we mentioned you in our most recent blog post mentioning how we recognise your loving and charitable work! More so, how we are upvoting all of your content with the aim of finacnailly supporting you, as it is in line with our mission statement

We thought that it would be important to let you know that we are supporting you, hoping that we could improve our relationship together!

Let us know what you think!

Best,

@charitycurator

WARNING! The comment below by @stevelivingston leads to a known phishing site that could steal your account.
Do not open links from users you do not trust. Do not provide your private keys to any third party websites.

Don't feel bad. They spend a lot of time coming up with these scams, and it only takes a few distracted seconds to fall prey. I'm sure the team will have you back in the driver's seat soon.

Thanks a lot, Matt!!
Some are trying to make me look like a fool now. Great moment for that.
Thanks for your kindness and understanding.

you don’t look like a fool. Nobody would think that. Probably lost a couple hundred STEEM but that’s the worst of it. Life goes on, violations occur. You’ll be back in no time.

I have my account back!!!

in no time was pretty accurate :-)
Thanks for your support!!

hey, really sorry about this, that sucks.
I have resteemed this, hope it helps.
But one question, why do you log in with your owner key in the first place?? that is the one you need in cases like this.
On a day to day basis we only need active or posting keys right?

anyway, sorry to hear about this, hope you get the account back and this just goes to show that everyone can get duped so security is really important because all our work can be gone in a moments notice

It was a mistake to use the owner key, just out of convenience.
I'm happy to let you know that I could recover my account and am posting again :-)

very glad to hear that... I would have been sad if you would have to restart again from scratch.
good to have the one and only back in place

Thanks @felander!!! I'm really happy to have it back :-)

So sorry to hear about this @surfermarly. Thanks for sharing this information and hope you get your account recovered.

This very bad... I have seen this link lot also ... :((((((

I hope you get your page soon back... or you can get new fast back up.

I did get it back!!!! :-)

This is very good :) I hope you not get this problem more.

Big hugs. I’m sure you will have your account back very soon.

Got it!!!!!!!!!! Yeeeeew :-)

Ohhhh fruck. This is annoying. I hope You can get the access to your account pretty soon. Hope that they can help you from Steemit, inc luckily You are a statment huge user here and I think all be good. But that is a clever way to trick people. Thanks for the warning. :)

Sorry to hear that Marly, I hope you can get your account back.

Resteemed to help spread the word.

I got it back!!!!!!!! :-))))

omg that really really is sophisticated! Please update us on the recovery process and I'm sorry that happened. Resteeming so people know

Sorry this happened to you. For now I'll follow you here until you regain control of your main account. Good luck to you.

I don't think I will be blog posting again any time soon. But thanks for your support.

Don't let an idiot make you stop being awesome. That's how the terrorists win!

This really sucks.

What I don't understand with these criminals is this: If they dedicated the same amount of time creating positive content as they do creating these scams, they can make their own money on here.

Some of these crooks can obviously code. So why not write some codes to help the platform and maybe get a delegation or something? I will never understand.

I don't know any answer to that question, I'm just really down right now.

Because a criminal mind is usually smart in some way and stupid as hell in all the other ways.

Dreaded reading it, am so sorry and i hope you'll recover it the soonest Marly.

I'm back, sweetie!!! Posting again from my main account, yuhuuuu :-)
Thanks for being with me!

Haha yeah i can see that! Rock and roll Marly!

Marly! :O

So sorry to hear of the pain and loss you're going through... );

Go catch a few waves to sooth your nerves until everything is "back to normal." Let me know if I can do anything...

Big Hugs!!! <3

- @creatr

😄😇😄

@creatr

Haha, got some vitamin sea in the meantime!!!

Guess what, I was able to recover my account! Yeeeeeew :-)
And guess who's the happiest surfer on Earth right now...?!

Big hugs back, @creatr!!!

That's great news, sweetie!

I am very glad to hear it.

Also happy that you got out in the ocean to shake some of this off... :D

Take care, my dear Marly! 🏄‍♀️ 😄😇😄

Surfing cures everything :-)

Thank you my friend!!!

My friend, you may wish to join this project :-)

Yes! Of course! Thank You!

I'm trying to connect w/ you on Discord... ;)

Awesome, got your friendship request and accepted.
Meet you there :-)

Just saw your reply here, will try to find you on Discord. ;)

Found ya :-)

Oh no I am sorry to hear that!

People are getting more and more cunning in hacking accounts!

I downvoted some of 'your' posts and 'your comments' below that post to decrease visibility. This sucks. Virtual hugs, being stolen from just feels like such a huge blow in the stomach :-(

I'm really down. Thanks for the flags and hugs!!

Yes, I would feel down too :-(

I'm back on track!!! Thank you so much for your support, it really means a lot to me :-)

I'm so sorry you got hacked, I was hacked last year in October, back when steem was worth a lot. It felt awful. I'm glad they are helping you. I was helped, too. We have awesome people here.,

Sorry to hear this gonna send to everyone i know on steem.

Hope you didn't have much liquid steem on SBD on that account. This is why steemit nees to use steem connect like busy and steempeak

Posted using Partiko Android

Oh damn you got hacked... And in a way that everyone can be tricked into this... Just don't feel bad surfer, this can happen to anyone! You always use your owner key to login at Steemit?

And like @coruscate is mentioning already, really impressive that you got your account back real quick. What is the procedure for this actually?

Hang loose 🤙

Just went to your page and it wants me to sign in with my active or owner key...

Well I'll try to follow you and voted!

OHHHH NOOOOOOOOOOOOOOOOOOOOOOOOOOOO

  ·  6 years ago (edited)

Warning removed

Message deleted as it was not a scam it was warning users about what happened in this post... A genuine comment. Sort out your bot...

Posted using Partiko Android

Your comment triggered both my bot and @guard. Mentionning phishing links or copying the content of phishing comments can lead (dumb) users to reuse it and our warning bots are very touchy with this.

I am so sorry that happened to you. I've been there and know how awful it feels. Sending hugs.

It happened something similar to me about a month ago! I received a comment like in your content, but fortunately my antivirus blocked immediatly that link and so I was safe. Sure, I immediatly change every passwords and I did the recovery of my account here, but it was a very bad experience. I hope everything will go back ok soon for you!

1510654234_the-office-congratulations.gif

Congratulations @dreamsoftheocean! You have received a personal award!

1 Year on Steemit
Click on the badge to view your Board of Honor.

Do not miss the last post from @steemitboard:

SteemitBoard Ranking update - Steem Power, Followers and Following added

Support SteemitBoard's project! Vote for its witness and get one more award!

Hi there! We bring good news!

We thought that we would like to let you know that we have added you to our list of users on our curation trail!

As a result, all content that you post, we will automatically Upvote you 100%!

Thank you for the good work that you are doing!

If you would like to know more, check out our most recent blog post here!

We would really appreciate it if you can show some support in any way, shape or form.

Best,

@charitycurator

You have a minor misspelling in the following sentence:

I'm going to tell you how it happend in order to prevent you from doing the very same mistake.
It should be it happened instead of it happend.

Thank you, corrected.