Sallybeth23 reveals - How my steemit account was stolen, abused and later recovered

in steemit •  7 years ago  (edited)

64447_475102539209535_2117186031_n (1).jpg

The first indication that something was wrong was when I found myself unable to login to my account. My password was apparently incorrect suddenly.
I had my blog page on screen from the previous session but noticed to the top right of the screen, instead of my icon, just the log in sign. As I hit refresh on the page I suddenly saw all the posts on my blog not made by me but with my name as author to them. Every few minutes another was appearing.
The instant realization that someone had stolen my account and was now plastering their viral messages all over it hit me with a sickening blow.
I could not think what I had done to allow this to happen. How had my password been stolen to give someone access like this?

The post they were repeatedly reposting on my blog was the first clue of course. I realized it was a post I had briefly visited whilst cruising through the new posts section earlier that morning. Nonetheless at this point I still couldn't see how they had got me.

I set recovery in progress by going to the steemit menu - the three lines in the top right of the screen

26226080_Unknown.JPG

and clicking on stolen accounts recovery.

26226128_Unknown.JPG

I put in my last working password and my email address and was directed to wait for an email with recovery news.

I waited. Every few minutes I checked my email for a message from steemit. I waited. Minutes turned into hours and still nothing in my email.

I thought I would contact a couple of my steemit friends and followers that I talk to on Discord to warn them what had happened to my account. They said they would find out what they could. And find out they did And actually solved the mystery for me as to how the theft had happened.

Earlier that day I had clicked on a post entitled something like - At last I found a glitch in Steemit.

There was a link on the page to take the reader to more information - I had clicked on it .

At the moment I clicked on that link a sign in for returning users appeared. This was the series of events I was reminded of when my dear friend from steemph @immarojas sent me the following picture to reveal my error.

IMG_4508.PNG

As you can see in the top left corner of the screen it clearly states non secure site. I didn't notice. I didnt think to look even. I just saw what I often see during days in and out of steemit which is the familiar box for signing in.
Had I stopped to scrutinize the page there would have been more than one sketchy looking aspect which would have alerted me but I wasn't looking for such things.

Importantly as pointed out by my new dear friend @drakos and I quote - The https isn't always the best indicator, phishing websites can have a valid SSL certificate. Instead, you need to look at the FULL URL you're visiting including the https, like https://steemit.com. Phishing sites will often trick you into something like https://steeemit.com.

Then I made another glaring mistake in my personal security. I signed in using my main password rather than my private posting key which while giving me full access to my account would only give a hacker access to post on the account and not access to do things in my wallet.

So at this point I was no longer on steemits website and handing over my main steemit password !!!!

Of course they had me!

They had woven their web and I had walked straight into it.

26225760_Unknown.JPG

As the hours passed and still no email on recovery I watched as the dollars disappeared , my voting power went ever downward and my followers started to decrease in numbers. My surfer girl icon got changed for a cat of the hackers choosing and contaminated posts were continuously being added to my blog. The only plus point was that my steem power could not be easily disappeared. I watched in agony as the hacker proceed to first attempt to power down my steem and then seemingly give up and cancel the power down. At the end of the day I still had not heard from steemit recovery.
I was gutted!
By the next morning I felt entitled to ask how much longer this was likely to take without seeming like a nag. I knew other accounts had been stolen along with mine and that I might have to be patient. So I got into steem.chat and spoke with the steemabuse volunteers hoping for some reassuring news. As I was pressing for contact to a higher power from whom to beg a quick recovery, thankfully @drakos told me to contact @andrarchy for immediate help with stolen account recovery.
Within minutes of me contacting @andrarchy the email arrived and my account was recovered.

It was all over as suddenly as it began. It took me some hours to clean up the mess left from the hacker in my blog and there are still a bunch of resteems on my blog from him that I cannot delete. This is the scar left to tell the tale but I am grateful to be scarred yet alive still in the community. I am weakened by the theft of my cash but hopefully in the coming days my posts will generate enough to cover the loss and I shall feel totally recouped voting wise. I only have the strength to comment right now around the community - please excuse me for not upvoting your posts for the next few days.

So to sum up, if you are new here like me take care of your account. Do not sign in with your primary password and always be vigilant that posts don't lead you away from steemit to insecure sites. There are constantly elements at work that would strive to upset our community but at the same time be reassured that the block chain here is protecting your crypto like nowhere else can right now.

Be safe.

Steem on!

Have a beautiful day.

In the interests of protecting the most number of people here PLEASE RESTEEM this post.

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

I'm glad that you managed to recover your account. Hope you'll quickly go back on track. I'll share your story with a few of my followers to spread the word around. Hold on and good luck!

Thank you very much, I so appreciate your support xx

So sorry this happened to you. Just a reminder of how careful we should be with our passwords and to stay vigilant. Glad you were able to make it back and provide us with this informative post. I'll be resteeming it to help others.

thank you very much for your kind comment and for the resteem. I am so relieved to be back.

Wow, that is super scary and frustrating! Hopefully you will be back on track quickly.

thanks for your kind comment

That's so awful!! I saw the posts they were posting and knew right away it couldn't be you! I'm glad you're back! :)

Thanks very much @jamisa it was a terribly long and painful 36 hours 😂

please resteem this to help protect the community.

Welcome back @sallybeth23 resteemed and upvoted :-)

Thanks very much @shasta that is much appreciated.

Sunna Ma Bastagezz !!!

Thanks for your support!

This post received a 2.11% upvote from @randowhale thanks to @sallybeth23! To learn more, check out @randowhale 101 - Everything You Need to Know!

The https isn't always the best indicator, phishing websites can have a valid SSL certificate. Instead, you need to look at the FULL URL you're visiting including the https, like https://steemit.com. Phishing sites will often trick you into something like https://steeemit.com.

Oh thank you @drakos you are still saving my life! ;)
That is invaluable information that I am now editing in to the post above.

damn they can also try steemitt.com ?

Opps, I thought the same that she would have entered her master key in that, but at the same time I was really confused as to how can someone with a good reputation can do that, that was really confusing for me , but anyhow its a pleasure to have you again :)

I have a good reputation from my hard work here but I was still a little naive of the dangerous world I live in haha I have grown up fast in the last few days.
Thanks for your support.

haha thats good to hear ;D

  ·  7 years ago (edited)

So happy this was resolved :D

Every one please upvote and resteem this post to let all Steemians know how to avoid this fate themselves!

Thanks for the resteem and kind comment @icedrum

I am glad it is over and you are back.

Upped and resteemed.

Thanks very much for the lovely comment and resteem - It is great to be back =)

congratulation friend awesome post.please follow me and vote my post.all time I with you. @shiqder

thank you

This is the nightmare of nightmares. Thank your for so openly sharing this experience, because it can happen to anyone at any time.

Hindsight is easy we all know that, but sharing something like this is not.

So thank you most kindly and I am happy that you got the help from this great community. There are really a lot of good people on here !

Thank you @dandesign86 for your kind comment. This is a great community full of strength and positivity.

You are welcome ! Keep Steeming :)

Thanks for sharing this :o I resteemed it ;)

@ yoganarchista thank you very much that is so appreciated!! xxx

What an a horrible experience! I'm going to read up properly about keeping my keys and password now.

thanks for your comment - yes it was nasty- do learn how to protect yourself xx
following you in Taiwan too now btw

Good to know ! Hope ya good now !

Thanks yes I am fighting fit again - ever onward!!

Lo bueno es que estás de regreso! saludos :D

muchas gracias amigo xx

Now we all know better! I knew something was up. Rebound and grow wiser.

Yes thank you that is true. What doesn't kill us only makes us stronger.

This is quite a story - so sorry this happened to you. I passed this on to my friends as a warning to be careful, and also resteemed it. I hope your computer is safe. There are programs out there that can, once installed on your computer, read every keystroke, and the hacker can then just get all your log-in information and everything else! Some of those programs cannot be detected with a regular scan, it may need a deep scan by an expert to find them. I would also strongly advise to not let someone else use your computer to just 'check something out' -they might import a virus. This has happened to someone I know - and it was her boyfriend that was the culprit!

so I looked and found a whole bunch of similar hacker posts, like this one:
https://steemit.com/steemit/@raphi00/glitch-in-steemit
stupid idiot doesn't even know how to spell glitch (on the meme)

Thank you for the resteem and thank you very much for this important information. Sorry your friend had that happen too! How awful!

Something strange happened to me a few days ago. I backtracked to an article I had read, clicked on a link and the "returning users: login" flashed for a moment on my screen and then was gone. I didn't click on it and my password was already there (in dots). I haven't noticed anything out of the ordinary yet, but could somebody have planted a Trojan or maybe are just biding their time until I have more Steem (don't have much yet) before they rip me off? You got me worried. What should I do? I could probably go back and find the post where this happened without much problem. Should I alert my followers? Always something!

I think that is nothing to worry about but best you talk to the steem.chat team of volunteers on steem abuse if you have any concerns.

This post has received a 1.29 % upvote from @booster thanks to: @sallybeth23.

Oh damn, this can happen to me too, like clicking on a link in an article, got to be careful.

May this never happen to you again. Thankyou so much for sharing this.

thanks very much for your comment. Yes be careful. I am moving much more carefully around now myself! haha

Hehe

thanks for the summary and the details - resteemed and I guess I will read through again tomorrow morning and many others will - so happy and glad for you that you are back and shared this with us... cheers from the seven mountains in Germany

thank you very much for the resteem and lovely comment. Your blog looks really nice so I am following you.

Have a beautiful day!

thank you @sallybeth23 and a beautiful day to you - just now starting into the day here, kids are all out of the house for the next three hours, so I can get some chores done.... but, before I start them, I'll enjoy my peaceful morning coffee and and steemit :-) cheers from the seven mountains in Germany

Mmmm sounds blissful.

thanks for the information you uploaded ... i learned many things .. again thaking you for spreading suck kind of information (Y) .. and your this post compels me to start following you ... you can also follow me back @heisali

thank you I already am following you. Do pay attention now haha that is how things happen by not paying attention. haha

please resteem this to help protect the community.

hahahah ok i am gona resteam it (Y)

This wonderful post has received a bellyrub 1.39 % upvote from @bellyrub thanks to this cool cat: @sallybeth23. My pops @zeartul is one of your top steemit witness, if you like my bellyrubs please go vote for him, if you love what he is doing vote for this comment as well.

Damn that's so messed up. I saw the weird post from "you" yesterday and was like, whatttt? Fishy as hell it was, I instantly thought you must've been hacked as it was not like you. Resteemed. And sorry this happened to you and shoutout to the Steemians @andrarchy & @drakos who were able to help you so quickly!

thanks very much it was a horrid experience for sure. But super cool to be back!!

Happy to have you back!!! 👋🏻
Thank you for the update and for your advice. I think it was the day before yesterday when I told my hubby about you and the strange changes on your account and we speculated what could have been happened. See, people noticed and at least worried and thought about you. Same thing could have happened to me, I am afraid. Thank you again and all the best from the two of us! 😘

Thank you truly for your comment and concern and for noticing my plight as it unfolded! You are good friends to have.

Your are welcome! 😊

How awful!!! Glad you're back! Hang in there.. Thank you for posting and letting us aware of what you had to terribly go thru!

Thank you so much for your lovely comment - I will get stronger every day from this moment onwards.
It is wonderful to be back.
You have a new follower @evelynkpallatt xxx
MANY THANKS FOR THE RESTEEM TOO!!!

I totally agree.. you can only get stronger!! Thank you for following me. And my pleasure for the resteem!

Glad you are back @sallybeth23 and thanks for explaining what happened to you. Using private password info. especially. resteem and re-follow.

thanks very much @manorvillemike it is good to have you back as a follower! xx And many thanks for the resteem.

It's very stressful isn't it?

I just did a post with some info about keys that may be helpful for anyone wanting to avoid all this.

Glad to hear you got your account back.

https://steemit.com/steemit/@sift666/have-i-been-hacked-or-blocked

thanks for that

PS - I just realised it was your account that I was reading about when I had problems with mine - yours was the horror story everyone was posting about!

Yes indeed it was mine, nice to be back in control.

where is meep lol.?

@meep - I hope you are still with us!!!

What a terrible thing, I truly feel with you!

A big thank you for the warning. Hope they'll get these guys!

Thank you so much xxx

Don't feel too bad, that was a pretty good fake.

Hard not to learn from such a gut-wrenching event =/

Thanks for your kind comment - all praise to the block chain for protecting my steem I have to say. 👌

I'm so sorry that this happened to you!
I've seen that pop up message a couple of times and assumed it was just another glitch, so who knows what I've done. Changed the password now.

I have some questions.

I've tried to log in with my posting key, but I always get an error. Any time I try to log in with anything other than my password I get errors saying it's the wrong key.
I haven't found anything that explains it to me properly.
Can anyone help?

It is the private posting, not regular posting key that you need so .... You need to first log in with your master password then go to permissions and to the right of your posting key is a small box that says Private key - show - so reveal that private key by clicking on that and then copy the private key. Log out and log back in using that instead of the master password.

I've tried that but still get errors. I'll give it another go.
Thanks for the advice!

Oh dear sorry to hear that and this is the extent of my knowledge to help you but I am sure there are people at steem.chat that can quickly put you right.
Best of luck

phishing is the fuckest method ever but here its killer man i mean i always saw phishing method on facebook but this is really dangerous !

It's true we have to be constantly vigilant but also learn how to protect ourselves.

I just read about this glitch scam a short while ago, maybe the person had come across your story. Thanks for spreading awareness. Upvoted, hopefully this post will help you recover some steem.

Thanks for the upvote and support. It is very much appreciated.

  ·  7 years ago Reveal Comment