Account details leaked/hacked

Roker Rick

Full Back
My email account used on here was accessed today. This is the only site I use this email on, so it's definitely related to this site.

Without going into details, who do I speak to regarding this?
 


We do store email details here, but not passwords. (its a double salted one way encryption that is stored on the database, so no way to decrypt it)

Your browser will also encrypt everything between your device and here, so the only way this could be decoded in transit is a man in the middle attack. Do you use a VPN as they can allow this?

Do you use the same password in multiple places?

I would be looking more at your device. What have you installed on their recently? Have you visited any “dodgy” websites?

I would also ask what makes you think your email account was accessed. What is the evidence of this?
 
I would also ask what makes you think your email account was accessed. What is the evidence of this?
I recieved a notification that security details had been altered. On my activity list it shows an unauthorised log-in.

I'd rather if you replied by PM, for obvious reasons.
 
Ok will contact via PM.

I have every confidence in our security, but I feel it is important to discuss whatever we can transparently, then in the unlikely event anyone is affected by any breach it gives others with a similar experience a chance to give their input.

As above, we don't store passwords on the database, only the double salted encrypted version of it - so effectively near impossible to decrypt.

When you enter your password to logon, it is re-encrypted using the same method and compared with the encrypted version we have on file - but it is never stored.
Of course if you have a trojan on your device, this can be intercepted.
 

Back
Top