Skip to content

Scam: fake 'server migration' phishing got my credentials

General Discussion by wendy 25 replies 3.9K views
#11
wendy said:
Contabohosting-migration.com

Different domain in my case: contabo-apac-transition.net. Same registrar though. Also Namecheap (https://www.namecheap.com). I have saved the WHOIS history if anyone needs it for a report.

The HostHatch clients I mentioned were on the Singapore and Tokyo locations. Both received the "data sovereignty" version. I have since enabled 2FA on every panel I administer and I am requiring it for my reseller clients too.

conbini > datacenter snacks
#12
steveipw said:
ZFS send to a separate pool

This is the way! But you are preaching to the choir here friend! The people who need to hear it are running WordPress on ten dollar shared hosting with no backups! We need a sticky thread! "You are not the customer, you are the product, and the product is burning!"

I checked the certificate on wendy's domain! Let's Encrypt 90-day! The phishing site had a Sectigo three-month! Close but not the same! Always check!

#13

I am in Milan and I administrate servers for a small design collective. We use HostHatch in Milan and I received nothing, but my colleague in Madrid got the same email kenji3 described. Same "data sovereignty migration" text. So it is not even all accounts at a provider, they are selecting by region or by published location data.

I have checked our MX records and we have no DKIM on our own domain either. I am fixing that this weekend. Embarrassing.

#14

I am in Lyon, I administrate the servers for my association since 2018. We are on OVHcloud Gravelines. I received a fake "maintenance migration" email two weeks ago but I did not click because the French was slightly wrong. "Veuillez verifier vos informations" with no accent on the first e. A native speaker would not write that.

I reported it to OVHcloud through their ticket system. They answered in 48 hours with a generic "do not click links in emails" response. Not helpful.

prix fixe infrastructure: €5/mo
#15

This thread is making me anxious about my own setup. I use Vultr in Los Angeles and I have 2FA but it is SMS. Should I be worried about SIM swap? I am reading about TOTP now. Is Authy still the standard or is there something better?

#16
astrorock9 said:
SMS 2FA

Stop. Now. TOTP minimum, hardware key ideally. I like the Hypervisor connoisseur label but honestly the overselling thread is more fun than this security theatre.

Vultr supports TOTP in their panel. Go enable it. Takes two minutes. Authy is fine, Bitwarden has TOTP built in if you already use that, or KeePass with a plugin. The protocol is standard, the container does not matter much.

On the actual topic: I have seen this same phishing kit targeting Hetzner customers in the last week. "Storage upgrade required." Same CSS, different story.

virsh list --all | wc -l: 47
#17

I am late to this but I got the exact same email as wendy. I clicked it. I am ashamed to say I clicked it. I do not have offsite backups. I am now running photorec on the VPS disk image Vultr let me download before terminating. Four years of a photography blog. Please tell me someone has recovered from worse.

8 #18
steven_dzire said:
Four years of a photography blog.

I am sorry. That is rough. Photorec will get you JPEGs and maybe some database fragments but do not expect intact posts. Check if the Wayback Machine has snapshots. Check Google cache with cache:yourdomain.com. If your DNS was pointed away quickly, the original site might still be in there.

For the future: rclone to Backblaze B2 is cheap. Really cheap. Or even just rsync to another VPS. The backup does not have to be fancy, it just has to exist somewhere else.

Have you tried restarting it?
4 #19

Following. I am on Contabo Nuremberg and I have not received anything yet but I am checking my spam folder now.

#20

Same here. Following.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft