Notices
Racing & Drivers Education Forum
Sponsored by:
Sponsored by:

Clubregistration Hacked?

Thread Tools
 
Search this Thread
 
Old 08-09-2018, 03:42 PM
  #16  
dan212
Rennlist Member
 
dan212's Avatar
 
Join Date: Sep 2007
Location: NYC
Posts: 1,671
Received 136 Likes on 97 Posts
Default

I got the same ransomeware email. Same unique address in use.

Originally Posted by ZAPmobile
My wife (also a PCA member) and I reported this to the national office 3-4 weeks ago, and she identified the spam as coming from the club registration site. She asked that someone get back to her (never happened), and that a notice should be sent out to ALL people potentially affected by this hacking. Further, she strongly suggested that this be done ASAP. Last night, I received a similar message to hers, so clearly, in the interim 3-4 weeks, nothing has been done. Needless-to-say, she was less than amused and called PCA headquarters again today.

She was able to directly identify the password (in our case) as being unique to the club registration site, just in case anyone is wondering. The new hack is trying to extort money from members so it won't be published that they are looking at **** sites. In many cases, we are sure that this is not the case, as they claim to have noted on the supposedly hacked computers.
Old 08-09-2018, 04:22 PM
  #17  
Wild Weasel
Drifting
Thread Starter
 
Wild Weasel's Avatar
 
Join Date: May 2016
Posts: 2,032
Received 311 Likes on 175 Posts
Default

Originally Posted by ZAPmobile
In many cases, we are sure that this is not the case
In many cases? Not all? Are you saying they might still email out video of my junk to everyone I know?

I kinda think lots of the people on my contact list might get a kick out of that.
Old 08-09-2018, 06:25 PM
  #18  
Sean F
NASA Racer
Rennlist Member
 
Sean F's Avatar
 
Join Date: Jul 2005
Location: Westchester, NY
Posts: 4,778
Received 34 Likes on 20 Posts
Default

Again to be clear on implications here - these criminals likely have physical address of people known to have race cars...i.e., better off than most and a pretty good robbery target.
Old 08-09-2018, 06:27 PM
  #19  
mpruden
Three Wheelin'
 
mpruden's Avatar
 
Join Date: Sep 2013
Location: Folsom CA
Posts: 1,673
Received 51 Likes on 35 Posts
Default

Just so I understand, you guys are receiving emails with usernames and passwords included (that is, written out in plain text) in the actual email message?

BTW, I'm just a guy with a background in similar systems. I'm in no way affiliated with clubregistration.net.
Old 08-09-2018, 06:52 PM
  #20  
ZAPmobile
Rennlist Member
 
ZAPmobile's Avatar
 
Join Date: Jan 2007
Location: Hillsborough, North Carolina
Posts: 889
Received 6 Likes on 3 Posts
Default

Yes
Old 08-09-2018, 07:07 PM
  #21  
laranja
Pro
 
laranja's Avatar
 
Join Date: Mar 2016
Posts: 651
Received 15 Likes on 15 Posts
Default

It's very possible for hackers to unencrypt password files. Many sites use weak / easily broken encryption, and many
passwords can be tested & quickly unencrypted using dictionary attacks.

Simple truth is most sites don't have the time / resources / expertise to prevent these types of hacks.
Old 08-09-2018, 07:32 PM
  #22  
Sean F
NASA Racer
Rennlist Member
 
Sean F's Avatar
 
Join Date: Jul 2005
Location: Westchester, NY
Posts: 4,778
Received 34 Likes on 20 Posts
Default

Also, I have been getting notifications of unauthorized login attempts to other accounts = obviously trying out the hacked username/password combo for access to banking, etc.
Old 08-09-2018, 08:15 PM
  #23  
The Fat Kid
Pro
 
The Fat Kid's Avatar
 
Join Date: Mar 2016
Location: New England
Posts: 662
Likes: 0
Received 41 Likes on 33 Posts
Default

How many accounts were hacked?

Originally Posted by Sean F
putting aside financial data, you do store address and phone number - correct? So if they have passwords, i'm guessing they have that info as well.
They would certainly have access to all of that info with username and password...

Originally Posted by ZAPmobile
My wife (also a PCA member) and I reported this to the national office 3-4 weeks ago, and she identified the spam as coming from the club registration site. She asked that someone get back to her (never happened), and that a notice should be sent out to ALL people potentially affected by this hacking. Further, she strongly suggested that this be done ASAP. Last night, I received a similar message to hers, so clearly, in the interim 3-4 weeks, nothing has been done. Needless-to-say, she was less than amused and called PCA headquarters again today.

She was able to directly identify the password (in our case) as being unique to the club registration site, just in case anyone is wondering. The new hack is trying to extort money from members so it won't be published that they are looking at **** sites. In many cases, we are sure that this is not the case, as they claim to have noted on the supposedly hacked computers.
Thanks for trying to get them to alert users to the hack. A notification email would have been nice.
Old 08-10-2018, 01:10 PM
  #24  
calvarado312
2nd Gear
 
calvarado312's Avatar
 
Join Date: Aug 2018
Posts: 2
Likes: 0
Received 0 Likes on 0 Posts
Default

ClubReg has been made aware of the breach and we are working to contact the accounts. An official notice will go out this weekend or Monday. We do take this very seriously. Again we are asked about credit card info. We do NOT store that information on our servers, nor do we have access to it.

We do apologize for the inconvenience this may cause everyone. Please understand that while we do not discuss our methods of encryption we are already looking into how to protect it further to minimize this happening again in the future. If you wish to discuss this you may call our offices directly at 512-273-5016

Thank you,

Chris Alvarado
ClubRegistration.net
Old 08-10-2018, 02:15 PM
  #25  
forklift
Rennlist Member
 
forklift's Avatar
 
Join Date: Nov 2003
Location: VA
Posts: 2,182
Received 13 Likes on 10 Posts
Default

It is my understanding that the sextorion (sp) emails went out to a LOT of people worldwide. A few have noted that it was their old Linkedin pw but could be from other hacks also.

https://www.businessinsider.com/new-...bitcoin-2018-7
Old 08-10-2018, 02:28 PM
  #26  
Wild Weasel
Drifting
Thread Starter
 
Wild Weasel's Avatar
 
Join Date: May 2016
Posts: 2,032
Received 311 Likes on 175 Posts
Default

Originally Posted by forklift
It is my understanding that the sextorion (sp) emails went out to a LOT of people worldwide. A few have noted that it was their old Linkedin pw but could be from other hacks also.

https://www.businessinsider.com/new-...bitcoin-2018-7
I just keep waiting for the email blast to go out. I'm intrigued. It occurs to me that I don't even HAVE a webcam so I'm curious as to how they did it.

DO THEY HAVE SOMEONE IN MY HOUSE??
Old 08-11-2018, 11:25 AM
  #27  
Glyndellis
Pro
 
Glyndellis's Avatar
 
Join Date: Oct 2013
Posts: 636
Received 182 Likes on 112 Posts
Default

People look at **** sites on computers? When did that start happening?
Old 08-11-2018, 01:48 PM
  #28  
Der ABT
Burning Brakes
 
Der ABT's Avatar
 
Join Date: Nov 2003
Location: Virginia
Posts: 1,046
Received 37 Likes on 26 Posts
Default

They sent a video that can never be unseen of Gary....i paid to just have them stop sending it...best 100k i ever spent
Old 08-11-2018, 04:52 PM
  #29  
Gary R.
Rennlist Member
 
Gary R.'s Avatar
 
Join Date: Dec 2004
Location: Valencia, Spain
Posts: 15,598
Received 290 Likes on 172 Posts
Talking

Originally Posted by Der ABT
They sent a video that can never be unseen of Gary....i paid to just have them stop sending it...best 100k i ever spent
Was it this one, I know you always hated it....

Old 08-11-2018, 06:19 PM
  #30  
LuigiVampa
WRONGLY ACCUSED!
Rennlist Member
 
LuigiVampa's Avatar
 
Join Date: Nov 2011
Location: PCA Gulag
Posts: 14,992
Received 4,427 Likes on 1,942 Posts
Default

Originally Posted by Glyndellis
People look at **** sites on computers? When did that start happening?
Really funny offbroadway show to see when you have had a few drinks - right on topic here:



Quick Reply: Clubregistration Hacked?



All times are GMT -3. The time now is 11:07 AM.