<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Inti De Ceukelaire]]></title><description><![CDATA[Ethical hacker & cybercrime investigator]]></description><link>https://inti.io</link><image><url>https://substackcdn.com/image/fetch/$s_!HLKa!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5128d80f-faa2-454a-9bc9-d6465b16dfad_1160x1096.png</url><title>Inti De Ceukelaire</title><link>https://inti.io</link></image><generator>Substack</generator><lastBuildDate>Wed, 08 Apr 2026 08:49:11 GMT</lastBuildDate><atom:link href="https://inti.io/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[INTI Comm. V.]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[intidc@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[intidc@substack.com]]></itunes:email><itunes:name><![CDATA[Inti De Ceukelaire]]></itunes:name></itunes:owner><itunes:author><![CDATA[Inti De Ceukelaire]]></itunes:author><googleplay:owner><![CDATA[intidc@substack.com]]></googleplay:owner><googleplay:email><![CDATA[intidc@substack.com]]></googleplay:email><googleplay:author><![CDATA[Inti De Ceukelaire]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[How I infiltrated phishing panels targeting European banks and tracked down their operators]]></title><description><![CDATA[Good phishers clearly aren't always good programmers.]]></description><link>https://inti.io/p/how-i-infiltrated-phishing-panels</link><guid isPermaLink="false">https://inti.io/p/how-i-infiltrated-phishing-panels</guid><dc:creator><![CDATA[Inti De Ceukelaire]]></dc:creator><pubDate>Mon, 09 Mar 2026 05:34:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Mt4c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F434cb028-ba20-4ae9-8983-31a2ca85dea6_2972x1762.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I live in the most lucrative country for phishing scams in the EU. Every month, millions of euros are lost, and according to recent reporting, nearly two-thirds of complaints to banks are ignored.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p><p>After hearing too many personal stories of hard-working individuals losing their life savings in a matter of minutes, I decided it&#8217;s time to take action.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://inti.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>In the past few weeks, I&#8217;ve tracked down the scammers responsible for dozens of phishing operations targeting several banks in Europe. </p><p>I took down their panels, gathered evidence and hunted down their identities.</p><p>Despite knowing who they are and multiple attempts to report them to the respective banks, these folks are still on the loose, and I will need your help bringing them to justice. </p><p><strong>If you are a victim of phishing and recognize some of the phishing panels below, or know someone who does, please contact me at phishing [at] inti.io with your story and evidence.</strong></p><p>Here&#8217;s how it unfolded:</p><h3>Becoming the phisher to reveal their identity</h3><p>End of January, a scammer sent me a phishing e-mail impersonating Belgian bank Argenta to let me know that my banking card reader needs an update:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tVM5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37000b0b-0a24-4970-8ced-6c08bd8f41ac_1446x920.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tVM5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37000b0b-0a24-4970-8ced-6c08bd8f41ac_1446x920.png 424w, https://substackcdn.com/image/fetch/$s_!tVM5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37000b0b-0a24-4970-8ced-6c08bd8f41ac_1446x920.png 848w, https://substackcdn.com/image/fetch/$s_!tVM5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37000b0b-0a24-4970-8ced-6c08bd8f41ac_1446x920.png 1272w, https://substackcdn.com/image/fetch/$s_!tVM5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37000b0b-0a24-4970-8ced-6c08bd8f41ac_1446x920.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tVM5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37000b0b-0a24-4970-8ced-6c08bd8f41ac_1446x920.png" width="1446" height="920" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/37000b0b-0a24-4970-8ced-6c08bd8f41ac_1446x920.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:920,&quot;width&quot;:1446,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:611354,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37000b0b-0a24-4970-8ced-6c08bd8f41ac_1446x920.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tVM5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37000b0b-0a24-4970-8ced-6c08bd8f41ac_1446x920.png 424w, https://substackcdn.com/image/fetch/$s_!tVM5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37000b0b-0a24-4970-8ced-6c08bd8f41ac_1446x920.png 848w, https://substackcdn.com/image/fetch/$s_!tVM5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37000b0b-0a24-4970-8ced-6c08bd8f41ac_1446x920.png 1272w, https://substackcdn.com/image/fetch/$s_!tVM5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37000b0b-0a24-4970-8ced-6c08bd8f41ac_1446x920.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Dutch text message reminding me to active a new card reader</figcaption></figure></div><p>I got curious, so decided to inspect the website using Chrome&#8217;s devtools to see what&#8217;s going on</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yAEu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c700628-734d-4a0c-9873-4db8a84b1a62_2972x1758.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yAEu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c700628-734d-4a0c-9873-4db8a84b1a62_2972x1758.png 424w, https://substackcdn.com/image/fetch/$s_!yAEu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c700628-734d-4a0c-9873-4db8a84b1a62_2972x1758.png 848w, https://substackcdn.com/image/fetch/$s_!yAEu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c700628-734d-4a0c-9873-4db8a84b1a62_2972x1758.png 1272w, https://substackcdn.com/image/fetch/$s_!yAEu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c700628-734d-4a0c-9873-4db8a84b1a62_2972x1758.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yAEu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c700628-734d-4a0c-9873-4db8a84b1a62_2972x1758.png" width="1456" height="861" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5c700628-734d-4a0c-9873-4db8a84b1a62_2972x1758.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:861,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:832276,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c700628-734d-4a0c-9873-4db8a84b1a62_2972x1758.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yAEu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c700628-734d-4a0c-9873-4db8a84b1a62_2972x1758.png 424w, https://substackcdn.com/image/fetch/$s_!yAEu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c700628-734d-4a0c-9873-4db8a84b1a62_2972x1758.png 848w, https://substackcdn.com/image/fetch/$s_!yAEu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c700628-734d-4a0c-9873-4db8a84b1a62_2972x1758.png 1272w, https://substackcdn.com/image/fetch/$s_!yAEu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c700628-734d-4a0c-9873-4db8a84b1a62_2972x1758.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Inspecting the phishing page background activity through DevTools</figcaption></figure></div><p>Once I had entered some fake card details, the page made a request to the pages <code>check-action.php</code> and <code>loading.php</code>.</p><p>I decided to take a look at the HTML source code of loading.php to see if I could get any clues about the phishing framework used. <br><br>I immediately spotted some <em>terrible</em> code that would fetch text document from the administration area containing a list of IP&#8217;s that aren&#8217;t welcome, redirecting them to an arbitrary website:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bITt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb15704f-4f56-4922-8fe9-474bbaa8ccce_2976x1786.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bITt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb15704f-4f56-4922-8fe9-474bbaa8ccce_2976x1786.png 424w, https://substackcdn.com/image/fetch/$s_!bITt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb15704f-4f56-4922-8fe9-474bbaa8ccce_2976x1786.png 848w, https://substackcdn.com/image/fetch/$s_!bITt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb15704f-4f56-4922-8fe9-474bbaa8ccce_2976x1786.png 1272w, https://substackcdn.com/image/fetch/$s_!bITt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb15704f-4f56-4922-8fe9-474bbaa8ccce_2976x1786.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bITt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb15704f-4f56-4922-8fe9-474bbaa8ccce_2976x1786.png" width="1456" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db15704f-4f56-4922-8fe9-474bbaa8ccce_2976x1786.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1338533,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb15704f-4f56-4922-8fe9-474bbaa8ccce_2976x1786.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bITt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb15704f-4f56-4922-8fe9-474bbaa8ccce_2976x1786.png 424w, https://substackcdn.com/image/fetch/$s_!bITt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb15704f-4f56-4922-8fe9-474bbaa8ccce_2976x1786.png 848w, https://substackcdn.com/image/fetch/$s_!bITt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb15704f-4f56-4922-8fe9-474bbaa8ccce_2976x1786.png 1272w, https://substackcdn.com/image/fetch/$s_!bITt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb15704f-4f56-4922-8fe9-474bbaa8ccce_2976x1786.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">A hidden link to a part of the admin section</figcaption></figure></div><p>Many amateur phishing panels store their data in plain text files rather than databases, likely because they are simpler to deploy.</p><p>Now that I had located the administration panel, I tried navigating to it directly. I was presented with a login page:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Mt4c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F434cb028-ba20-4ae9-8983-31a2ca85dea6_2972x1762.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Mt4c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F434cb028-ba20-4ae9-8983-31a2ca85dea6_2972x1762.png 424w, https://substackcdn.com/image/fetch/$s_!Mt4c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F434cb028-ba20-4ae9-8983-31a2ca85dea6_2972x1762.png 848w, https://substackcdn.com/image/fetch/$s_!Mt4c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F434cb028-ba20-4ae9-8983-31a2ca85dea6_2972x1762.png 1272w, https://substackcdn.com/image/fetch/$s_!Mt4c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F434cb028-ba20-4ae9-8983-31a2ca85dea6_2972x1762.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Mt4c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F434cb028-ba20-4ae9-8983-31a2ca85dea6_2972x1762.png" width="1456" height="863" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/434cb028-ba20-4ae9-8983-31a2ca85dea6_2972x1762.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:863,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1074198,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F434cb028-ba20-4ae9-8983-31a2ca85dea6_2972x1762.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Mt4c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F434cb028-ba20-4ae9-8983-31a2ca85dea6_2972x1762.png 424w, https://substackcdn.com/image/fetch/$s_!Mt4c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F434cb028-ba20-4ae9-8983-31a2ca85dea6_2972x1762.png 848w, https://substackcdn.com/image/fetch/$s_!Mt4c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F434cb028-ba20-4ae9-8983-31a2ca85dea6_2972x1762.png 1272w, https://substackcdn.com/image/fetch/$s_!Mt4c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F434cb028-ba20-4ae9-8983-31a2ca85dea6_2972x1762.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I don&#8217;t know the username and password, but perhaps I don&#8217;t need it.</figcaption></figure></div><p>Two things struck me here:</p><ol><li><p>Scammers still like outdated h4ck0r visuals for their phishing page</p></li><li><p>&#8220;Or your IP Address is Change&#8221; indicates that login sessions are likely tied to the users&#8217; IP address </p></li></ol><p>Now I had a problem, because I didn&#8217;t know the username and password, and I did not know the scammers IP address either.</p><p>Then it hit me: the scammers likely tested the panel locally on their own machine before deploying it. If the software trusted requests coming from <code>127.0.0.1</code> (localhost), there was a chance the original session file had been uploaded along with the panel.</p><p>So I used a proxy tool called <a href="https://portswigger.net/burp">Burp Suite</a> to make the website believe I&#8217;m accessing the website locally on my computer (with IP address 127.0.0.1)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gNgP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3fd3524-df92-401d-97a9-b5699b758034_2952x1690.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gNgP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3fd3524-df92-401d-97a9-b5699b758034_2952x1690.png 424w, https://substackcdn.com/image/fetch/$s_!gNgP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3fd3524-df92-401d-97a9-b5699b758034_2952x1690.png 848w, https://substackcdn.com/image/fetch/$s_!gNgP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3fd3524-df92-401d-97a9-b5699b758034_2952x1690.png 1272w, https://substackcdn.com/image/fetch/$s_!gNgP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3fd3524-df92-401d-97a9-b5699b758034_2952x1690.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gNgP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3fd3524-df92-401d-97a9-b5699b758034_2952x1690.png" width="1456" height="834" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a3fd3524-df92-401d-97a9-b5699b758034_2952x1690.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:834,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:719066,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3fd3524-df92-401d-97a9-b5699b758034_2952x1690.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gNgP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3fd3524-df92-401d-97a9-b5699b758034_2952x1690.png 424w, https://substackcdn.com/image/fetch/$s_!gNgP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3fd3524-df92-401d-97a9-b5699b758034_2952x1690.png 848w, https://substackcdn.com/image/fetch/$s_!gNgP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3fd3524-df92-401d-97a9-b5699b758034_2952x1690.png 1272w, https://substackcdn.com/image/fetch/$s_!gNgP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3fd3524-df92-401d-97a9-b5699b758034_2952x1690.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Making the app believe it&#8217;s running locally by changing my IP to 127.0.0.1</figcaption></figure></div><p>Then I refreshed and boom goes the dynamite &#128165;:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wSpd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f83683-e494-46c9-84ce-ab930e967e28_2968x1704.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wSpd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f83683-e494-46c9-84ce-ab930e967e28_2968x1704.png 424w, https://substackcdn.com/image/fetch/$s_!wSpd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f83683-e494-46c9-84ce-ab930e967e28_2968x1704.png 848w, https://substackcdn.com/image/fetch/$s_!wSpd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f83683-e494-46c9-84ce-ab930e967e28_2968x1704.png 1272w, https://substackcdn.com/image/fetch/$s_!wSpd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f83683-e494-46c9-84ce-ab930e967e28_2968x1704.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wSpd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f83683-e494-46c9-84ce-ab930e967e28_2968x1704.png" width="1456" height="836" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/09f83683-e494-46c9-84ce-ab930e967e28_2968x1704.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:836,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:395303,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f83683-e494-46c9-84ce-ab930e967e28_2968x1704.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wSpd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f83683-e494-46c9-84ce-ab930e967e28_2968x1704.png 424w, https://substackcdn.com/image/fetch/$s_!wSpd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f83683-e494-46c9-84ce-ab930e967e28_2968x1704.png 848w, https://substackcdn.com/image/fetch/$s_!wSpd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f83683-e494-46c9-84ce-ab930e967e28_2968x1704.png 1272w, https://substackcdn.com/image/fetch/$s_!wSpd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09f83683-e494-46c9-84ce-ab930e967e28_2968x1704.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Hacker voice: &#8220;We&#8217;re in&#8221;</figcaption></figure></div><p>On behalf of the scammer, I could now access the session of the visitors:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sniS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd95de3c-916c-4fa4-90d1-5e96cae929dd_2966x1710.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sniS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd95de3c-916c-4fa4-90d1-5e96cae929dd_2966x1710.png 424w, https://substackcdn.com/image/fetch/$s_!sniS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd95de3c-916c-4fa4-90d1-5e96cae929dd_2966x1710.png 848w, https://substackcdn.com/image/fetch/$s_!sniS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd95de3c-916c-4fa4-90d1-5e96cae929dd_2966x1710.png 1272w, https://substackcdn.com/image/fetch/$s_!sniS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd95de3c-916c-4fa4-90d1-5e96cae929dd_2966x1710.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sniS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd95de3c-916c-4fa4-90d1-5e96cae929dd_2966x1710.png" width="1456" height="839" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd95de3c-916c-4fa4-90d1-5e96cae929dd_2966x1710.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:839,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:494005,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd95de3c-916c-4fa4-90d1-5e96cae929dd_2966x1710.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sniS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd95de3c-916c-4fa4-90d1-5e96cae929dd_2966x1710.png 424w, https://substackcdn.com/image/fetch/$s_!sniS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd95de3c-916c-4fa4-90d1-5e96cae929dd_2966x1710.png 848w, https://substackcdn.com/image/fetch/$s_!sniS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd95de3c-916c-4fa4-90d1-5e96cae929dd_2966x1710.png 1272w, https://substackcdn.com/image/fetch/$s_!sniS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd95de3c-916c-4fa4-90d1-5e96cae929dd_2966x1710.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">This is what a phishing panel looks like</figcaption></figure></div><p>This page allowed the scammer to control what the victim would see on their screen and would allow them to copy/paste their banking token once obtained. From looking at the source code, every action I would take here would be logged to the attackers telegram account by sending a request to <strong>telegramclick.php</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!23iZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179aa9e-0446-4f2a-96f0-5a03c5a03059_2966x1700.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!23iZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179aa9e-0446-4f2a-96f0-5a03c5a03059_2966x1700.png 424w, https://substackcdn.com/image/fetch/$s_!23iZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179aa9e-0446-4f2a-96f0-5a03c5a03059_2966x1700.png 848w, https://substackcdn.com/image/fetch/$s_!23iZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179aa9e-0446-4f2a-96f0-5a03c5a03059_2966x1700.png 1272w, https://substackcdn.com/image/fetch/$s_!23iZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179aa9e-0446-4f2a-96f0-5a03c5a03059_2966x1700.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!23iZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179aa9e-0446-4f2a-96f0-5a03c5a03059_2966x1700.png" width="1456" height="835" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6179aa9e-0446-4f2a-96f0-5a03c5a03059_2966x1700.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:835,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:251546,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179aa9e-0446-4f2a-96f0-5a03c5a03059_2966x1700.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!23iZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179aa9e-0446-4f2a-96f0-5a03c5a03059_2966x1700.png 424w, https://substackcdn.com/image/fetch/$s_!23iZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179aa9e-0446-4f2a-96f0-5a03c5a03059_2966x1700.png 848w, https://substackcdn.com/image/fetch/$s_!23iZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179aa9e-0446-4f2a-96f0-5a03c5a03059_2966x1700.png 1272w, https://substackcdn.com/image/fetch/$s_!23iZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6179aa9e-0446-4f2a-96f0-5a03c5a03059_2966x1700.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Phishing operators have a joystick system to control what their victims see</figcaption></figure></div><p>At this point, I wanted to ensure to stop this scam as soon as possible so that the users currently on the phishers&#8217; page wouldn&#8217;t lose their money.</p><p>My first job was to ensure that the attacker wouldn&#8217;t be alerted. <br><br>Luckily, the admin panel had a delete file functionality that allowed me to traverse paths, so I started with deleting the telegram integration so my actions would be silent for the scammer:</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;afd2d356-419e-4412-941a-ad05a11a2f2c&quot;,&quot;duration&quot;:null}"></div><p>The site would now appear broken for new visitors and no more banking details could be sent to the scammer that was still unaware at this point.</p><p>Now that the phish was no longer functional, I looked for ways to gain access to the files on the server to look for clues of the scammers&#8217; identity.</p><p>The scammer had set up a Wordpress blog on the domain as a fake facade for the panel:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zCEy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c7803a-61fd-4a55-bd9c-f0cf697bf143_3444x1876.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zCEy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c7803a-61fd-4a55-bd9c-f0cf697bf143_3444x1876.png 424w, https://substackcdn.com/image/fetch/$s_!zCEy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c7803a-61fd-4a55-bd9c-f0cf697bf143_3444x1876.png 848w, https://substackcdn.com/image/fetch/$s_!zCEy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c7803a-61fd-4a55-bd9c-f0cf697bf143_3444x1876.png 1272w, https://substackcdn.com/image/fetch/$s_!zCEy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c7803a-61fd-4a55-bd9c-f0cf697bf143_3444x1876.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zCEy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c7803a-61fd-4a55-bd9c-f0cf697bf143_3444x1876.png" width="1456" height="793" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/95c7803a-61fd-4a55-bd9c-f0cf697bf143_3444x1876.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:793,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:205456,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c7803a-61fd-4a55-bd9c-f0cf697bf143_3444x1876.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zCEy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c7803a-61fd-4a55-bd9c-f0cf697bf143_3444x1876.png 424w, https://substackcdn.com/image/fetch/$s_!zCEy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c7803a-61fd-4a55-bd9c-f0cf697bf143_3444x1876.png 848w, https://substackcdn.com/image/fetch/$s_!zCEy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c7803a-61fd-4a55-bd9c-f0cf697bf143_3444x1876.png 1272w, https://substackcdn.com/image/fetch/$s_!zCEy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95c7803a-61fd-4a55-bd9c-f0cf697bf143_3444x1876.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Installing Wordpress next to the phishing panel turned out to be a very big mistake from the scammer&#8230;</figcaption></figure></div><p>He probably should not have done that, as Wordpress allows whoever sets it up to execute their own code and plugins.</p><p>But since I didn&#8217;t set it up, I had to make Wordpress think it wasn&#8217;t installed already first. That turned out to be extremely easy, as I just had to locate a file called <strong>wp-config.php</strong> on the server, <strong>delete</strong> it using the same technique I used to delete <strong>telegramclick.php </strong>earlier,  and refresh the page.</p><blockquote><p>WordPress stores its installation state in a file called <code>wp-config.php</code>. If that file disappears, WordPress assumes it hasn&#8217;t been installed yet and launches the setup wizard:</p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bzNS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9738c30-0bf0-4974-9a28-6ca554bc12c1_3340x1974.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bzNS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9738c30-0bf0-4974-9a28-6ca554bc12c1_3340x1974.png 424w, https://substackcdn.com/image/fetch/$s_!bzNS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9738c30-0bf0-4974-9a28-6ca554bc12c1_3340x1974.png 848w, https://substackcdn.com/image/fetch/$s_!bzNS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9738c30-0bf0-4974-9a28-6ca554bc12c1_3340x1974.png 1272w, https://substackcdn.com/image/fetch/$s_!bzNS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9738c30-0bf0-4974-9a28-6ca554bc12c1_3340x1974.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bzNS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9738c30-0bf0-4974-9a28-6ca554bc12c1_3340x1974.png" width="1456" height="861" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e9738c30-0bf0-4974-9a28-6ca554bc12c1_3340x1974.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:861,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:375163,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9738c30-0bf0-4974-9a28-6ca554bc12c1_3340x1974.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bzNS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9738c30-0bf0-4974-9a28-6ca554bc12c1_3340x1974.png 424w, https://substackcdn.com/image/fetch/$s_!bzNS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9738c30-0bf0-4974-9a28-6ca554bc12c1_3340x1974.png 848w, https://substackcdn.com/image/fetch/$s_!bzNS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9738c30-0bf0-4974-9a28-6ca554bc12c1_3340x1974.png 1272w, https://substackcdn.com/image/fetch/$s_!bzNS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9738c30-0bf0-4974-9a28-6ca554bc12c1_3340x1974.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">After deleting wp-config.php, I could become the new admin</figcaption></figure></div><p>After linking it to a mock database and setting a new username and password, I was now running a Wordpress blog on the same page the scammer had used to host their phishing panel:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uwlo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8398eb3-9d17-4b8c-83e8-5766f197b48e_3456x1972.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uwlo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8398eb3-9d17-4b8c-83e8-5766f197b48e_3456x1972.png 424w, https://substackcdn.com/image/fetch/$s_!uwlo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8398eb3-9d17-4b8c-83e8-5766f197b48e_3456x1972.png 848w, https://substackcdn.com/image/fetch/$s_!uwlo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8398eb3-9d17-4b8c-83e8-5766f197b48e_3456x1972.png 1272w, https://substackcdn.com/image/fetch/$s_!uwlo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8398eb3-9d17-4b8c-83e8-5766f197b48e_3456x1972.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uwlo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8398eb3-9d17-4b8c-83e8-5766f197b48e_3456x1972.png" width="1456" height="831" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8398eb3-9d17-4b8c-83e8-5766f197b48e_3456x1972.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:831,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:761424,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8398eb3-9d17-4b8c-83e8-5766f197b48e_3456x1972.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uwlo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8398eb3-9d17-4b8c-83e8-5766f197b48e_3456x1972.png 424w, https://substackcdn.com/image/fetch/$s_!uwlo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8398eb3-9d17-4b8c-83e8-5766f197b48e_3456x1972.png 848w, https://substackcdn.com/image/fetch/$s_!uwlo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8398eb3-9d17-4b8c-83e8-5766f197b48e_3456x1972.png 1272w, https://substackcdn.com/image/fetch/$s_!uwlo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8398eb3-9d17-4b8c-83e8-5766f197b48e_3456x1972.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;Access granted.&#8221;&#8230; again!</figcaption></figure></div><p>I could now see all the files of the server, including the <strong>argg.zip</strong> backup that the phisher had created and could technically be downloaded by anyone.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jgkW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb70bc93c-9dde-4853-9440-d1b10b0d82c2_2656x1108.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jgkW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb70bc93c-9dde-4853-9440-d1b10b0d82c2_2656x1108.png 424w, https://substackcdn.com/image/fetch/$s_!jgkW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb70bc93c-9dde-4853-9440-d1b10b0d82c2_2656x1108.png 848w, https://substackcdn.com/image/fetch/$s_!jgkW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb70bc93c-9dde-4853-9440-d1b10b0d82c2_2656x1108.png 1272w, https://substackcdn.com/image/fetch/$s_!jgkW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb70bc93c-9dde-4853-9440-d1b10b0d82c2_2656x1108.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jgkW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb70bc93c-9dde-4853-9440-d1b10b0d82c2_2656x1108.png" width="1456" height="607" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b70bc93c-9dde-4853-9440-d1b10b0d82c2_2656x1108.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:607,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:543121,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb70bc93c-9dde-4853-9440-d1b10b0d82c2_2656x1108.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jgkW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb70bc93c-9dde-4853-9440-d1b10b0d82c2_2656x1108.png 424w, https://substackcdn.com/image/fetch/$s_!jgkW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb70bc93c-9dde-4853-9440-d1b10b0d82c2_2656x1108.png 848w, https://substackcdn.com/image/fetch/$s_!jgkW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb70bc93c-9dde-4853-9440-d1b10b0d82c2_2656x1108.png 1272w, https://substackcdn.com/image/fetch/$s_!jgkW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb70bc93c-9dde-4853-9440-d1b10b0d82c2_2656x1108.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">All this work only to see that the scammer had uploaded a backup called argg.zip for everyone to download</figcaption></figure></div><p>Interestingly, that backup contained the scammers&#8217; personal access logs with  <strong>multiple residential IP addresses from Morocco and one from a university in France</strong> accessing the panel months before it went live. <br><br>Since Argenta does not operate in Morocco or France, these early logins were unlikely to be victims.</p><p>These IP addresses matched the hardcoded IP addresses that I found in the admin panel </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TBHG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9672938b-5a45-4717-9f3d-2aa1cb6249a3_448x380.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TBHG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9672938b-5a45-4717-9f3d-2aa1cb6249a3_448x380.png 424w, https://substackcdn.com/image/fetch/$s_!TBHG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9672938b-5a45-4717-9f3d-2aa1cb6249a3_448x380.png 848w, https://substackcdn.com/image/fetch/$s_!TBHG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9672938b-5a45-4717-9f3d-2aa1cb6249a3_448x380.png 1272w, https://substackcdn.com/image/fetch/$s_!TBHG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9672938b-5a45-4717-9f3d-2aa1cb6249a3_448x380.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TBHG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9672938b-5a45-4717-9f3d-2aa1cb6249a3_448x380.png" width="448" height="380" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9672938b-5a45-4717-9f3d-2aa1cb6249a3_448x380.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:380,&quot;width&quot;:448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:24390,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9672938b-5a45-4717-9f3d-2aa1cb6249a3_448x380.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TBHG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9672938b-5a45-4717-9f3d-2aa1cb6249a3_448x380.png 424w, https://substackcdn.com/image/fetch/$s_!TBHG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9672938b-5a45-4717-9f3d-2aa1cb6249a3_448x380.png 848w, https://substackcdn.com/image/fetch/$s_!TBHG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9672938b-5a45-4717-9f3d-2aa1cb6249a3_448x380.png 1272w, https://substackcdn.com/image/fetch/$s_!TBHG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9672938b-5a45-4717-9f3d-2aa1cb6249a3_448x380.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Leaving your personal IP address in a phishing kit is like spraying illegal graffiti with your first, last and middle name</figcaption></figure></div><p>What kind of criminals leave their own IP addresses hardcoded in their source code? We&#8217;re about to find out, but not before I changed the source code of the phishing framework to only work from Morocco, and display this message to the rest of the world:</p><blockquote><p>Phishing attempt blocked! Do NOT enter your information. You can safely close this page.</p></blockquote><p>Watch it in action:</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;7d47aa9b-69f4-41bf-91c1-7159c7077465&quot;,&quot;duration&quot;:null}"></div><p>The <strong>telegramclick.php</strong> file that I deleted earlier was also present in the backup and contained the telegram bot API token that would inform the scammers when a visitor had entered a valid bank card to start collecting the banking codes on their end.</p><p>The backup also contained the Telegram bot API token used by the panel. With that token, I could inspect the bot configuration and identify the usernames of the administrators receiving the stolen banking details. <br><br>According to the group metadata, there were four members involved:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QOp5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc64000f6-8b5a-472a-b022-16483166b2e6_2116x434.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QOp5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc64000f6-8b5a-472a-b022-16483166b2e6_2116x434.png 424w, https://substackcdn.com/image/fetch/$s_!QOp5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc64000f6-8b5a-472a-b022-16483166b2e6_2116x434.png 848w, https://substackcdn.com/image/fetch/$s_!QOp5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc64000f6-8b5a-472a-b022-16483166b2e6_2116x434.png 1272w, https://substackcdn.com/image/fetch/$s_!QOp5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc64000f6-8b5a-472a-b022-16483166b2e6_2116x434.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QOp5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc64000f6-8b5a-472a-b022-16483166b2e6_2116x434.png" width="1456" height="299" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c64000f6-8b5a-472a-b022-16483166b2e6_2116x434.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:299,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31613,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc64000f6-8b5a-472a-b022-16483166b2e6_2116x434.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QOp5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc64000f6-8b5a-472a-b022-16483166b2e6_2116x434.png 424w, https://substackcdn.com/image/fetch/$s_!QOp5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc64000f6-8b5a-472a-b022-16483166b2e6_2116x434.png 848w, https://substackcdn.com/image/fetch/$s_!QOp5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc64000f6-8b5a-472a-b022-16483166b2e6_2116x434.png 1272w, https://substackcdn.com/image/fetch/$s_!QOp5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc64000f6-8b5a-472a-b022-16483166b2e6_2116x434.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Thanks to Telegram, we know that this is a group of 4 people</figcaption></figure></div><p>Now that the scammer think their code works perfectly while not getting any new clients, let&#8217;s get back to unmasking them.</p><p>I put the IP address in the data breach lookup service <a href="http://osintleak.com">osintleak.com</a> and found a gmail linked to this residential IP address from 2024. Unfortunately the e-mail address did not contain the full name, but I had something new to work with:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NigD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2727c889-a9f5-4353-a82c-6d784daab104_1430x644.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NigD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2727c889-a9f5-4353-a82c-6d784daab104_1430x644.png 424w, https://substackcdn.com/image/fetch/$s_!NigD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2727c889-a9f5-4353-a82c-6d784daab104_1430x644.png 848w, https://substackcdn.com/image/fetch/$s_!NigD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2727c889-a9f5-4353-a82c-6d784daab104_1430x644.png 1272w, https://substackcdn.com/image/fetch/$s_!NigD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2727c889-a9f5-4353-a82c-6d784daab104_1430x644.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NigD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2727c889-a9f5-4353-a82c-6d784daab104_1430x644.png" width="1430" height="644" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2727c889-a9f5-4353-a82c-6d784daab104_1430x644.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:644,&quot;width&quot;:1430,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:43561,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2727c889-a9f5-4353-a82c-6d784daab104_1430x644.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NigD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2727c889-a9f5-4353-a82c-6d784daab104_1430x644.png 424w, https://substackcdn.com/image/fetch/$s_!NigD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2727c889-a9f5-4353-a82c-6d784daab104_1430x644.png 848w, https://substackcdn.com/image/fetch/$s_!NigD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2727c889-a9f5-4353-a82c-6d784daab104_1430x644.png 1272w, https://substackcdn.com/image/fetch/$s_!NigD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2727c889-a9f5-4353-a82c-6d784daab104_1430x644.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Online bookmaker 1win was breached in October 2024</figcaption></figure></div><p>Then unexpectedly, Google+ came to the rescue. Who thought I&#8217;d be using Google+ in 2026?! I used EPIEOS Google+ reverse search to find out the Google profile once linked to this e-mail address:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q4YL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf2a3712-b5a0-4204-b8ea-0677ca7f3f40_3436x1900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q4YL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf2a3712-b5a0-4204-b8ea-0677ca7f3f40_3436x1900.png 424w, https://substackcdn.com/image/fetch/$s_!Q4YL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf2a3712-b5a0-4204-b8ea-0677ca7f3f40_3436x1900.png 848w, https://substackcdn.com/image/fetch/$s_!Q4YL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf2a3712-b5a0-4204-b8ea-0677ca7f3f40_3436x1900.png 1272w, https://substackcdn.com/image/fetch/$s_!Q4YL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf2a3712-b5a0-4204-b8ea-0677ca7f3f40_3436x1900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q4YL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf2a3712-b5a0-4204-b8ea-0677ca7f3f40_3436x1900.png" width="1456" height="805" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/af2a3712-b5a0-4204-b8ea-0677ca7f3f40_3436x1900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:805,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:622746,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf2a3712-b5a0-4204-b8ea-0677ca7f3f40_3436x1900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Q4YL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf2a3712-b5a0-4204-b8ea-0677ca7f3f40_3436x1900.png 424w, https://substackcdn.com/image/fetch/$s_!Q4YL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf2a3712-b5a0-4204-b8ea-0677ca7f3f40_3436x1900.png 848w, https://substackcdn.com/image/fetch/$s_!Q4YL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf2a3712-b5a0-4204-b8ea-0677ca7f3f40_3436x1900.png 1272w, https://substackcdn.com/image/fetch/$s_!Q4YL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf2a3712-b5a0-4204-b8ea-0677ca7f3f40_3436x1900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Google+ haunts us till this date</figcaption></figure></div><p>I will not disclose the full identity of this person of interest as this does not prove that he was the one to publish the phishing panel from that IP address. <br><br>This person, as well as the some other profiles I found linked to the early logins from Morocco, all fit the description of technical university students in their early 20&#8217;s, some of them boasting with cars and jewelry on social media.</p><h3>What happened in the next few days</h3><p>After a few hours, the scammers finally found out that something was wrong and decided to relocate the website to a different domain. </p><p>For days, they kept on re-uploading my hacked backdoor version, so every time they uploaded a new version I attempted to disable it again.</p><p>In total, I was able to take down seven campaigns with thousands of users targeted.</p><p>After that, the scammers had found and fixed the vulnerability. </p><p>Luckily for me, I had downloaded the source code and have found multiple vulnerabilities that would allow me to regain access. Since these vulnerabilities haven&#8217;t been fixed, I will not disclose them in this blogpost.</p><p>However, for the past few weeks it&#8217;s been quiet and I&#8217;d assume this group either got tired of me messing with them, or their attempts have gone off my radar. </p><p>But we have to bring them to justice as these aren&#8217;t one-off criminals. A quick reverse domain search has revealed this group would reupload the campaigns almost daily:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DwkF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77f01606-1d0a-4565-a8ae-8a8c7deae528_2598x1104.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DwkF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77f01606-1d0a-4565-a8ae-8a8c7deae528_2598x1104.png 424w, https://substackcdn.com/image/fetch/$s_!DwkF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77f01606-1d0a-4565-a8ae-8a8c7deae528_2598x1104.png 848w, https://substackcdn.com/image/fetch/$s_!DwkF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77f01606-1d0a-4565-a8ae-8a8c7deae528_2598x1104.png 1272w, https://substackcdn.com/image/fetch/$s_!DwkF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77f01606-1d0a-4565-a8ae-8a8c7deae528_2598x1104.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DwkF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77f01606-1d0a-4565-a8ae-8a8c7deae528_2598x1104.png" width="1456" height="619" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/77f01606-1d0a-4565-a8ae-8a8c7deae528_2598x1104.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:619,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:324675,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77f01606-1d0a-4565-a8ae-8a8c7deae528_2598x1104.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DwkF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77f01606-1d0a-4565-a8ae-8a8c7deae528_2598x1104.png 424w, https://substackcdn.com/image/fetch/$s_!DwkF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77f01606-1d0a-4565-a8ae-8a8c7deae528_2598x1104.png 848w, https://substackcdn.com/image/fetch/$s_!DwkF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77f01606-1d0a-4565-a8ae-8a8c7deae528_2598x1104.png 1272w, https://substackcdn.com/image/fetch/$s_!DwkF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77f01606-1d0a-4565-a8ae-8a8c7deae528_2598x1104.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">For every scammer domain that goes down, new ones emerge</figcaption></figure></div><p>After discovering logo&#8217;s of other banks in the phishing panel, I got suspicious that this wasn&#8217;t a one-off for this particular group:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YOoO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cb74613-1a0b-4901-98d6-774374f2667b_1350x742.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YOoO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cb74613-1a0b-4901-98d6-774374f2667b_1350x742.png 424w, https://substackcdn.com/image/fetch/$s_!YOoO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cb74613-1a0b-4901-98d6-774374f2667b_1350x742.png 848w, https://substackcdn.com/image/fetch/$s_!YOoO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cb74613-1a0b-4901-98d6-774374f2667b_1350x742.png 1272w, https://substackcdn.com/image/fetch/$s_!YOoO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cb74613-1a0b-4901-98d6-774374f2667b_1350x742.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YOoO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cb74613-1a0b-4901-98d6-774374f2667b_1350x742.png" width="1350" height="742" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3cb74613-1a0b-4901-98d6-774374f2667b_1350x742.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:742,&quot;width&quot;:1350,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:252090,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://inti.io/i/187300061?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cb74613-1a0b-4901-98d6-774374f2667b_1350x742.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YOoO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cb74613-1a0b-4901-98d6-774374f2667b_1350x742.png 424w, https://substackcdn.com/image/fetch/$s_!YOoO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cb74613-1a0b-4901-98d6-774374f2667b_1350x742.png 848w, https://substackcdn.com/image/fetch/$s_!YOoO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cb74613-1a0b-4901-98d6-774374f2667b_1350x742.png 1272w, https://substackcdn.com/image/fetch/$s_!YOoO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cb74613-1a0b-4901-98d6-774374f2667b_1350x742.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Looks like they had plans with other banks as well?</figcaption></figure></div><p>A quick Google search confirmed that the same platform had been used for other European banks as well.</p><p>At this point, I felt this was something I needed to report as soon as possible. Unsure where to go as someone who isn&#8217;t really a victim, I decided to report it to Argenta.</p><p><strong>Responsible disclosure timeline</strong></p><p>Jan 25th &gt; Called Argenta phishing desk, was asked to write an e-mail<br>Jan 25th &gt; Wrote an e-mail with the details &amp; plan for blogpost<br>Jan 26th &gt; Informed SafeOnWeb on verdacht@safeonweb.be (which is an automated inbox as it turns out, if you need a human best to inform info@safeonweb.be instead)<br>Feb 25th &lt; First e-mail acknowledgement of disclosure received from Argenta<br>Mar 9th &gt; Blogpost published</p><p>It is unclear whether this evidence will be passed on to law enforcement as I&#8217;m not entirely sure whether that would be within the banks&#8217; scope of responsibilities. For this reason, police officers working on this case specifically may contact me to obtain the evidence.</p><p>Let&#8217;s start bringing these criminals to justice.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://inti.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://inti.io/p/how-i-infiltrated-phishing-panels?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://inti.io/p/how-i-infiltrated-phishing-panels?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><h3>Disclaimer</h3><p>Technically, hacking back phishing panels can be illegal in under certain jurisdictions and I would not recommend doing so without fully understanding and acknowledging the risk. <br><br>The examples in this blogpost have been thoroughly planned, weighed and precautions have been taken to minimize collateral damage or interference with existing investigations.<br><br>The actions described in this article were taken solely to disrupt an active phishing operation and prevent victims from entering sensitive information.<br><br><strong>A note on the role of banks</strong></p><blockquote><p>This post is not meant to dunk on banks. Phishing is a complex and constantly evolving problem, and many financial institutions are actively investing in tools and partnerships to better protect their customers.</p><p>Initiatives such as KBC&#8217;s <em><a href="https://newsroom.kbc.com/belgische-primeur-schakel-engelbewaarder-in-bij-verdachte-betalingen">Engelbewaarder</a></em>, which allows customers to involve a trusted person when suspicious payments occur, are examples of steps being taken to reduce fraud. Argenta is also working with partners to combat phishing and online scams, and other banks have similar initiatives.</p><p>At the same time, hunting down hundreds of phishing campaigns uploaded every month is not an easy task for any organization.</p><p>Combating phishing ultimately requires banks, law enforcement, and the security community to work together, ideally within frameworks that make it easier for everyone to contribute.  Let this post be another step towards that future!</p></blockquote><p></p><p></p><p></p><p></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>https://www.politie.be/5350/nl/nieuws/uit-het-nieuws-nergens-in-heel-de-eu-is-de-kans-op-daadwerkelijke-schade-door-phishing-zo</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[How brands like Orange downplay security breaches]]></title><description><![CDATA[The secret PR playbook to spin & win any cybersecurity incident]]></description><link>https://inti.io/p/how-brands-like-orange-downplay-security</link><guid isPermaLink="false">https://inti.io/p/how-brands-like-orange-downplay-security</guid><dc:creator><![CDATA[Inti De Ceukelaire]]></dc:creator><pubDate>Thu, 21 Aug 2025 06:11:43 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/5d1073c6-9896-418c-a5fb-e69c78acf8a4_1882x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I hate writing this, because I don&#8217;t want to inspire more PR people to sweep rampant security breaches under the rug. But someone has to call out how organisations protect their brand over their users and how unknowingly, traditional media helps them to deceive the people at risk.</p><p>Yesterday, I got an e-mail from Orange stating that I am one of the 850,000 Belgian users affected in a cybersecurity breach that happened a few weeks ago. I was pleased to see the e-mail contained a link to a<a href="https://corporate.orange.be/en/node/57971"> press release</a> and a <a href="https://orange.be/communication">landing page</a> with more information, but my joy quickly turned into disgust when I noticed that the landing page is merely a PR statement that is here to deceive the media and their customers. <br><br>The deceptive communication is subtle - here&#8217;s a guide for everyone to spot it:</p><h3>Sneaky communication tricks</h3><ul><li><p><strong>Putting the focus on what did NOT happen</strong>: look at the (translated) breach notification below. Notice something?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fdJF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F773816b4-566f-40ab-b5ab-785223f69ac3_1060x350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fdJF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F773816b4-566f-40ab-b5ab-785223f69ac3_1060x350.png 424w, https://substackcdn.com/image/fetch/$s_!fdJF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F773816b4-566f-40ab-b5ab-785223f69ac3_1060x350.png 848w, https://substackcdn.com/image/fetch/$s_!fdJF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F773816b4-566f-40ab-b5ab-785223f69ac3_1060x350.png 1272w, https://substackcdn.com/image/fetch/$s_!fdJF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F773816b4-566f-40ab-b5ab-785223f69ac3_1060x350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fdJF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F773816b4-566f-40ab-b5ab-785223f69ac3_1060x350.png" width="1060" height="350" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/773816b4-566f-40ab-b5ab-785223f69ac3_1060x350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:350,&quot;width&quot;:1060,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:58336,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://inti.io/i/171462064?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F773816b4-566f-40ab-b5ab-785223f69ac3_1060x350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!fdJF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F773816b4-566f-40ab-b5ab-785223f69ac3_1060x350.png 424w, https://substackcdn.com/image/fetch/$s_!fdJF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F773816b4-566f-40ab-b5ab-785223f69ac3_1060x350.png 848w, https://substackcdn.com/image/fetch/$s_!fdJF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F773816b4-566f-40ab-b5ab-785223f69ac3_1060x350.png 1272w, https://substackcdn.com/image/fetch/$s_!fdJF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F773816b4-566f-40ab-b5ab-785223f69ac3_1060x350.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#8220;What data was affected&#8221; in the Orange Belgium breach notification uses a dark PR pattern</figcaption></figure></div><p>The first statement in <strong>bold</strong> does not answer the question. For every breach, I could come up with a gazillion data points that did not get leaked. Then they go on and talk about a hacker that has <em>gained access to a system containing the following data</em> - notice that they make no direct connection between the hacker and the data (which was undoubtedly the actual target of the hacker, not the <em>system containing data</em>).<br></p></li><li><p><strong>Ambiguous headlines</strong>: boring or deceptive headlines for e-mails and press releases to lower significance or even reframe the disclosure as a good thing. Let&#8217;s take a look at Orange&#8217;s headline:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UTWJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf703d8-a80e-4f1b-a319-f3d4f9a1e253_1430x368.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UTWJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf703d8-a80e-4f1b-a319-f3d4f9a1e253_1430x368.png 424w, https://substackcdn.com/image/fetch/$s_!UTWJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf703d8-a80e-4f1b-a319-f3d4f9a1e253_1430x368.png 848w, https://substackcdn.com/image/fetch/$s_!UTWJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf703d8-a80e-4f1b-a319-f3d4f9a1e253_1430x368.png 1272w, https://substackcdn.com/image/fetch/$s_!UTWJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf703d8-a80e-4f1b-a319-f3d4f9a1e253_1430x368.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UTWJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf703d8-a80e-4f1b-a319-f3d4f9a1e253_1430x368.png" width="1430" height="368" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/edf703d8-a80e-4f1b-a319-f3d4f9a1e253_1430x368.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:368,&quot;width&quot;:1430,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:54669,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://inti.io/i/171462064?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf703d8-a80e-4f1b-a319-f3d4f9a1e253_1430x368.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UTWJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf703d8-a80e-4f1b-a319-f3d4f9a1e253_1430x368.png 424w, https://substackcdn.com/image/fetch/$s_!UTWJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf703d8-a80e-4f1b-a319-f3d4f9a1e253_1430x368.png 848w, https://substackcdn.com/image/fetch/$s_!UTWJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf703d8-a80e-4f1b-a319-f3d4f9a1e253_1430x368.png 1272w, https://substackcdn.com/image/fetch/$s_!UTWJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedf703d8-a80e-4f1b-a319-f3d4f9a1e253_1430x368.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Headline: &#8220;Orange Belgium informs its customers about a cyberattack&#8221;</figcaption></figure></div><p>There are two subtle tricks embedded into this headline:</p><ul><li><p>Because it&#8217;s written from a <strong>third person</strong> perspective, it appears more neutral but is also easier for press to pick up as-is, without tweaking it.</p></li><li><p>Focus on <strong>own</strong> <strong>action</strong> rather than <strong>important</strong> <strong>facts</strong>: the highlight is on the word <em>informs</em> which carries a positive sentiment, followed the vaguely worded &#8220;<em>a cyberattack</em>&#8221; which could also point to a cyber attack in a different company. Knowing that Orange&#8217;s parent company also delivers cybersecurity services, this could even be read as a positive thing!</p><p></p></li></ul></li><li><p><strong>There&#8217;s always a lack of &#8220;evidence&#8221;</strong>: a top trick in the book is to talk about the lack of evidence that the data was leaked or sold <em>at the time of the press release</em>. It exploits the notion that customers trust companies to conduct fast and proper research, while this is actually not in their best interest. In this case, Orange tried to play the classic &#8216;no evidence&#8217; trick at 12PM, conveniently when the press picked it up, only to remove the statement from the <a href="https://archive.is/stHi2">page again at 4:30PM.</a> Luckily for you, but unluckily for them, the page has since been <a href="https://web.archive.org/web/20250820122752/https://www.orange.be/nl/belangrijke-informatie">archived</a>. <br>UPDATE: The next day at 12:05, they have added the clause again.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!axPC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17cbbd3-f499-4756-9387-3eb3e360a693_1014x546.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!axPC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17cbbd3-f499-4756-9387-3eb3e360a693_1014x546.png 424w, https://substackcdn.com/image/fetch/$s_!axPC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17cbbd3-f499-4756-9387-3eb3e360a693_1014x546.png 848w, https://substackcdn.com/image/fetch/$s_!axPC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17cbbd3-f499-4756-9387-3eb3e360a693_1014x546.png 1272w, https://substackcdn.com/image/fetch/$s_!axPC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17cbbd3-f499-4756-9387-3eb3e360a693_1014x546.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!axPC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17cbbd3-f499-4756-9387-3eb3e360a693_1014x546.png" width="1014" height="546" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f17cbbd3-f499-4756-9387-3eb3e360a693_1014x546.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:546,&quot;width&quot;:1014,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:115873,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://inti.io/i/171462064?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17cbbd3-f499-4756-9387-3eb3e360a693_1014x546.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!axPC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17cbbd3-f499-4756-9387-3eb3e360a693_1014x546.png 424w, https://substackcdn.com/image/fetch/$s_!axPC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17cbbd3-f499-4756-9387-3eb3e360a693_1014x546.png 848w, https://substackcdn.com/image/fetch/$s_!axPC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17cbbd3-f499-4756-9387-3eb3e360a693_1014x546.png 1272w, https://substackcdn.com/image/fetch/$s_!axPC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff17cbbd3-f499-4756-9387-3eb3e360a693_1014x546.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">No &#8220;evidence&#8221; at 12PM, deleted at 4:30PM. This is odd to say the least for official comms after an investigation of a breach that happened weeks ago. (translated screenshot, original <a href="https://web.archive.org/web/20250820122752/https://www.orange.be/nl/belangrijke-informatie">here</a>)</figcaption></figure></div></li><li><p><strong>The PR dictionary: </strong>some interesting word choices / euphemisms from the communications:</p><ul><li><p><strong>Cyber attack</strong> instead of <strong>data breach: </strong>the first word helps to victimise the organisation, the latter can have serious regulatory consequences.</p></li><li><p>The hacker <strong>consulted</strong> (rather than <strong>stole</strong>): I know consultants charge criminal rates but we shouldn&#8217;t confuse them with real criminals.</p></li><li><p><strong>Critical </strong>and <strong>sensitive</strong>: these self-defined words can mean anything. In this case, phone numbers, PUK and SIM card numbers (that could come in handy during SIM swapping attacks) are not defined as critical despite being extremely rare for hackers to get their hands on, whereas something more trivial/public such as an e-mail address is defined critical. It&#8217;s a moving target: if e-mail addresses would have been included, an overzealous marketeer could redefine &#8220;critical&#8221; as &#8220;access to raw text message data and phone call logs&#8221;. </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!h9iO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b6b0aa6-3093-4cd3-be07-ff2546a1dcfd_2260x274.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!h9iO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b6b0aa6-3093-4cd3-be07-ff2546a1dcfd_2260x274.png 424w, https://substackcdn.com/image/fetch/$s_!h9iO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b6b0aa6-3093-4cd3-be07-ff2546a1dcfd_2260x274.png 848w, https://substackcdn.com/image/fetch/$s_!h9iO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b6b0aa6-3093-4cd3-be07-ff2546a1dcfd_2260x274.png 1272w, https://substackcdn.com/image/fetch/$s_!h9iO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b6b0aa6-3093-4cd3-be07-ff2546a1dcfd_2260x274.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!h9iO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b6b0aa6-3093-4cd3-be07-ff2546a1dcfd_2260x274.png" width="1456" height="177" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3b6b0aa6-3093-4cd3-be07-ff2546a1dcfd_2260x274.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:177,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:94569,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://inti.io/i/171462064?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b6b0aa6-3093-4cd3-be07-ff2546a1dcfd_2260x274.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!h9iO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b6b0aa6-3093-4cd3-be07-ff2546a1dcfd_2260x274.png 424w, https://substackcdn.com/image/fetch/$s_!h9iO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b6b0aa6-3093-4cd3-be07-ff2546a1dcfd_2260x274.png 848w, https://substackcdn.com/image/fetch/$s_!h9iO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b6b0aa6-3093-4cd3-be07-ff2546a1dcfd_2260x274.png 1272w, https://substackcdn.com/image/fetch/$s_!h9iO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b6b0aa6-3093-4cd3-be07-ff2546a1dcfd_2260x274.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">&#8220;Critical&#8221; is a self-defined moving target</figcaption></figure></div><h6></h6></li></ul></li><li><p><strong>Justification for lack of transparency</strong>: as usual, the breached corporation refuses to provide more technical details to &#8220;<em>ensure the integrity of the investigation and protect the privacy of those involved&#8221;</em>.  <br>Yeah - right. Your privacy matters so much to them that they won&#8217;t tell you how they failed to protect your private details. If I were cynical, I would think that the true reason why they provide as little detail as possible is to avoid owning up to a mistake that could inspire people for a class-action suit.</p></li><li><p><strong>No sorry, no crime: </strong>Orange informs its users how they can protect themselves against the mess that it created, but fails to acknowledge the inconvenience or risk brings to their users. <br>For an organisation that publicly boasts that their &#8220;<em><strong>customer-centric approach</strong></em> has been a key pillar of Orange Belgium's success<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>&#8221;, this seems to be a serious mismatch with their approach. <br>Or would they suddenly see a &#8220;we&#8217;re sorry this happened&#8221; be an admission of guilt of their own negligence?</p></li></ul><p>The only thing missing on my bingo card is that they did not send out the press release on a Friday afternoon. But should I congratulate them for that?</p><p>As a society, we should not demand companies to be unhackable. Security breaches can happen to the best-protected. But I think it is our responsibility to call out organisations for being deceptive and deflecting responsibility onto their customers. Only by speaking up, we can make the PR industry rethink their strategies and focus on honesty over deniability, but looking at how the traditional media picked up the press release without asking <em>critical</em> questions it looks like we still have a long way to go.</p><p>I will also take additional action: because Orange has shown that it cannot be trusted, I will file an <a href="https://www.gegevensbeschermingsautoriteit.be/burger/acties/klacht-indienen">official complaint</a> with the responsible Data Protection Authority and demand full transparency as to what has really transpired and how our personal information was (mis)used.</p><p><strong>If you want to hear about my progress or read my upcoming blog about </strong><em><strong>another uncovered Belgian telecom disaster</strong></em><strong>, then I encourage you to subscribe to my free newsletter:</strong></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://inti.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://inti.io/subscribe?"><span>Subscribe now</span></a></p><p></p><h6>Disclaimer: this article describes my personal views and opinions as an Orange customer and is unaffiliated with anyone or anything but myself.<br></h6><p></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>https://corporate.orange.be/en/news-medias/lead-future-offers-and-customer-experience-excellence</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Hacking a sushi restaurant (video below)]]></title><description><![CDATA[It turned out not to be the romantic candlelit dinner my wife had hoped for.]]></description><link>https://inti.io/p/hacking-a-sushi-restaurant-video</link><guid isPermaLink="false">https://inti.io/p/hacking-a-sushi-restaurant-video</guid><dc:creator><![CDATA[Inti De Ceukelaire]]></dc:creator><pubDate>Mon, 24 Mar 2025 20:29:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HLKa!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5128d80f-faa2-454a-9bc9-d6465b16dfad_1160x1096.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Time for a quick update. I&#8217;m in the middle of a research project that&#8217;s taking a bit longer to finish and write up, but in the meantime, I figured I&#8217;d share a random hacking moment: hacking a sushi restaurant. Yep. There&#8217;s a video below.</p><p>A few months ago, my wife and I were traveling through Germany and ended up at this all-you-can-eat sushi place. The concept was simple: you get a tablet, order as many plates as you want within your timeslot, and eat.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://inti.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">This Substack is reader-supported. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The moment the waitress handed me that tablet, my wife sighed. She knew exactly where this was going. So much for a peaceful, romantic dinner.</p><p>I spent the next 30 minutes poking around to see if I could extend our timeslot&#8212;instead of, you know&#8230; actually eating.</p><p>Getting out of the app&#8217;s kiosk mode was way too easy. I just swiped down on the clock, opened the control panel, and tapped &#8220;Devices&#8221; to jump straight into the Android settings. First thing I tried was changing the system clock, hoping it&#8217;d mess with the countdown timer. Nope. Didn&#8217;t work.</p><p>Then I checked out the file browser. To my surprise, the app&#8217;s config file was just&#8230; there. I opened it in the browser and realized the app was basically just a web app running locally. Hit the login screen, opened up the browser dev tools, and there it was:</p><p>The admin password&#8212;<strong>8888</strong>&#8212;hardcoded right into the page.</p><p>Anyone with half a clue could&#8217;ve found it. Once logged in, I had full control&#8212;clearing tables, wiping bills, adjusting time slots&#8230; the works.</p><p>Of course, I logged back out. I&#8217;m still an ethical hacker at the end of the day.</p><p>I showed the waitress, but she just shrugged and said, <em>&#8220;Our customers aren&#8217;t that smart.&#8221;</em> Cool. Still shot the restaurant a message afterwards, but surprise: no reply. Been about 3 months now.</p><p>The best part? I barely ate. Spent the whole time hacking instead of stuffing my face with sushi. Ended up booking another dinner the next night just to make up for it.</p><p>Anyway&#8212;video&#8217;s below.</p><div class="instagram" data-attrs="{&quot;instagram_id&quot;:&quot;DHnmWfgNP7q&quot;,&quot;title&quot;:&quot;A post shared by @intidc&quot;,&quot;author_name&quot;:&quot;intidc&quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/__ss-rehost__IG-meta-DHnmWfgNP7q.jpg&quot;,&quot;timestamp&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="InstagramToDOM"><div class="instagram-top-bar"><a class="instagram-author-name" href="https://instagram.com/intidc" target="_blank">intidc</a></div><a class="instagram-image" href="https://instagram.com/p/DHnmWfgNP7q" target="_blank"><img src="https://substackcdn.com/image/fetch/$s_!2yRi!,w_640,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F__ss-rehost__IG-meta-DHnmWfgNP7q.jpg" loading="lazy"></a><div class="instagram-bottom-bar"><div class="instagram-title">A post shared by <a href="https://instagram.com/intidc" target="_blank">@intidc</a></div></div></div>]]></content:encoded></item><item><title><![CDATA[When privacy expires: how I got access to tons of sensitive citizen data after buying cheap domains]]></title><description><![CDATA[As part of a large-scale privacy investigation, I have bought more than 100 domain names previously belonging to social welfare and justice institutions in Belgium. What I observed was unsettling.]]></description><link>https://inti.io/p/when-privacy-expires-how-i-got-access</link><guid isPermaLink="false">https://inti.io/p/when-privacy-expires-how-i-got-access</guid><dc:creator><![CDATA[Inti De Ceukelaire]]></dc:creator><pubDate>Tue, 21 May 2024 19:10:48 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4417a05f-844a-4a9e-9d29-66ce05987164_930x586.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Cybersecurity has always been transient: what is deemed to be secure today, may be considered easily hackable tomorrow. Domain names in web and e-mail addresses, such as info [at ] inti.io, are leased in time. This means that if nobody thinks of renewing them after they expire, they will be put up for sale. It made me wonder what would happen to the graveyard of cloud accounts attached to the e-mail addresses that once belonged to these expired domains.</p><p>Concerned about my data and that of my fellow citizens, I decided to start an investigation: <strong>is it possible to revive old cloud accounts that were once used to store our sensitive data?</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://inti.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Inti De Ceukelaire is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>First, I needed a list of companies or institutions whose e-mail addresses either ceased to exist due to bankruptcy or changed as part of a merger, split, or rebranding operation. This wasn&#8217;t particularly hard to do, as organizations typically announce these changes to the public.</p><p>I immediately thought of the fusion of the Belgian municipalities, where entire towns and cities with thousands of inhabitants were merged under a new name. The old domain names containing the previous name were simply rerouted to the new name, e.g., puurs.be will take you to puurs-sint-amands.be. This was the case for all domain names, except one: somebody had already bought overpelt.be (which became Pelt after merging with Neerpelt).</p><p>The administration of Pelt housed about 15,000 residents upon their merger in 2018. Since 2022, their website has hosted a &#8220;blog&#8221; that is actually a fake facade for dubious purposes. In this case, it looks like the new owner is merely using it to artificially increase the Google ranking of other websites, but one can never be sure.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RER5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd546c375-1360-472b-9e13-6e024a2219e2_3456x1996.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RER5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd546c375-1360-472b-9e13-6e024a2219e2_3456x1996.png 424w, https://substackcdn.com/image/fetch/$s_!RER5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd546c375-1360-472b-9e13-6e024a2219e2_3456x1996.png 848w, https://substackcdn.com/image/fetch/$s_!RER5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd546c375-1360-472b-9e13-6e024a2219e2_3456x1996.png 1272w, https://substackcdn.com/image/fetch/$s_!RER5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd546c375-1360-472b-9e13-6e024a2219e2_3456x1996.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RER5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd546c375-1360-472b-9e13-6e024a2219e2_3456x1996.png" width="1456" height="841" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d546c375-1360-472b-9e13-6e024a2219e2_3456x1996.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:841,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2346192,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RER5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd546c375-1360-472b-9e13-6e024a2219e2_3456x1996.png 424w, https://substackcdn.com/image/fetch/$s_!RER5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd546c375-1360-472b-9e13-6e024a2219e2_3456x1996.png 848w, https://substackcdn.com/image/fetch/$s_!RER5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd546c375-1360-472b-9e13-6e024a2219e2_3456x1996.png 1272w, https://substackcdn.com/image/fetch/$s_!RER5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd546c375-1360-472b-9e13-6e024a2219e2_3456x1996.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">@overpelt.be was once used to manage citizen affairs of roughly 15,000 people. Now it&#8217;s hosting a suspicious blog by an author with a fake name.</figcaption></figure></div><p>The same is happening with former publicly listed companies that went bankrupt, such as alfacamgroup.com (bankrupt in 2013), Thrombogenics (bankrupt in 2019), and fng.eu (bankrupt in 2022), which once had hundreds of employees on their payroll. These are now bought up and swapped out for dubious websites that still accept incoming e-mail:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zCde!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb342e364-5acf-4641-bd44-64898c882774_3456x2070.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zCde!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb342e364-5acf-4641-bd44-64898c882774_3456x2070.png 424w, https://substackcdn.com/image/fetch/$s_!zCde!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb342e364-5acf-4641-bd44-64898c882774_3456x2070.png 848w, https://substackcdn.com/image/fetch/$s_!zCde!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb342e364-5acf-4641-bd44-64898c882774_3456x2070.png 1272w, https://substackcdn.com/image/fetch/$s_!zCde!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb342e364-5acf-4641-bd44-64898c882774_3456x2070.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zCde!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb342e364-5acf-4641-bd44-64898c882774_3456x2070.png" width="1456" height="872" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b342e364-5acf-4641-bd44-64898c882774_3456x2070.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:872,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3966106,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zCde!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb342e364-5acf-4641-bd44-64898c882774_3456x2070.png 424w, https://substackcdn.com/image/fetch/$s_!zCde!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb342e364-5acf-4641-bd44-64898c882774_3456x2070.png 848w, https://substackcdn.com/image/fetch/$s_!zCde!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb342e364-5acf-4641-bd44-64898c882774_3456x2070.png 1272w, https://substackcdn.com/image/fetch/$s_!zCde!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb342e364-5acf-4641-bd44-64898c882774_3456x2070.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Domain names of former publicly listed companies on the stock exchange now have dubious facades that still accept incoming e-mail.</figcaption></figure></div><p>Except for search ranking hacks, nobody can really know for sure what the intentions of their new owners are.</p><p>Moving further down my list of recently expired domains, I started seeing patterns&#8212;and not ones I was pleased to see. A considerable number of the recently expired domains contained abbreviations of Belgian social welfare institutions:</p><ul><li><p>OCMW (44 expired domains)</p><ul><li><p>Institutions that help the most vulnerable people in our society with financial issues, crisis situations, social housing, legal and medical assistance, and disability assistance.</p></li></ul></li><li><p>CAW (12 expired domains)</p><ul><li><p>Similar responsibilities as OCMW, but more directed toward a general audience (including youth), providing psychosocial support for individuals and families, and more aimed toward prevention.</p></li></ul></li><li><p>CLB (12 expired domains)</p><ul><li><p>Social institutions focused on providing support to students and pupils with school-related learning or family difficulties.</p></li></ul></li></ul><p>In addition to identifying 68 domains related to the Belgian social welfare system, I concluded that multiple domains associated with certain psychiatric hospitals (4 expired domains), as well as the Belgian justice system, were also affected, from police zones (32 expired domains), which migrated to a @police.belgium.eu e-mail address in 2018, to local courts and tribunals (3 expired domains).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!u0zC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4081042d-3924-47db-953e-02b6438c8712_4048x1048.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!u0zC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4081042d-3924-47db-953e-02b6438c8712_4048x1048.png 424w, https://substackcdn.com/image/fetch/$s_!u0zC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4081042d-3924-47db-953e-02b6438c8712_4048x1048.png 848w, https://substackcdn.com/image/fetch/$s_!u0zC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4081042d-3924-47db-953e-02b6438c8712_4048x1048.png 1272w, https://substackcdn.com/image/fetch/$s_!u0zC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4081042d-3924-47db-953e-02b6438c8712_4048x1048.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!u0zC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4081042d-3924-47db-953e-02b6438c8712_4048x1048.png" width="1456" height="377" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4081042d-3924-47db-953e-02b6438c8712_4048x1048.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:377,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:369785,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!u0zC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4081042d-3924-47db-953e-02b6438c8712_4048x1048.png 424w, https://substackcdn.com/image/fetch/$s_!u0zC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4081042d-3924-47db-953e-02b6438c8712_4048x1048.png 848w, https://substackcdn.com/image/fetch/$s_!u0zC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4081042d-3924-47db-953e-02b6438c8712_4048x1048.png 1272w, https://substackcdn.com/image/fetch/$s_!u0zC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4081042d-3924-47db-953e-02b6438c8712_4048x1048.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I found 107 domains for sale previously belonging to social welfare and justice institutions, each of the price of &#8364;8.</figcaption></figure></div><p>As a responsible citizen, I wanted to avoid these sensitive domains ending up in the wrong hands, so I bought all of the more than 100 domains for around &#8364;850. As the legal and rightful owner of these domains, I now had insights into how they were still used.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mKFn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc66ec40-60cc-4590-9aec-49ccaf76559b_1420x596.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mKFn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc66ec40-60cc-4590-9aec-49ccaf76559b_1420x596.png 424w, https://substackcdn.com/image/fetch/$s_!mKFn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc66ec40-60cc-4590-9aec-49ccaf76559b_1420x596.png 848w, https://substackcdn.com/image/fetch/$s_!mKFn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc66ec40-60cc-4590-9aec-49ccaf76559b_1420x596.png 1272w, https://substackcdn.com/image/fetch/$s_!mKFn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc66ec40-60cc-4590-9aec-49ccaf76559b_1420x596.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mKFn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc66ec40-60cc-4590-9aec-49ccaf76559b_1420x596.png" width="1420" height="596" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cc66ec40-60cc-4590-9aec-49ccaf76559b_1420x596.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:596,&quot;width&quot;:1420,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:64459,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mKFn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc66ec40-60cc-4590-9aec-49ccaf76559b_1420x596.png 424w, https://substackcdn.com/image/fetch/$s_!mKFn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc66ec40-60cc-4590-9aec-49ccaf76559b_1420x596.png 848w, https://substackcdn.com/image/fetch/$s_!mKFn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc66ec40-60cc-4590-9aec-49ccaf76559b_1420x596.png 1272w, https://substackcdn.com/image/fetch/$s_!mKFn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc66ec40-60cc-4590-9aec-49ccaf76559b_1420x596.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I bought all the domains to ensure nobody else could grab them.</figcaption></figure></div><p>Once I bought the domains, I started receiving e-mails for these e-mail addresses:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VBBy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8687f4be-6b55-459a-8773-7cba5687169d_636x412.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VBBy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8687f4be-6b55-459a-8773-7cba5687169d_636x412.png 424w, https://substackcdn.com/image/fetch/$s_!VBBy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8687f4be-6b55-459a-8773-7cba5687169d_636x412.png 848w, https://substackcdn.com/image/fetch/$s_!VBBy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8687f4be-6b55-459a-8773-7cba5687169d_636x412.png 1272w, https://substackcdn.com/image/fetch/$s_!VBBy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8687f4be-6b55-459a-8773-7cba5687169d_636x412.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VBBy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8687f4be-6b55-459a-8773-7cba5687169d_636x412.png" width="502" height="325.1949685534591" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8687f4be-6b55-459a-8773-7cba5687169d_636x412.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:412,&quot;width&quot;:636,&quot;resizeWidth&quot;:502,&quot;bytes&quot;:35535,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VBBy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8687f4be-6b55-459a-8773-7cba5687169d_636x412.png 424w, https://substackcdn.com/image/fetch/$s_!VBBy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8687f4be-6b55-459a-8773-7cba5687169d_636x412.png 848w, https://substackcdn.com/image/fetch/$s_!VBBy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8687f4be-6b55-459a-8773-7cba5687169d_636x412.png 1272w, https://substackcdn.com/image/fetch/$s_!VBBy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8687f4be-6b55-459a-8773-7cba5687169d_636x412.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Illustrative picture of incoming e-mails</figcaption></figure></div><p>I started making a list of various e-mail addresses that once belonged to these domains, which I obtained from public sources.  Then, I used the &#8216;Forgot password&#8217; functionality on popular cloud services to check whether these e-mail addresses were still linked to an active account and whether I could receive the password reset links sent to these e-mail addresses that would theoretically allow me to log in to these sensitive cloud accounts:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Wui6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfbd136-0423-4bb4-b958-d487fed90be6_1702x324.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Wui6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfbd136-0423-4bb4-b958-d487fed90be6_1702x324.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Wui6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfbd136-0423-4bb4-b958-d487fed90be6_1702x324.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Wui6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfbd136-0423-4bb4-b958-d487fed90be6_1702x324.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Wui6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfbd136-0423-4bb4-b958-d487fed90be6_1702x324.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Wui6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfbd136-0423-4bb4-b958-d487fed90be6_1702x324.jpeg" width="1456" height="277" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/abfbd136-0423-4bb4-b958-d487fed90be6_1702x324.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:277,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:51931,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Wui6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfbd136-0423-4bb4-b958-d487fed90be6_1702x324.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Wui6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfbd136-0423-4bb4-b958-d487fed90be6_1702x324.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Wui6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfbd136-0423-4bb4-b958-d487fed90be6_1702x324.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Wui6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabfbd136-0423-4bb4-b958-d487fed90be6_1702x324.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">As I was about to take a picture of the 279 intercepted cloud storage password reset links, someone e-mailed me regarding what appeared to be a confidential health matter.</figcaption></figure></div><p>For the 848 e-mail addresses I was able to identify within a week, I successfully obtained the password reset e-mails for 80 Dropbox accounts, 142 Google Drive accounts, 57 Microsoft / OneDrive / SharePoint accounts, and a dozen Smartschool and Doccle accounts. I realized that by buying these domains, I had gained access to tons of sensitive citizen information stored in the cloud accounts linked to these e-mail addresses.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z_V0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cdf8f88-5396-45e7-9d81-202b646c5e92_3222x1418.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z_V0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cdf8f88-5396-45e7-9d81-202b646c5e92_3222x1418.png 424w, https://substackcdn.com/image/fetch/$s_!Z_V0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cdf8f88-5396-45e7-9d81-202b646c5e92_3222x1418.png 848w, https://substackcdn.com/image/fetch/$s_!Z_V0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cdf8f88-5396-45e7-9d81-202b646c5e92_3222x1418.png 1272w, https://substackcdn.com/image/fetch/$s_!Z_V0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cdf8f88-5396-45e7-9d81-202b646c5e92_3222x1418.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z_V0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cdf8f88-5396-45e7-9d81-202b646c5e92_3222x1418.png" width="1456" height="641" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5cdf8f88-5396-45e7-9d81-202b646c5e92_3222x1418.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:641,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:593429,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z_V0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cdf8f88-5396-45e7-9d81-202b646c5e92_3222x1418.png 424w, https://substackcdn.com/image/fetch/$s_!Z_V0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cdf8f88-5396-45e7-9d81-202b646c5e92_3222x1418.png 848w, https://substackcdn.com/image/fetch/$s_!Z_V0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cdf8f88-5396-45e7-9d81-202b646c5e92_3222x1418.png 1272w, https://substackcdn.com/image/fetch/$s_!Z_V0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cdf8f88-5396-45e7-9d81-202b646c5e92_3222x1418.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Some of the 279 cloud storage accounts I could access seemed to belong to extremely sensitive groups (slachtofferhulp = victim support, police recherche = investigations, bjb = legal assistance office, etc.). Note that these are reproductions, not the actual codes in the e-mails.</figcaption></figure></div><p>I did not have to log in to any of these accounts to check whether they actually contained files, as I started receiving e-mails like this:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1SC8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0a032fb-854c-4493-bfea-e01d56aba6ef_1952x950.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1SC8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0a032fb-854c-4493-bfea-e01d56aba6ef_1952x950.png 424w, https://substackcdn.com/image/fetch/$s_!1SC8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0a032fb-854c-4493-bfea-e01d56aba6ef_1952x950.png 848w, https://substackcdn.com/image/fetch/$s_!1SC8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0a032fb-854c-4493-bfea-e01d56aba6ef_1952x950.png 1272w, https://substackcdn.com/image/fetch/$s_!1SC8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0a032fb-854c-4493-bfea-e01d56aba6ef_1952x950.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1SC8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0a032fb-854c-4493-bfea-e01d56aba6ef_1952x950.png" width="1456" height="709" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f0a032fb-854c-4493-bfea-e01d56aba6ef_1952x950.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:709,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:350825,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1SC8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0a032fb-854c-4493-bfea-e01d56aba6ef_1952x950.png 424w, https://substackcdn.com/image/fetch/$s_!1SC8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0a032fb-854c-4493-bfea-e01d56aba6ef_1952x950.png 848w, https://substackcdn.com/image/fetch/$s_!1SC8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0a032fb-854c-4493-bfea-e01d56aba6ef_1952x950.png 1272w, https://substackcdn.com/image/fetch/$s_!1SC8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0a032fb-854c-4493-bfea-e01d56aba6ef_1952x950.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Reproduction of the content of the "storage warning&#8221; Dropbox e-mail</figcaption></figure></div><p>These weren&#8217;t the only e-mails I started receiving. Shockingly, years after these e-mail addresses were abandoned, they still received extremely sensitive information. To respect the sender&#8217;s privacy as much as possible, I avoided opening the e-mails. Based on the titles, the sending authority, and the recipient, I was able to classify the e-mails into the following categories. In the list below, I&#8217;ve selected 2 - 3 example e-mails per category.</p><ol><li><p>Confidential justice information Information regarding released detainees, public defenders, &#8230;</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iBqF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e17a79b-343a-475a-b532-cfbe0ff55a86_2692x70.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iBqF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e17a79b-343a-475a-b532-cfbe0ff55a86_2692x70.png 424w, https://substackcdn.com/image/fetch/$s_!iBqF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e17a79b-343a-475a-b532-cfbe0ff55a86_2692x70.png 848w, https://substackcdn.com/image/fetch/$s_!iBqF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e17a79b-343a-475a-b532-cfbe0ff55a86_2692x70.png 1272w, https://substackcdn.com/image/fetch/$s_!iBqF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e17a79b-343a-475a-b532-cfbe0ff55a86_2692x70.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iBqF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e17a79b-343a-475a-b532-cfbe0ff55a86_2692x70.png" width="1456" height="38" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9e17a79b-343a-475a-b532-cfbe0ff55a86_2692x70.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:38,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:36580,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iBqF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e17a79b-343a-475a-b532-cfbe0ff55a86_2692x70.png 424w, https://substackcdn.com/image/fetch/$s_!iBqF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e17a79b-343a-475a-b532-cfbe0ff55a86_2692x70.png 848w, https://substackcdn.com/image/fetch/$s_!iBqF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e17a79b-343a-475a-b532-cfbe0ff55a86_2692x70.png 1272w, https://substackcdn.com/image/fetch/$s_!iBqF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e17a79b-343a-475a-b532-cfbe0ff55a86_2692x70.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KACi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F961b5791-4d64-4ad5-9899-de23f0bfa39b_2422x76.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KACi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F961b5791-4d64-4ad5-9899-de23f0bfa39b_2422x76.png 424w, https://substackcdn.com/image/fetch/$s_!KACi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F961b5791-4d64-4ad5-9899-de23f0bfa39b_2422x76.png 848w, https://substackcdn.com/image/fetch/$s_!KACi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F961b5791-4d64-4ad5-9899-de23f0bfa39b_2422x76.png 1272w, https://substackcdn.com/image/fetch/$s_!KACi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F961b5791-4d64-4ad5-9899-de23f0bfa39b_2422x76.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KACi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F961b5791-4d64-4ad5-9899-de23f0bfa39b_2422x76.png" width="1456" height="46" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/961b5791-4d64-4ad5-9899-de23f0bfa39b_2422x76.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:46,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:25547,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KACi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F961b5791-4d64-4ad5-9899-de23f0bfa39b_2422x76.png 424w, https://substackcdn.com/image/fetch/$s_!KACi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F961b5791-4d64-4ad5-9899-de23f0bfa39b_2422x76.png 848w, https://substackcdn.com/image/fetch/$s_!KACi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F961b5791-4d64-4ad5-9899-de23f0bfa39b_2422x76.png 1272w, https://substackcdn.com/image/fetch/$s_!KACi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F961b5791-4d64-4ad5-9899-de23f0bfa39b_2422x76.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></li><li><p>Payment reminders for people in debt</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZMj-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff32ae0a3-9deb-4fbb-af42-f6b4ad35660b_2702x304.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZMj-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff32ae0a3-9deb-4fbb-af42-f6b4ad35660b_2702x304.png 424w, https://substackcdn.com/image/fetch/$s_!ZMj-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff32ae0a3-9deb-4fbb-af42-f6b4ad35660b_2702x304.png 848w, https://substackcdn.com/image/fetch/$s_!ZMj-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff32ae0a3-9deb-4fbb-af42-f6b4ad35660b_2702x304.png 1272w, https://substackcdn.com/image/fetch/$s_!ZMj-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff32ae0a3-9deb-4fbb-af42-f6b4ad35660b_2702x304.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZMj-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff32ae0a3-9deb-4fbb-af42-f6b4ad35660b_2702x304.png" width="1456" height="164" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f32ae0a3-9deb-4fbb-af42-f6b4ad35660b_2702x304.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:164,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:120359,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZMj-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff32ae0a3-9deb-4fbb-af42-f6b4ad35660b_2702x304.png 424w, https://substackcdn.com/image/fetch/$s_!ZMj-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff32ae0a3-9deb-4fbb-af42-f6b4ad35660b_2702x304.png 848w, https://substackcdn.com/image/fetch/$s_!ZMj-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff32ae0a3-9deb-4fbb-af42-f6b4ad35660b_2702x304.png 1272w, https://substackcdn.com/image/fetch/$s_!ZMj-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff32ae0a3-9deb-4fbb-af42-f6b4ad35660b_2702x304.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></li><li><p>E-mails related to vulnerable people&#8217;s health or social situation</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uAE1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965e5fac-8579-479f-b06f-35a1b3690f86_1520x314.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uAE1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965e5fac-8579-479f-b06f-35a1b3690f86_1520x314.png 424w, https://substackcdn.com/image/fetch/$s_!uAE1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965e5fac-8579-479f-b06f-35a1b3690f86_1520x314.png 848w, https://substackcdn.com/image/fetch/$s_!uAE1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965e5fac-8579-479f-b06f-35a1b3690f86_1520x314.png 1272w, https://substackcdn.com/image/fetch/$s_!uAE1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965e5fac-8579-479f-b06f-35a1b3690f86_1520x314.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uAE1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965e5fac-8579-479f-b06f-35a1b3690f86_1520x314.png" width="1456" height="301" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/965e5fac-8579-479f-b06f-35a1b3690f86_1520x314.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:301,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:49616,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uAE1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965e5fac-8579-479f-b06f-35a1b3690f86_1520x314.png 424w, https://substackcdn.com/image/fetch/$s_!uAE1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965e5fac-8579-479f-b06f-35a1b3690f86_1520x314.png 848w, https://substackcdn.com/image/fetch/$s_!uAE1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965e5fac-8579-479f-b06f-35a1b3690f86_1520x314.png 1272w, https://substackcdn.com/image/fetch/$s_!uAE1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F965e5fac-8579-479f-b06f-35a1b3690f86_1520x314.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></li><li><p>Meeting invites to special committees:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Dgew!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2567f82-dc61-400e-ad4e-a0aabc9e3da3_2672x156.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Dgew!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2567f82-dc61-400e-ad4e-a0aabc9e3da3_2672x156.png 424w, https://substackcdn.com/image/fetch/$s_!Dgew!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2567f82-dc61-400e-ad4e-a0aabc9e3da3_2672x156.png 848w, https://substackcdn.com/image/fetch/$s_!Dgew!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2567f82-dc61-400e-ad4e-a0aabc9e3da3_2672x156.png 1272w, https://substackcdn.com/image/fetch/$s_!Dgew!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2567f82-dc61-400e-ad4e-a0aabc9e3da3_2672x156.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Dgew!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2567f82-dc61-400e-ad4e-a0aabc9e3da3_2672x156.png" width="1456" height="85" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f2567f82-dc61-400e-ad4e-a0aabc9e3da3_2672x156.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:85,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:46122,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Dgew!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2567f82-dc61-400e-ad4e-a0aabc9e3da3_2672x156.png 424w, https://substackcdn.com/image/fetch/$s_!Dgew!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2567f82-dc61-400e-ad4e-a0aabc9e3da3_2672x156.png 848w, https://substackcdn.com/image/fetch/$s_!Dgew!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2567f82-dc61-400e-ad4e-a0aabc9e3da3_2672x156.png 1272w, https://substackcdn.com/image/fetch/$s_!Dgew!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff2567f82-dc61-400e-ad4e-a0aabc9e3da3_2672x156.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></li><li><p>Official copies of attestation documents, as well as Doccle / bank documents for people in debt management</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZKEf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faabe129a-c698-4138-a6c2-03314ac136d3_1852x230.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZKEf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faabe129a-c698-4138-a6c2-03314ac136d3_1852x230.png 424w, https://substackcdn.com/image/fetch/$s_!ZKEf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faabe129a-c698-4138-a6c2-03314ac136d3_1852x230.png 848w, https://substackcdn.com/image/fetch/$s_!ZKEf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faabe129a-c698-4138-a6c2-03314ac136d3_1852x230.png 1272w, https://substackcdn.com/image/fetch/$s_!ZKEf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faabe129a-c698-4138-a6c2-03314ac136d3_1852x230.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZKEf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faabe129a-c698-4138-a6c2-03314ac136d3_1852x230.png" width="1456" height="181" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aabe129a-c698-4138-a6c2-03314ac136d3_1852x230.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:181,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:47038,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZKEf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faabe129a-c698-4138-a6c2-03314ac136d3_1852x230.png 424w, https://substackcdn.com/image/fetch/$s_!ZKEf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faabe129a-c698-4138-a6c2-03314ac136d3_1852x230.png 848w, https://substackcdn.com/image/fetch/$s_!ZKEf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faabe129a-c698-4138-a6c2-03314ac136d3_1852x230.png 1272w, https://substackcdn.com/image/fetch/$s_!ZKEf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faabe129a-c698-4138-a6c2-03314ac136d3_1852x230.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></li><li><p>Questions or information from or regarding vulnerable people in difficult situations <br><br><em>(no reproduction or screenshot here as it is considered too personal/sensitive to even refer to)</em><br></p></li><li><p>Insurance claim documents directed to the police</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bt1j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cd4f743-5967-4be6-aa65-f05a6ca7bd6b_2676x468.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bt1j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cd4f743-5967-4be6-aa65-f05a6ca7bd6b_2676x468.png 424w, https://substackcdn.com/image/fetch/$s_!Bt1j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cd4f743-5967-4be6-aa65-f05a6ca7bd6b_2676x468.png 848w, https://substackcdn.com/image/fetch/$s_!Bt1j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cd4f743-5967-4be6-aa65-f05a6ca7bd6b_2676x468.png 1272w, https://substackcdn.com/image/fetch/$s_!Bt1j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cd4f743-5967-4be6-aa65-f05a6ca7bd6b_2676x468.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bt1j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cd4f743-5967-4be6-aa65-f05a6ca7bd6b_2676x468.png" width="1456" height="255" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6cd4f743-5967-4be6-aa65-f05a6ca7bd6b_2676x468.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:255,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:136732,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bt1j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cd4f743-5967-4be6-aa65-f05a6ca7bd6b_2676x468.png 424w, https://substackcdn.com/image/fetch/$s_!Bt1j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cd4f743-5967-4be6-aa65-f05a6ca7bd6b_2676x468.png 848w, https://substackcdn.com/image/fetch/$s_!Bt1j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cd4f743-5967-4be6-aa65-f05a6ca7bd6b_2676x468.png 1272w, https://substackcdn.com/image/fetch/$s_!Bt1j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6cd4f743-5967-4be6-aa65-f05a6ca7bd6b_2676x468.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></li><li><p>Smartschool announcements and document references directed to CLB (pupil counseling institution)</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k703!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4498229-6f14-4747-941e-b2d8f6751ae8_2490x466.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k703!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4498229-6f14-4747-941e-b2d8f6751ae8_2490x466.png 424w, https://substackcdn.com/image/fetch/$s_!k703!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4498229-6f14-4747-941e-b2d8f6751ae8_2490x466.png 848w, https://substackcdn.com/image/fetch/$s_!k703!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4498229-6f14-4747-941e-b2d8f6751ae8_2490x466.png 1272w, https://substackcdn.com/image/fetch/$s_!k703!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4498229-6f14-4747-941e-b2d8f6751ae8_2490x466.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k703!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4498229-6f14-4747-941e-b2d8f6751ae8_2490x466.png" width="1456" height="272" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e4498229-6f14-4747-941e-b2d8f6751ae8_2490x466.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:272,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:267945,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!k703!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4498229-6f14-4747-941e-b2d8f6751ae8_2490x466.png 424w, https://substackcdn.com/image/fetch/$s_!k703!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4498229-6f14-4747-941e-b2d8f6751ae8_2490x466.png 848w, https://substackcdn.com/image/fetch/$s_!k703!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4498229-6f14-4747-941e-b2d8f6751ae8_2490x466.png 1272w, https://substackcdn.com/image/fetch/$s_!k703!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4498229-6f14-4747-941e-b2d8f6751ae8_2490x466.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></li><li><p>Technical access invitations and reports for firewall, antivirus, </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cpFw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336100a2-eda9-4a31-875e-35a4adc5f9a3_2030x76.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cpFw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336100a2-eda9-4a31-875e-35a4adc5f9a3_2030x76.png 424w, https://substackcdn.com/image/fetch/$s_!cpFw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336100a2-eda9-4a31-875e-35a4adc5f9a3_2030x76.png 848w, https://substackcdn.com/image/fetch/$s_!cpFw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336100a2-eda9-4a31-875e-35a4adc5f9a3_2030x76.png 1272w, https://substackcdn.com/image/fetch/$s_!cpFw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336100a2-eda9-4a31-875e-35a4adc5f9a3_2030x76.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cpFw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336100a2-eda9-4a31-875e-35a4adc5f9a3_2030x76.png" width="1456" height="55" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/336100a2-eda9-4a31-875e-35a4adc5f9a3_2030x76.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:55,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:33404,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cpFw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336100a2-eda9-4a31-875e-35a4adc5f9a3_2030x76.png 424w, https://substackcdn.com/image/fetch/$s_!cpFw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336100a2-eda9-4a31-875e-35a4adc5f9a3_2030x76.png 848w, https://substackcdn.com/image/fetch/$s_!cpFw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336100a2-eda9-4a31-875e-35a4adc5f9a3_2030x76.png 1272w, https://substackcdn.com/image/fetch/$s_!cpFw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F336100a2-eda9-4a31-875e-35a4adc5f9a3_2030x76.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yYGQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72b1cbf7-e2a4-4c64-bc97-09819c394597_2674x148.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yYGQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72b1cbf7-e2a4-4c64-bc97-09819c394597_2674x148.png 424w, https://substackcdn.com/image/fetch/$s_!yYGQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72b1cbf7-e2a4-4c64-bc97-09819c394597_2674x148.png 848w, https://substackcdn.com/image/fetch/$s_!yYGQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72b1cbf7-e2a4-4c64-bc97-09819c394597_2674x148.png 1272w, https://substackcdn.com/image/fetch/$s_!yYGQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72b1cbf7-e2a4-4c64-bc97-09819c394597_2674x148.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yYGQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72b1cbf7-e2a4-4c64-bc97-09819c394597_2674x148.png" width="1456" height="81" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72b1cbf7-e2a4-4c64-bc97-09819c394597_2674x148.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:81,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:89164,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yYGQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72b1cbf7-e2a4-4c64-bc97-09819c394597_2674x148.png 424w, https://substackcdn.com/image/fetch/$s_!yYGQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72b1cbf7-e2a4-4c64-bc97-09819c394597_2674x148.png 848w, https://substackcdn.com/image/fetch/$s_!yYGQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72b1cbf7-e2a4-4c64-bc97-09819c394597_2674x148.png 1272w, https://substackcdn.com/image/fetch/$s_!yYGQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72b1cbf7-e2a4-4c64-bc97-09819c394597_2674x148.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div></li><li><p>Other: personal employee-related e-mails</p><ol><li><p>Tax-on-web messages</p></li><li><p>Payroll information</p></li><li><p>Linkedin updates, personal accounts (strava running app, e-commerce orders, payments with apple pay, &#8230;)</p></li></ol></li></ol><p>&#8230;And hundreds of other e-mails. In merely a few days.<br><br>Some emails that came in looked as if they came from vulnerable people themselves, asking for help. It may be that they haven&#8217;t received or understood the message to update their address book.<br><br>I did not interfere with any of the e-mails, as this would go beyond the objectives of this investigation, but it is concerning, to say the least, that these individuals will never receive a reply. They would not have received a response anyway, but it makes me wonder how many cries for help get lost in abandoned e-mail inboxes.</p><p>After the short duration of this experiment, I disabled incoming e-mails for these domains. Prior to publication, the CCB (Centre for Cybersecurity Belgium) has briefed their previous owners and informed them about the risks of expired domains.</p><p>With hundreds of new domain names set to expire in the coming year, structural changes will be needed to prevent this from happening again. I am publishing this blog today to raise awareness about this threat to society that goes far beyond the borders of Belgium and is relevant to all governmental institutions around the world. We should collectively look into a better strategy for managing the lifecycle of domain names, especially those tied to sensitive or critical services. This could include creating policies for the secure handling and proper decommissioning of expired domains and their associated cloud accounts, ensuring they don't fall into the wrong hands, and maintaining continuity for important communications. Enforcing two-factor authentication on cloud accounts could also greatly reduce the risks associated with these attacks. At least, that&#8217;s what I&#8217;m trying to do for my own inti.io domain, because undoubtedly, it may belong to someone else one day - and that idea shouldn&#8217;t be as scary as it sounds right now.</p><p><strong>FAQ</strong></p><ol><li><p><strong>As a company owner or system administrator, how can I prevent against this?<br><br></strong>Everything starts with awareness: anyone can create rules, but if employees do not understand the &#8216;why&#8217;, they may not follow them. This blog post can serve as a tangible example of what can go wrong if we start storing, sharing, and receiving sensitive data on non-approved cloud storage providers.. The use of multifactor authentication (MFA) is a must, as well as implementing proper change management procedures and communications. If you&#8217;re changing e-mail addresses, make sure everyone knows and has a reasonable amount of time to adapt their address book. Set an out-of-office response for anyone e-mailing to the old e-mail address, reminding them that you are phasing the e-mail domain out. Enable auto-renewal for expired domain names, or renew them for a minimum period of ten years. Search Google for references to the old e-mail domain and ensure they&#8217;re updated. Some cloud services, such as <a href="https://support.google.com/a/answer/1668854?hl=en">Google</a>, also allow domain administrators to limit registration for certain e-mail domains.</p><p></p></li><li><p><strong>Why didn&#8217;t you just report the expired domain names?</strong></p><p><br>Expired domain names themselves do not constitute a threat to citizen privacy: organizations may have legitimate reasons for letting domain names expire. I needed to prove the existence of the actual threats to make a case.<br></p></li><li><p><strong>Why didn&#8217;t you report this issue to all affected parties prior to publishing this?</strong></p><p><br>By taking all sensitive domain names I could find off the market, I was able to mitigate the majority of the risk for the time being. Tracking down their owners is trickier, as I am now the sole recipient of the only e-mail address I had on file for them. By raising public awareness, I am hoping to inform all system administrators that may be affected by this issue, now or in the future. Prior to publication, I made multiple authorities aware of this issue. Special thanks in particular to the Centre for Cybersecurity Belgium (CCB) for providing swift and effective support into handling this case with the highest priority.<br></p></li><li><p><strong>Is buying a domain name and receiving their e-mails legal?</strong></p><p><br>It depends. The act of buying an expired domain name is completely legal; however, buying a trademarked domain name (cybersquatting) may violate copyright laws, especially when done with malicious intentions. Some countries have laws that prevent you from opening physical mail directed to someone else, however there is debate whether this also affects e-mails, as they may be considered as opened (&#8220;downloaded&#8221;) the moment you receive them. The laws that do talk about electronic communication typically forbid the interception of communication between two or more non-consenting or unaware participants through the means of any device (such as a secret listening device or a man-in-the-middle attack), but in this case, one could argue that the recipient is the actual addressee in the conversation as they are the legitimate owner of the domain name - the intended receiver was never part of the conversation. Then there&#8217;s also privacy laws that prohibit sharing and processing data of subjects without their consent, but by sharing content with an expired e-mail address, the sender may be the one violating the data subject's privacy rights by not conducting due diligence on the e-mail address.<br><br>The act of actually taking over and logging into the expired cloud accounts, such as Dropbox, would likely fall under the definition of illegal hacking. Just by buying the domain, you do not become the owner of the related accounts. During this research, no actual passwords were reset.</p><p><br>There isn&#8217;t much to find on this internet regarding this particular case, but I did find an <a href="https://law.stackexchange.com/questions/35917/legal-protections-for-an-expired-email-domain">interesting StackExchange conversation</a> related to this scenario.&nbsp;<br></p></li><li><p><strong>Is this limited to Belgium?<br><br></strong>No, not at all. In fact, during my research, I found that someone reported a similar issue <a href="https://www.rijnmond.nl/nieuws/150868/vertrouwelijke-mails-aan-politie-rijnmond-in-handen-van-hacker">for a single domain with police related e-mail addresses in the Netherlands</a>. In Australia, someone did the same with <a href="https://blog.ironbastion.com.au/hacking-law-firms-abandoned-domain-name-attack/">six expired e-mail addresses</a> belonging to law firms. </p><p></p></li><li><p><strong>How long did the experiment take?</strong></p><p><br>A little over a week. I deemed this to be enough to get a decent understanding about which e-mail domains were still active, as it would cover all days of the week and potentially automated e-mails scheduled on a certain day. After the experiment was over, I started explicitly blocking e-mails to my domain.<br></p></li><li><p><strong>What steps did you take to mitigate risk, if any?</strong></p><p><br>Since the domain names I have purchased were already expired, their previous owners should not have experienced any negative side effects. The e-mails sent to my addresses would have never reached them in the first place. Additionally, I had embedded my personal details in both the DNS name records and the websites belonging to them, so that anyone noticing something strange could immediately contact me to reclaim their domain at no cost.<br><br>During the testing period, nobody reached out despite leaving my contact details.<br><br>As far as data privacy goes, I tried to limit myself from any excessive sensitive data exposure by mainly looking at an e-mails&#8217; subject, its sender and recipient to determine the class of its content. I proved the ability to take over the cloud accounts, but never actually completed the password reset in order to preserve the integrity of these accounts. The e-mails are stored in a separate and secure environment in the cloud, and will be deleted shortly.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Axfr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d817705-53c5-4772-b133-a0976c76a23e_996x290.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Axfr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d817705-53c5-4772-b133-a0976c76a23e_996x290.png 424w, https://substackcdn.com/image/fetch/$s_!Axfr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d817705-53c5-4772-b133-a0976c76a23e_996x290.png 848w, https://substackcdn.com/image/fetch/$s_!Axfr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d817705-53c5-4772-b133-a0976c76a23e_996x290.png 1272w, https://substackcdn.com/image/fetch/$s_!Axfr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d817705-53c5-4772-b133-a0976c76a23e_996x290.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Axfr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d817705-53c5-4772-b133-a0976c76a23e_996x290.png" width="996" height="290" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1d817705-53c5-4772-b133-a0976c76a23e_996x290.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:290,&quot;width&quot;:996,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:66716,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Axfr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d817705-53c5-4772-b133-a0976c76a23e_996x290.png 424w, https://substackcdn.com/image/fetch/$s_!Axfr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d817705-53c5-4772-b133-a0976c76a23e_996x290.png 848w, https://substackcdn.com/image/fetch/$s_!Axfr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d817705-53c5-4772-b133-a0976c76a23e_996x290.png 1272w, https://substackcdn.com/image/fetch/$s_!Axfr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d817705-53c5-4772-b133-a0976c76a23e_996x290.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Banner shown on every domain I bought. Nobody ended up &#8216;missing&#8217; their domains.</figcaption></figure></div><h2><br>Subscribe to my blog! </h2><p>This piece of research was made possible thanks to my subscribers! <br><a href="https://inti.io/p/why-subscribe">You can subscribe today for free</a> to be the first to hear about future disclosures. You can also decide to sponsor me on the same page. Last year, I received $200 in sponsorships through this blog, which helped me pay (partially) for the domains in this experiment.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://inti.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Inti De Ceukelaire is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Scan to scam: how thieves can steal credits at cashless music festivals]]></title><description><![CDATA[A curious case of 'quishing' (QR code phishing) at certain cashless music festivals]]></description><link>https://inti.io/p/scan-to-scam-how-thieves-can-steal</link><guid isPermaLink="false">https://inti.io/p/scan-to-scam-how-thieves-can-steal</guid><dc:creator><![CDATA[Inti De Ceukelaire]]></dc:creator><pubDate>Wed, 21 Jun 2023 12:23:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!k84-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1909b1b3-9d41-4c54-8032-3e57f2130b5d_2510x1252.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Convenience is king, especially at music festivals where every extra minute spent in line can prolong the queue with hours. As a music enthousiast, I understand why crowds and crews choose cashless payments over any alternatives, but they may not realize that this comes at the cost: under the right conditions, it turns out to be incredibly easy to collect others&#8217; remaining credits while also locking them out of their account, or even collecting their enterance wristband.</p><p>Cashless payments aren&#8217;t exactly new to music festivals here in Belgium, with &#8220;Tomorrowland&#8221; using <em>Pearls</em> as their virtual currency for years now. Most of these cashless systems work with RFID (radio frequency identification, such as NFC) technologies embedded into the festival entrance bracelet, which allows users to top up their balance at several cashless points positioned throughout the festival grounds. After the festival, this virtual currency can be refunded.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://inti.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Inti De Ceukelaire is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>While RFID is not perfect, it is typically not possible to clone a wristband of a festivalgoer because the data can be encrypted to only allow interactions between authorized tags and devices. This is also what &#8220;Rock Werchter&#8221; wrote on their website when they announced that this years&#8217; editions were going to be <a href="https://www.rockwerchter.be/en/cashless">completely cashless</a>:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hXiw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e83f71-58f1-412c-98bd-22a24b8e36cd_1442x232.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hXiw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e83f71-58f1-412c-98bd-22a24b8e36cd_1442x232.png 424w, https://substackcdn.com/image/fetch/$s_!hXiw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e83f71-58f1-412c-98bd-22a24b8e36cd_1442x232.png 848w, https://substackcdn.com/image/fetch/$s_!hXiw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e83f71-58f1-412c-98bd-22a24b8e36cd_1442x232.png 1272w, https://substackcdn.com/image/fetch/$s_!hXiw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e83f71-58f1-412c-98bd-22a24b8e36cd_1442x232.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hXiw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e83f71-58f1-412c-98bd-22a24b8e36cd_1442x232.png" width="1442" height="232" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91e83f71-58f1-412c-98bd-22a24b8e36cd_1442x232.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:232,&quot;width&quot;:1442,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:42960,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hXiw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e83f71-58f1-412c-98bd-22a24b8e36cd_1442x232.png 424w, https://substackcdn.com/image/fetch/$s_!hXiw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e83f71-58f1-412c-98bd-22a24b8e36cd_1442x232.png 848w, https://substackcdn.com/image/fetch/$s_!hXiw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e83f71-58f1-412c-98bd-22a24b8e36cd_1442x232.png 1272w, https://substackcdn.com/image/fetch/$s_!hXiw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91e83f71-58f1-412c-98bd-22a24b8e36cd_1442x232.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a><figcaption class="image-caption">Never call a system &#8216;secure&#8217; based on one protection</figcaption></figure></div><p>Even if a thief would break past this encryption layer, it would be incredibly hard to steal enough credits to be worth their time, as they would have to hold a cloner device right next to their victims&#8217; wristband for multiple seconds. It simply would not be practical.</p><p>Enter QR codes. New this year is that festival wristbands can be equipped with a QR code on the RFID tag, allowing ticket holders to easily top up their balance by scanning it with their mobile phone:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k84-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1909b1b3-9d41-4c54-8032-3e57f2130b5d_2510x1252.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k84-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1909b1b3-9d41-4c54-8032-3e57f2130b5d_2510x1252.png 424w, https://substackcdn.com/image/fetch/$s_!k84-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1909b1b3-9d41-4c54-8032-3e57f2130b5d_2510x1252.png 848w, https://substackcdn.com/image/fetch/$s_!k84-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1909b1b3-9d41-4c54-8032-3e57f2130b5d_2510x1252.png 1272w, https://substackcdn.com/image/fetch/$s_!k84-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1909b1b3-9d41-4c54-8032-3e57f2130b5d_2510x1252.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k84-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1909b1b3-9d41-4c54-8032-3e57f2130b5d_2510x1252.png" width="1456" height="726" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1909b1b3-9d41-4c54-8032-3e57f2130b5d_2510x1252.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:726,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4075101,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!k84-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1909b1b3-9d41-4c54-8032-3e57f2130b5d_2510x1252.png 424w, https://substackcdn.com/image/fetch/$s_!k84-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1909b1b3-9d41-4c54-8032-3e57f2130b5d_2510x1252.png 848w, https://substackcdn.com/image/fetch/$s_!k84-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1909b1b3-9d41-4c54-8032-3e57f2130b5d_2510x1252.png 1272w, https://substackcdn.com/image/fetch/$s_!k84-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1909b1b3-9d41-4c54-8032-3e57f2130b5d_2510x1252.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">An enterance wristband for TW Classic 2023, featuring a QR code </figcaption></figure></div><p>The back of the wristband features a unique identifier consisting of 6 uppercase letters. This side of the chip is typically not visible to by onlookers, as it is facing the wrist of the wearer.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oDYH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4af7ce5-3b5a-4aa9-8242-2c4616fa1ec9_2510x1142.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oDYH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4af7ce5-3b5a-4aa9-8242-2c4616fa1ec9_2510x1142.png 424w, https://substackcdn.com/image/fetch/$s_!oDYH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4af7ce5-3b5a-4aa9-8242-2c4616fa1ec9_2510x1142.png 848w, https://substackcdn.com/image/fetch/$s_!oDYH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4af7ce5-3b5a-4aa9-8242-2c4616fa1ec9_2510x1142.png 1272w, https://substackcdn.com/image/fetch/$s_!oDYH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4af7ce5-3b5a-4aa9-8242-2c4616fa1ec9_2510x1142.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oDYH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4af7ce5-3b5a-4aa9-8242-2c4616fa1ec9_2510x1142.png" width="1456" height="662" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e4af7ce5-3b5a-4aa9-8242-2c4616fa1ec9_2510x1142.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:662,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3873387,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oDYH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4af7ce5-3b5a-4aa9-8242-2c4616fa1ec9_2510x1142.png 424w, https://substackcdn.com/image/fetch/$s_!oDYH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4af7ce5-3b5a-4aa9-8242-2c4616fa1ec9_2510x1142.png 848w, https://substackcdn.com/image/fetch/$s_!oDYH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4af7ce5-3b5a-4aa9-8242-2c4616fa1ec9_2510x1142.png 1272w, https://substackcdn.com/image/fetch/$s_!oDYH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4af7ce5-3b5a-4aa9-8242-2c4616fa1ec9_2510x1142.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This ID key is used to link your wristband to your online accounts which you can use to request a refund once the festival is over:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9Qdu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b55cac8-c492-4110-8f8c-4c7d6ae3e006_3062x884.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9Qdu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b55cac8-c492-4110-8f8c-4c7d6ae3e006_3062x884.png 424w, https://substackcdn.com/image/fetch/$s_!9Qdu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b55cac8-c492-4110-8f8c-4c7d6ae3e006_3062x884.png 848w, https://substackcdn.com/image/fetch/$s_!9Qdu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b55cac8-c492-4110-8f8c-4c7d6ae3e006_3062x884.png 1272w, https://substackcdn.com/image/fetch/$s_!9Qdu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b55cac8-c492-4110-8f8c-4c7d6ae3e006_3062x884.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9Qdu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b55cac8-c492-4110-8f8c-4c7d6ae3e006_3062x884.png" width="1456" height="420" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3b55cac8-c492-4110-8f8c-4c7d6ae3e006_3062x884.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:420,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:172086,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9Qdu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b55cac8-c492-4110-8f8c-4c7d6ae3e006_3062x884.png 424w, https://substackcdn.com/image/fetch/$s_!9Qdu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b55cac8-c492-4110-8f8c-4c7d6ae3e006_3062x884.png 848w, https://substackcdn.com/image/fetch/$s_!9Qdu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b55cac8-c492-4110-8f8c-4c7d6ae3e006_3062x884.png 1272w, https://substackcdn.com/image/fetch/$s_!9Qdu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b55cac8-c492-4110-8f8c-4c7d6ae3e006_3062x884.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>With almost 309 million possible combinations, it is unlikely for someone with malicious intentions to guess the code manually. Assuming that automated guessing attempts would be blocked, hiding the tag number at the back of the wristband seems like a good solution, if it weren&#8217;t for the fact that the code is hiding in plain sight: the QR code!</p><p>Let&#8217;s take a look at the decoded data contained within the QR code:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BqrU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda2f5b9f-6c51-450f-9c9d-253b2d60c1cb_2556x1186.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BqrU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda2f5b9f-6c51-450f-9c9d-253b2d60c1cb_2556x1186.png 424w, https://substackcdn.com/image/fetch/$s_!BqrU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda2f5b9f-6c51-450f-9c9d-253b2d60c1cb_2556x1186.png 848w, https://substackcdn.com/image/fetch/$s_!BqrU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda2f5b9f-6c51-450f-9c9d-253b2d60c1cb_2556x1186.png 1272w, https://substackcdn.com/image/fetch/$s_!BqrU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda2f5b9f-6c51-450f-9c9d-253b2d60c1cb_2556x1186.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BqrU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda2f5b9f-6c51-450f-9c9d-253b2d60c1cb_2556x1186.png" width="1456" height="676" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da2f5b9f-6c51-450f-9c9d-253b2d60c1cb_2556x1186.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:676,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1943935,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BqrU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda2f5b9f-6c51-450f-9c9d-253b2d60c1cb_2556x1186.png 424w, https://substackcdn.com/image/fetch/$s_!BqrU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda2f5b9f-6c51-450f-9c9d-253b2d60c1cb_2556x1186.png 848w, https://substackcdn.com/image/fetch/$s_!BqrU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda2f5b9f-6c51-450f-9c9d-253b2d60c1cb_2556x1186.png 1272w, https://substackcdn.com/image/fetch/$s_!BqrU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda2f5b9f-6c51-450f-9c9d-253b2d60c1cb_2556x1186.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Decoded data: https://weez.li/UDTRQWAJ?short_tag=XMLFBM</strong></figcaption></figure></div><p>As it turns out, these QR codes contain a link to <em>weez.li</em>, which has the short_tag XMLFBM in as a URL parameter. If we can simply read the QR codes of other festivalgoers, we can obtain their tag number and claim their refunds.</p><p>I did a little experiment during last weekends&#8217; TW Classic Festival: how easy would it be to collect as many valid QR codes as possible, without looking suspicious? As comes in handy during rock concerts, it is common practice to raise &#8216;<em>devil horns (&#129304;)</em>&#8217; in between songs to show appreciation for the band, resulting in a sea of QR codes emerging from the crowd:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!l9p0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F939d063e-ba04-45d7-a63a-1e888ee56f9b_2506x1410.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!l9p0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F939d063e-ba04-45d7-a63a-1e888ee56f9b_2506x1410.png 424w, https://substackcdn.com/image/fetch/$s_!l9p0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F939d063e-ba04-45d7-a63a-1e888ee56f9b_2506x1410.png 848w, https://substackcdn.com/image/fetch/$s_!l9p0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F939d063e-ba04-45d7-a63a-1e888ee56f9b_2506x1410.png 1272w, https://substackcdn.com/image/fetch/$s_!l9p0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F939d063e-ba04-45d7-a63a-1e888ee56f9b_2506x1410.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!l9p0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F939d063e-ba04-45d7-a63a-1e888ee56f9b_2506x1410.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/939d063e-ba04-45d7-a63a-1e888ee56f9b_2506x1410.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3924713,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!l9p0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F939d063e-ba04-45d7-a63a-1e888ee56f9b_2506x1410.png 424w, https://substackcdn.com/image/fetch/$s_!l9p0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F939d063e-ba04-45d7-a63a-1e888ee56f9b_2506x1410.png 848w, https://substackcdn.com/image/fetch/$s_!l9p0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F939d063e-ba04-45d7-a63a-1e888ee56f9b_2506x1410.png 1272w, https://substackcdn.com/image/fetch/$s_!l9p0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F939d063e-ba04-45d7-a63a-1e888ee56f9b_2506x1410.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The person in front of me making the &#129304; gesture, exposing their QR code</figcaption></figure></div><p>Social media also proved to be a useful resource, as people would post pictures of their wristbands online, along with the hashtag of the festival</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IIz5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89e1ec9d-68a8-41b1-bcb0-a431cfc9f06e_2938x1938.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IIz5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89e1ec9d-68a8-41b1-bcb0-a431cfc9f06e_2938x1938.png 424w, https://substackcdn.com/image/fetch/$s_!IIz5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89e1ec9d-68a8-41b1-bcb0-a431cfc9f06e_2938x1938.png 848w, https://substackcdn.com/image/fetch/$s_!IIz5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89e1ec9d-68a8-41b1-bcb0-a431cfc9f06e_2938x1938.png 1272w, https://substackcdn.com/image/fetch/$s_!IIz5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89e1ec9d-68a8-41b1-bcb0-a431cfc9f06e_2938x1938.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IIz5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89e1ec9d-68a8-41b1-bcb0-a431cfc9f06e_2938x1938.png" width="1456" height="960" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/89e1ec9d-68a8-41b1-bcb0-a431cfc9f06e_2938x1938.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:960,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:7573781,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IIz5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89e1ec9d-68a8-41b1-bcb0-a431cfc9f06e_2938x1938.png 424w, https://substackcdn.com/image/fetch/$s_!IIz5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89e1ec9d-68a8-41b1-bcb0-a431cfc9f06e_2938x1938.png 848w, https://substackcdn.com/image/fetch/$s_!IIz5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89e1ec9d-68a8-41b1-bcb0-a431cfc9f06e_2938x1938.png 1272w, https://substackcdn.com/image/fetch/$s_!IIz5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89e1ec9d-68a8-41b1-bcb0-a431cfc9f06e_2938x1938.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Even if the QR code is blurred or not completely visible, it may still be possible to retrieve the data because most of the QR code data simply contains error correction bits. <a href="http://datagenetics.com/blog/november12013/index.html">Here&#8217;s a link</a> to a great article that explains the technical bits on how unreadable or damaged QR codes can be restored:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oF_f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa08010bc-2fd8-44d8-a16a-7064ed3d9486_776x496.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oF_f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa08010bc-2fd8-44d8-a16a-7064ed3d9486_776x496.png 424w, https://substackcdn.com/image/fetch/$s_!oF_f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa08010bc-2fd8-44d8-a16a-7064ed3d9486_776x496.png 848w, https://substackcdn.com/image/fetch/$s_!oF_f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa08010bc-2fd8-44d8-a16a-7064ed3d9486_776x496.png 1272w, https://substackcdn.com/image/fetch/$s_!oF_f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa08010bc-2fd8-44d8-a16a-7064ed3d9486_776x496.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oF_f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa08010bc-2fd8-44d8-a16a-7064ed3d9486_776x496.png" width="776" height="496" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a08010bc-2fd8-44d8-a16a-7064ed3d9486_776x496.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:496,&quot;width&quot;:776,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:60698,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oF_f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa08010bc-2fd8-44d8-a16a-7064ed3d9486_776x496.png 424w, https://substackcdn.com/image/fetch/$s_!oF_f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa08010bc-2fd8-44d8-a16a-7064ed3d9486_776x496.png 848w, https://substackcdn.com/image/fetch/$s_!oF_f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa08010bc-2fd8-44d8-a16a-7064ed3d9486_776x496.png 1272w, https://substackcdn.com/image/fetch/$s_!oF_f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa08010bc-2fd8-44d8-a16a-7064ed3d9486_776x496.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Source: http://datagenetics.com/blog/november12013/index.html</figcaption></figure></div><p>Using  <a href="https://www.reddit.com/r/StableDiffusion/comments/141hg9x/controlnet_for_qr_code/">stable diffusion</a> AI forensics, QR code reading apps will likely improve to read QR codes from afar and with limited visibility, which would make it easier for non-technical attackers to steal a considerable amount of bracelet tags in a short amount of time.</p><h3>Attack scenario #1: Claiming leftover terminal or cash top-ups for unlinked accounts after the event</h3><p>In some scenarios, it seems possible for an attacker to refund any leftover currency to their account rather than their victims&#8217; account, simply by providing their IBAN to their newly linked tag:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HFga!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c311967-7e90-4be4-959d-292559100f74_2058x226.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HFga!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c311967-7e90-4be4-959d-292559100f74_2058x226.png 424w, https://substackcdn.com/image/fetch/$s_!HFga!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c311967-7e90-4be4-959d-292559100f74_2058x226.png 848w, https://substackcdn.com/image/fetch/$s_!HFga!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c311967-7e90-4be4-959d-292559100f74_2058x226.png 1272w, https://substackcdn.com/image/fetch/$s_!HFga!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c311967-7e90-4be4-959d-292559100f74_2058x226.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HFga!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c311967-7e90-4be4-959d-292559100f74_2058x226.png" width="1456" height="160" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8c311967-7e90-4be4-959d-292559100f74_2058x226.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:160,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:72482,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HFga!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c311967-7e90-4be4-959d-292559100f74_2058x226.png 424w, https://substackcdn.com/image/fetch/$s_!HFga!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c311967-7e90-4be4-959d-292559100f74_2058x226.png 848w, https://substackcdn.com/image/fetch/$s_!HFga!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c311967-7e90-4be4-959d-292559100f74_2058x226.png 1272w, https://substackcdn.com/image/fetch/$s_!HFga!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c311967-7e90-4be4-959d-292559100f74_2058x226.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Source: documentation of the affected vendor.</figcaption></figure></div><p>Note that, according to the documentation, festivals may also automatically refund the remaining funds to the payment provider that the top-up was made online with (e.g. Payconiq), in which case the attacker would not be able to reroute the funds to their account. For on-site top-ups, such as through terminals or cash, the remaining funds can be claimed by anyone as long at the bracelet owner did not register an account.</p><h3>Attack scenario #2: Wristband swapping by reporting scanned bracelet as &#8216;lost&#8217;</h3><p>According to the cashless <a href="https://www.twclassic.be/en/cashless">FAQ section</a>, it is possible to deactivate an old wristband by reporting it as lost, as long as you&#8217;ve registered it. Since this technique allows users to claim unclaimed wristbands, an attacker could register the tag of another festivalgoer that has topped up their unregistered bracelet, and then go swap it at the helpdesk, where, according to the documentation, they would deactivate the wristband of the user and load their credits onto your account:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fRm0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e40cf68-7463-4d84-9829-1f9a7e1ef14d_1448x418.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fRm0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e40cf68-7463-4d84-9829-1f9a7e1ef14d_1448x418.png 424w, https://substackcdn.com/image/fetch/$s_!fRm0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e40cf68-7463-4d84-9829-1f9a7e1ef14d_1448x418.png 848w, https://substackcdn.com/image/fetch/$s_!fRm0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e40cf68-7463-4d84-9829-1f9a7e1ef14d_1448x418.png 1272w, https://substackcdn.com/image/fetch/$s_!fRm0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e40cf68-7463-4d84-9829-1f9a7e1ef14d_1448x418.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fRm0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e40cf68-7463-4d84-9829-1f9a7e1ef14d_1448x418.png" width="1448" height="418" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e40cf68-7463-4d84-9829-1f9a7e1ef14d_1448x418.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:418,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:109473,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fRm0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e40cf68-7463-4d84-9829-1f9a7e1ef14d_1448x418.png 424w, https://substackcdn.com/image/fetch/$s_!fRm0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e40cf68-7463-4d84-9829-1f9a7e1ef14d_1448x418.png 848w, https://substackcdn.com/image/fetch/$s_!fRm0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e40cf68-7463-4d84-9829-1f9a7e1ef14d_1448x418.png 1272w, https://substackcdn.com/image/fetch/$s_!fRm0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e40cf68-7463-4d84-9829-1f9a7e1ef14d_1448x418.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Even if they would ask for our ticket, as a double confirmation, a procedure that is not listed on the website, we could show the ticket number or QR code that could be disclosed on the portal:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JtGm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99149387-289a-47c1-a52c-777221094c66_1640x393.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JtGm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99149387-289a-47c1-a52c-777221094c66_1640x393.png 424w, https://substackcdn.com/image/fetch/$s_!JtGm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99149387-289a-47c1-a52c-777221094c66_1640x393.png 848w, https://substackcdn.com/image/fetch/$s_!JtGm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99149387-289a-47c1-a52c-777221094c66_1640x393.png 1272w, https://substackcdn.com/image/fetch/$s_!JtGm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99149387-289a-47c1-a52c-777221094c66_1640x393.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JtGm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99149387-289a-47c1-a52c-777221094c66_1640x393.png" width="1456" height="349" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/99149387-289a-47c1-a52c-777221094c66_1640x393.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:349,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:136607,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JtGm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99149387-289a-47c1-a52c-777221094c66_1640x393.png 424w, https://substackcdn.com/image/fetch/$s_!JtGm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99149387-289a-47c1-a52c-777221094c66_1640x393.png 848w, https://substackcdn.com/image/fetch/$s_!JtGm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99149387-289a-47c1-a52c-777221094c66_1640x393.png 1272w, https://substackcdn.com/image/fetch/$s_!JtGm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F99149387-289a-47c1-a52c-777221094c66_1640x393.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">The ticket number for the scanned QR was also exposed for TW Classic. Censored for privacy reasons.</figcaption></figure></div><p>When succesful, this attack would allow thieves to steal and recover the funds of another festivalgoer by scanning their wristband and going to the helpdesk. Note that we have not tried this full flow at the festival itself, but given that you already have their valid ticket number and their wristband linked, we believe that this attack is likely to be succesful according to the FAQ.</p><h3>Attack scenario #3: revealing what, when and where they ordered</h3><p>There&#8217;s also a less intrusive scenario that allows an attacker to link the bracelet, log into the portal and monitor the live transactions of the festivalgoer:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fclS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa53ea1a7-ca6f-4a1d-9986-f5b3f8397796_3584x1980.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fclS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa53ea1a7-ca6f-4a1d-9986-f5b3f8397796_3584x1980.png 424w, https://substackcdn.com/image/fetch/$s_!fclS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa53ea1a7-ca6f-4a1d-9986-f5b3f8397796_3584x1980.png 848w, https://substackcdn.com/image/fetch/$s_!fclS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa53ea1a7-ca6f-4a1d-9986-f5b3f8397796_3584x1980.png 1272w, https://substackcdn.com/image/fetch/$s_!fclS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa53ea1a7-ca6f-4a1d-9986-f5b3f8397796_3584x1980.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fclS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa53ea1a7-ca6f-4a1d-9986-f5b3f8397796_3584x1980.png" width="1456" height="804" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a53ea1a7-ca6f-4a1d-9986-f5b3f8397796_3584x1980.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:804,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:357507,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fclS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa53ea1a7-ca6f-4a1d-9986-f5b3f8397796_3584x1980.png 424w, https://substackcdn.com/image/fetch/$s_!fclS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa53ea1a7-ca6f-4a1d-9986-f5b3f8397796_3584x1980.png 848w, https://substackcdn.com/image/fetch/$s_!fclS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa53ea1a7-ca6f-4a1d-9986-f5b3f8397796_3584x1980.png 1272w, https://substackcdn.com/image/fetch/$s_!fclS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa53ea1a7-ca6f-4a1d-9986-f5b3f8397796_3584x1980.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The transactions of a festivalgoer I have intercepted the QR code from, with prior approval for the sake of the demo (Werchter Boutique)</figcaption></figure></div><p>Interestingly, if you look at the raw data that is loaded into the page, it also contains the exact locations of where these transactions happened, meaning that you can track where people are or what concerts they are attending simply by monitoring their transactions:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Mm8J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ee27e18-63c0-4100-992f-8f06e19cc5d6_1294x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Mm8J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ee27e18-63c0-4100-992f-8f06e19cc5d6_1294x480.png 424w, https://substackcdn.com/image/fetch/$s_!Mm8J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ee27e18-63c0-4100-992f-8f06e19cc5d6_1294x480.png 848w, https://substackcdn.com/image/fetch/$s_!Mm8J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ee27e18-63c0-4100-992f-8f06e19cc5d6_1294x480.png 1272w, https://substackcdn.com/image/fetch/$s_!Mm8J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ee27e18-63c0-4100-992f-8f06e19cc5d6_1294x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Mm8J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ee27e18-63c0-4100-992f-8f06e19cc5d6_1294x480.png" width="1294" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5ee27e18-63c0-4100-992f-8f06e19cc5d6_1294x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:1294,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78268,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Mm8J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ee27e18-63c0-4100-992f-8f06e19cc5d6_1294x480.png 424w, https://substackcdn.com/image/fetch/$s_!Mm8J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ee27e18-63c0-4100-992f-8f06e19cc5d6_1294x480.png 848w, https://substackcdn.com/image/fetch/$s_!Mm8J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ee27e18-63c0-4100-992f-8f06e19cc5d6_1294x480.png 1272w, https://substackcdn.com/image/fetch/$s_!Mm8J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ee27e18-63c0-4100-992f-8f06e19cc5d6_1294x480.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The person I tracked down ordered 3 50CL waters at bar 17 at 12:04AM</figcaption></figure></div><p>Note that the identity of the user is not revealed.</p><h2>What&#8217;s the risk?</h2><p>While the refund attack technically work, the likelihood of it being exploited on a large scale is rather low. While anyone can easily create multiple anonymous accounts without e-mail confirmation, they would still need to supply valid IBAN numbers to claim the refunds, which leaves a paper trail that may identify them. Assuming most people do not have hundreds of euros left on their accounts, the risk vs possible reward may not be interesting enough for people to start collecting QR codes. Once the gains are too big, they may get noticed by either their victims trying to get their refunds back, or any fraud detection algorithms these payment services typically implement.</p><p>The wristband swapping scenario might be the more dangerous one, because, when succesful, it would leave no traces: the attacker can simply create an account with dummy data, link it to the bracelet, go to the helpdesk to disable to original bracelet and get a new one, and cash out. It would however still require them to go try their luck at the helpdesk, with the registered bracelet and if available/needed the stolen ticket ID, which does pose a risk to get caught.</p><p>We believe that the real-time tracking scenario would be less risky to execute as anyone could simply create a fake account and link it to an unclaimed QR code around the wrist of a person of interest without leaving a lot of traces. Luckily, the amount of revealed information is limited to  the individual orders, at what time and where. Nevertheless, we do believe that this is a valid privacy concern that the audience needs to be informed about.</p><h2>How can I avoid someone links my festival tag?</h2><ol><li><p>Do not share pictures featuring your QR code online</p></li><li><p>Register your account upfront: a tag can only be linked to one account, so if you link your wristband prior to the festival, nobody will be able to link your tag before you do.</p></li><li><p>Put a piece of non-translucent tape over the QR code during the festival.</p></li><li><p>Wear one of these old-school sweatbands over your tag:</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_Rej!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0385177-7165-4de1-9009-7db8c6c1af9d_1058x1100.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_Rej!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0385177-7165-4de1-9009-7db8c6c1af9d_1058x1100.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_Rej!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0385177-7165-4de1-9009-7db8c6c1af9d_1058x1100.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_Rej!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0385177-7165-4de1-9009-7db8c6c1af9d_1058x1100.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_Rej!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0385177-7165-4de1-9009-7db8c6c1af9d_1058x1100.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_Rej!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0385177-7165-4de1-9009-7db8c6c1af9d_1058x1100.jpeg" width="340" height="353.4971644612476" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f0385177-7165-4de1-9009-7db8c6c1af9d_1058x1100.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1100,&quot;width&quot;:1058,&quot;resizeWidth&quot;:340,&quot;bytes&quot;:71095,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_Rej!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0385177-7165-4de1-9009-7db8c6c1af9d_1058x1100.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_Rej!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0385177-7165-4de1-9009-7db8c6c1af9d_1058x1100.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_Rej!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0385177-7165-4de1-9009-7db8c6c1af9d_1058x1100.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_Rej!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0385177-7165-4de1-9009-7db8c6c1af9d_1058x1100.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>How can this system be fixed to prevent this?</h2><p>There&#8217;s a couple of solutions to prevent this type of quishing (QR-code phishing) from happening.</p><p>Event organisers could require everybody to sign up prior to topping up their cashless wristband, but this introduces friction and forces people to hand over their personal details, which could raise privacy issues. I haven&#8217;t been able to find any unclaimed wristbands for Graspop Metal Meeting, leading me to believe that registration at the latest on check-in.</p><p>Upon linking the bracelet, event organisers could also ask to confirm the name listed on the ticket as an extra layer of protection, but this also has edgecases with separate top-up cards that can be shared by a group of people. This will also require them to share the names with the cashless vendors upfront.</p><p>In an ideal world, the QR code only works for top-ups. To view transaction data and request refunds, a separate code on the back of the chip could be used.</p><h2>Closing notes</h2><p>The introduction of cashless payments at music festivals is a much welcomed innovation, but as with all things we should ask ourselves the question '&#8220;how will someone abuse this?&#8221;. At mass gatherings with hundreds of thousands of annual visitors, you can be assured that someone will try to push the boundaries. Music festivals already heavily invest in physical security, and as they continue to pivot into the digital world, implementing and enforcing cybersecurity standards on their vendors and suppliers will be an absolute necessity.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6NrC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa26330c-d462-41eb-8228-ff8ad80b0803_548x231.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6NrC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa26330c-d462-41eb-8228-ff8ad80b0803_548x231.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6NrC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa26330c-d462-41eb-8228-ff8ad80b0803_548x231.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6NrC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa26330c-d462-41eb-8228-ff8ad80b0803_548x231.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6NrC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa26330c-d462-41eb-8228-ff8ad80b0803_548x231.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6NrC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa26330c-d462-41eb-8228-ff8ad80b0803_548x231.jpeg" width="548" height="231" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aa26330c-d462-41eb-8228-ff8ad80b0803_548x231.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:231,&quot;width&quot;:548,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:29907,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6NrC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa26330c-d462-41eb-8228-ff8ad80b0803_548x231.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6NrC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa26330c-d462-41eb-8228-ff8ad80b0803_548x231.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6NrC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa26330c-d462-41eb-8228-ff8ad80b0803_548x231.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6NrC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa26330c-d462-41eb-8228-ff8ad80b0803_548x231.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Music festivals already implement rigorous physical security checks. As they pivot into digital worlds,  enforcing cybersecurity standards will be crucial.</figcaption></figure></div><p>Note from the author: the affected vendor and festivals have had a chance to read this and suggest corrections prior to it being published.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://inti.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Inti De Ceukelaire is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>