Burning Shed Hacked!!!

QuadraphonicQuad

Help Support QuadraphonicQuad:

This site may earn a commission from merchant affiliate links, including eBay, Amazon, and others.
I thought I had only bought as a guest, but it looks like I created an account in January. I was going to check my password, and this is what is posted today:
Burning Shed 20-04-20.jpg
 
I don't usually create accounts for places like BS, generally purchasing as "Guest", but if I got the email, I must have done it. Fortunately, I keep very secure passwords on important stuff, and real shitty passwords for places like ImportCDs and Burning Shed.
 
Damn... All I need from BS right now is my PT's 'In Absentia' corrected blu-ray disc! I hope this attack does not affect the replacement program.
 
I use unique passwords for EVERY site that I have a login at ... why would anyone use the same password across multiple sites with all of the hacks that occur these days? The Burning Shed hack doesn't concern me in the least, since no financial data is stored.
 
I got the email as well but had maybe 2 direct transactions and used paypal so not too worried.
From what I can gather they prefer PayPal as if they have to give a refund PayPal returns the fee it charges, Credit Card companies don't!
 
If you have not already done so, then sign up with Troy Hunt's free Have I Been Pwned service to be notified any time your email address(es) appears in a verified breach.
Use a password manager to keep the unique generated/random/long/complex passwords for each of your accounts. Use multi-factor authentication where appropriate.
Despite being Australian, Troy is one of the most trusted authorities on the subject.
 
For hacks like this, the primary objective isn’t to get credit card information, but rather passwords that hopefully allow for the customer’s email account to be taken over without a person’s knowledge. A compromised email account is more valuable than a compromised credit card because the email account will be an avenue to potentially hijacking bank accounts, etc. that lead to the big payday for the crooks.

It is very important to have a unique, complex password for your email account(s).
 
Beware of two things:

The notice itself might be fake, sent by a phisher.

If there is a link on such an email to change your password, DO NOT USE IT!

Always go to the site in the usual way you go to it. Then manually change your password.
That's absolutely correct; I recall 4-5 years ago I got an e-mail from one of my Banks that didn't look totally kosher to me, so I sent it to their fraud department and it turned out it was a phishing scam!
 
Damn... All I need from BS right now is my PT's 'In Absentia' corrected blu-ray disc! I hope this attack does not affect the replacement program.

I bought the full deluxe edition last Sunday, one day before hacking. Burning Shed site is still down however I recived an email some minutes ago with the tracking number of my order.

So they are still packaging and shipping orders.
 
Anybody else receive this email from burningshed:

Hi

Thanks for your patience while we have been working on the site.

We have now reset all customers passwords.

Please click here https://burningshed.com/account/forgotten?email=xxxxxxxxxxx%40yahoo.com and we will automatically send you a temporary password.

Please login using the temporary password - check your spam or junk mail folder if you cannot find the email.

Once logged in YOU MUST CHANGE THIS TO A NEW PASSWORD OF YOUR CHOICE immediately.

We are very sorry for any inconvenience this has caused.

Kind Regards


Pete
[email protected]
 
Back
Top