shakedown.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A community for live music fans with roots in the jam scene. Shakedown Social is run by a team of volunteers (led by @clifff and @sethadam1) and funded by donations.

Administered by:

Server stats:

292
active users

#IdentityTheft

0 posts0 participants0 posts today

#Trump on Friday commuted the sentence & probation of #CarlosWatson, a co-founder of the now-defunct #digital #media company Ozy Media, on the day he was set to surrender to prison.

Watson was sentenced in Dec to almost 10yrs in #prison for #fraud, #IdentityTheft, #SecuritiesFraud, & #WireFraud.

Watson & Ozy were also ordered to pay $96M in restitution & forfeiture. As part of Trump’s commutation, they will no longer have to pay.

#law #felon47 #CFPB #SEC #corruption
cnbc.com/2025/03/28/trump-comm

CNBCTrump commutes sentence of Ozy Media founder Carlos Watson just before prison surrenderOzy had falsely claimed to have deals with Google and Oprah Winfrey before the company and CEO Watson were criminally charged.

Casino Data Jackpot – For Hackers: Merkur’s API Disaster

A couple of days ago, I saw a Mastodon post from Lilith Wittmann in my timeline. She linked to an article on her Medium page detailing a catastrophic security failure at Merkur AG. You can find the original Mastodon post here.

The casino company Merkur AG and its service providers have made almost all the data available in their casino systems publicly accessible. This includes payment data, gaming sessions, and copies of the ID cards of over one million players.

Lilith Wittmann’s Medium Post (German)

Oh wow. Losing data of a million customers is bad enough. To make things worse, they also integrated third-party services like Sumsub for Know Your Customer (KYC) checks. So, the leak also includes over 70,000 ID photos, selfies and proof of address from the KYC process.

A perfect setup for identity theft. What a mess!

All this was possible due to a unprotected GraphQL API endpoint.

Let’s learn from this!

For Merkur it is a massive damage. For us it is a lesson we can learn from: This breach is a good example of why securing APIs should be a top priority. Some simple steps that could have prevented this:

  • Never expose internal APIs to the public internet unless absolutely necessary. If an API must be public, it should have strict access controls, rate limits and maybe even IP-restrictions.
  • Put sensitive systems in a private subnet. Even if an API is misconfigured, at least it won’t be wide open to the world.
  • Use proper authentication, authorization, and role-based access control. A single user or role should never have unrestricted access to all sensitive data. Access should be limited to only the necessary fields for a given role.
  • Regular security audits. If you’re handling sensitive data, you better have security experts regularly pentesting your systems.

Obviously, a lot went wrong here. Let’s try to do better and avoid this kind of disaster in our own projects.

locked.de/casino-data-jackpot-
#hacking #IdentityTheft #Merkur #MerkurBreach #Privacy

mastodon.socialMastodon

This is the first I’ve heard of a “#BrushingScam,” where scammers “brush up” the reviews and trustworthiness of their online storefronts by using your personal data to order and review something on your behalf. They even send you the thing in hopes of #phishing more to commit #IdentityTheft.

proton.me/blog/brushing-scam

So now you have to treat the receipt of unordered merchandise the same as any other unsolicited commercial communication: a data #breach signal.

Proton · Received an unexplained package? It could be a brushing scam | ProtonA brushing scam means your personal data has leaked online. Learn how to protect yourself with hide-my-email aliases and dark web monitoring.

With #musk having access to all kinds of data now it seems like a lot of folks are recommending putting a freeze on your #credit to help avoid #IdentityTheft. I went through that today and while it was pretty painless creating an account with Equifax and Experian, Transunion really buries and hides the info as it seems like they would really like you to sign up and pay them a monthly fee. You don't have to by the way, they are required to do this for free. Anyway, for folks looking to do this themselves, I thought I'd type up the links and the various contact information:

TransUnion: service.transunion.com/dss/ord

Experian: experian.com/help/login.html

Equifax: my.equifax.com/consumer-regist

Having the online accounts are a double-edged sword in that someone could technically gain access to that and request your credit be unfrozen. You can still freeze your credit if you do not wish to create accounts with the three agencies. This can be done either by mail or by phone. By mail you need to provide your full name, social security number, address history for the past two years, date of birth, a copy of a utility bill or bank statement from the last 60 days, and a copy of a government issued identification card with your address on it (note that passports generally do not contain that so you'll want to use a driver's license or state-issued ID). Again here's the info you need:

TransUnion:
1-800-916-8800
TransUnion Credit Freeze
P.O. Box 160
Woodlyn, PA 19094

Experian:
1-888-397-3742
Experian Security Freeze
P.O. Box 9554
Allen, TX 75013

Equifax:
1-888-298-0045
Fill out the form here: assets.equifax.com/assets/pers and then mail to:
Equifax Information Services LLC
P.O. Box 105788
Atlanta, GA 30348-5788

If you have online accounts or you call, they are required by law to freeze your credit within 1 business day of you requesting it and unfreeze it within 1 hour. By mail it needs to be frozen within 3 business days of receipt of your mailing and unfrozen likewise within 3 business days of receiving your mailing.

Please note, you'll need to unfreeze your credit when applying for a loan, mortgage, etc.

I suspect the links and the required information changes with time so the above links may not work if you're finding this information and it's a long time past February 2025. So if it is, just confirm the above is still correct before going through the process.

The #USTreasury data has been compromised (if not, it's pretty damn close) so here's a #PSA:

FREEZE YOUR #CREDIT REPORTS.

NOW.

The #Treasury data is either going to be sold to thieves or used to f people over because that's what Those People do.

Lock your credit down before you get calls from collection agencies wondering why you haven't made any payments on [something] you didn't know you bought. If your credit can't be freely checked, they can't open new lines of credit to buy swastikas on Etsy or whatever the f they buy.

bricksandclicks.marketing/secu

Bricks & Clicks MarketingHow to freeze your credit reportsLearn how to freeze your credit reports on all three credit reporting agencies: Equifax, Experian, & Transunion. Links, phone numbers, & tips provided.
#US#USpol#Fraud

”Nothing short of an administrative coup“— @theatlantic.com 



“Elon Musk is not the president, but it does appear that he—a foreign-born, unelected billionaire who was not confirmed by Congress—is exercising profound influence over the federal government of the United States, seizing control of information, payments systems, and personnel management. It is nothing short of an administrative coup.”

theatlantic.com/technology/arc #musk #coup #IdentityTheft

The Atlantic · Elon Musk’s Bureaucratic CoupBy Charlie Warzel
Continued thread

Today is also a remeberence day of how #StateSponsoredMalware from #GammaGroup is used for a #masssurveillance #GreyMarketCALEA #DigitalSlaverySystem but also is being watched by other #StateSponsoredMalware that competes with #FinFisher #FinSpy #Finsky who's 100's of MILLIONS of installs of its clients in #AMER is used for #cryptowallettheft, #identitytheft , #propaganda & #GangStalking purposes by #OfficerProxys', luckily, #InternalAffairs can review who accessed what, when & where, for public reviews 🔍🧐.

Every Day is #infosec
👀
🔬
☣️📲☣️
👨‍⚖️ #CALEA #TCPDUMP #watchDay 👩‍⚖️

Make it a priority to #freeze your #credit...
...unless you don't mind #identitytheft & look forward to spending a year with lawyers repairing the damage criminals did in your name like opening financial accounts, buying cars & establishing leases.
✅ usa.gov/credit-freeze

www.usa.govHow to place or lift a security freeze on your credit report | USAGovLearn how to place a credit freeze. This prevents any new credit accounts from being created in your name and helps prevent identity theft.

Massive Data Breach at Wolf Haldenstein Exposes 3.5 Million Individuals: A Wake-Up Call for Cybersecurity

In a shocking revelation, Wolf Haldenstein law firm has disclosed a significant data breach affecting approximately 3.5 million individuals. This incident highlights critical vulnerabilities in data p...

news.lavx.hu/article/massive-d

Almost every person in the US has had their information stolen from a corporation that forces people to share that information. I'm sick of paying for the corporation's carelessness and criminality.

Each time a person's identity is stolen and used by malicious characters, each corporation that allowed the harmed individual's information to be stolen should have to pay back the harmed individual, plus damages and interest.

#Capitalism
#corpocracy
#IdentityTheft

Here's today's example of how all the #identityProtection companies are incompetent.
This is a screenshot from the enrollment process at #identityDefense.com.
Notice that the first field is asking me for a date but not telling me what date I'm supposed to enter.
I'm guessing they're asking for my birth-date, but I shouldn't have to guess.
Did anybody test this before they released it, and if so, are the testers so incompetent that they failed to flag this issue?
#infosec #privacy #identityTheft

Public Warning.

If you EVER, and I do mean EVER see a QR code for anything... not just some things, ANYTHING.

Treat it as a scam, do not scan it, they can easily be covered up with malicious redirects to fake sites to steal your financial details. Direct you to malware sites to try and infect your device.

Treat them all the same... as toxic, potential harmful to your identity and security.

Never trust them... EVER!!!

If you 100% must use one, do what you should be doing at any (ATM) cash machine, check for devices that have been installed by crooks. See if you can peel the code off, not just at the area around the code, but the whole sign... look for anything unusual and if you have any doubts... even if it's 1% doubt... DON'T USE IT

This isn't scaremongering, scammers and thieves are out there every day, placing fake QR codes on signs all over the place. No where is safe from them. The way to win is not to play. Don;t buy into the enshitification of everything, don;t be told that you can ONLY do it one specific way (legally they have to offer more than one way to pay for a service).

Please boost and spread the word.

#QRCodes
#ScamQRCodes
#Scammers
#Thieves
#IdentityTheft