Sweetwater account hacked

I mean your Sweetwater salesperson isn’t going to do a low level forensic analysis, if passwords available in any outside leak* are commonly re-used that is a drastically more likely vector than any other possibility.

*haveibeenpwned is fascinating/humbling

I wouldn’t save my card anywhere I don’t make regular weekly or semi-weekly purchases (e.g. my grocery delivery service).

1 Like

Yeah, also a very good point. Not entirely surprising that Sweetwater is large enough to have this interest from outside (might be more a US-based scam ring vs overseas?), but that’s another insecurity that we can address on our end.

It really seems to be a common case of credential stuffing. Which doesn’t really have anything to do with Sweetwater security.

https://owasp.org/www-community/attacks/Credential_stuffing

1 Like

Have access to SW acct now

  • Didn’t have 2FA :man_facepalming:
  • Just biometric login
  • SW refunded & cancelled the orders
  • Simple password from 2015 that was in a leak
  • SW cannot change your phone number, took 3 biz days to remove 2FA & fraudulent phone number
  • No remnants of fraud order/phone/email in my acct left

I get scammed like twice a year so fuck me, should prly tighten shit up finally. Luckily the banks have always had my back and give me funds back in a day.

Kinda hoping all this scam money is funding a rebellion somewhere

3 Likes

Glad you got it sorted out. Going forward I would HIGHLY recommend using a password manager like 1Password. I’ve been using it for many years and don’t know what I would do without it.

4 Likes

So is this then anything at all on Sweetwater ?

1 Like

Nothing was hacked past the initial website (not Sweetwater.)

The crook logged into the account since the email and password combination was shared with dozens of other sites.

Then the thread title is misleading, and we can feel safe using Sweetwater, assuming we do things in a safer acceptable way.

1 Like