Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Filter this topic showing only the reply marked as answer View this topic in a long page with up to 500 replies per page Create new topic
1 | ... | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29
Bung
6734 posts

Uber Geek
+1 received by user: 2927

Subscriber

  #3452700 13-Jan-2026 17:30
Send private message quote this post

MFA might help one account at a time, it wasn't the cure for one login being able to accesss every "Health Documents" folder.




boosacnoodle
1280 posts

Uber Geek
+1 received by user: 862


  #3457301 30-Jan-2026 16:52
Send private message quote this post

A company with, as far as I can tell, very little online presence has made a bold claim that they have identified the MMH hacker. Further investigation shows a website, which links to a Discord, where people can report incidents - with is largely empty aside from boilerplate posts. I'm left wondering if RNZ got duped.

 

https://www.rnz.co.nz/news/national/585494/cybersecurity-group-identifies-person-behind-manage-my-health-hack 


matthewperrin
22 posts

Geek
+1 received by user: 11


  #3457303 30-Jan-2026 16:58
Send private message quote this post

boosacnoodle:

 

A company with, as far as I can tell, very little online presence has made a bold claim that they have identified the MMH hacker. Further investigation shows a website, which links to a Discord, where people can report incidents - with is largely empty aside from boilerplate posts. I'm left wondering if RNZ got duped.

 

https://www.rnz.co.nz/news/national/585494/cybersecurity-group-identifies-person-behind-manage-my-health-hack 

 



Lol yes I was just trying to investgiate who the heck IOC3 is supposed to be. IOC3 -> IOCCC, but there are no related domain names or pages associated with that.
LLM's tell me no such real international organisation with any jurisdiction exists with that name or any related name.

And the linkedin points to a private tiny web security company.

Seems like the newsmedia got baited. 




freitasm

BDFL - Memuneh
80658 posts

Uber Geek
+1 received by user: 41071

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3457305 30-Jan-2026 17:00
Send private message quote this post

Grain of salt, etc.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


Zigg
437 posts

Ultimate Geek
+1 received by user: 307


  #3457306 30-Jan-2026 17:00
Send private message quote this post

"Those responsible, a hacker who calls themselves Kazu"

 

Big reveal there!


geek3001
221 posts

Master Geek
+1 received by user: 331

ID Verified
Subscriber

  #3457307 30-Jan-2026 17:09
Send private message quote this post

I read the report earlier, and my immediate thought was that it would surely be highly unlikely for the perpetrator to be named by a seemingly minor entity, before they were actually apprehended by whatever authority.

 

I would have expected any announcement from our own NZ authorities after the perpetrator was arrested.

 

A quick Google of the spokesperson named, seems to be an NZ actor based in the UK.

 

My $0.02 - I doubt the validity of the report and would say RNZ has been had good and proper.


 
 
 
 

Shop now for Dyson appliances (affiliate link).
boosacnoodle
1280 posts

Uber Geek
+1 received by user: 862


  #3457310 30-Jan-2026 17:14
Send private message quote this post

Where is the report?


geek3001
221 posts

Master Geek
+1 received by user: 331

ID Verified
Subscriber

  #3457313 30-Jan-2026 17:18
Send private message quote this post

boosacnoodle:

 

Where is the report?

 

 

By report, I meant the RNZ report at the URL that you posted earlier.


matthewperrin
22 posts

Geek
+1 received by user: 11


  #3457314 30-Jan-2026 17:19
Send private message quote this post

geek3001:

 

I read the report earlier, and my immediate thought was that it would surely be highly unlikely for the perpetrator to be named by a seemingly minor entity, before they were actually apprehended by whatever authority.

 

I would have expected any announcement from our own NZ authorities after the perpetrator was arrested.

 

A quick Google of the spokesperson named, seems to be an NZ actor based in the UK.

 

My $0.02 - I doubt the validity of the report and would say RNZ has been had good and proper.

 

 

I get major discord scriptkiddie vibes.


insane
3325 posts

Uber Geek
+1 received by user: 1006

ID Verified
Trusted
2degrees
Subscriber

  #3457332 30-Jan-2026 19:02
Send private message quote this post

RNZ:

 

.."We're just mindful that we're still looking into this individual, and we don't want to mistakenly drive this person underground by making them aware that there are these kinds of investigations ongoing into them."..

 

 

Then goes to the press...


turtleattacks
1008 posts

Uber Geek
+1 received by user: 305

Trusted

  #3458094 2-Feb-2026 16:01
Send private message quote this post

I was just having a look, joking around with my friends and noticed how easy it would be to register a domain, clone their login and send out 1000's of known NZ emails from a previous leak 

Forget DKIM, DMARC, SPF etc... I would almost guarantee that this wouldn't be 0% effective. 

 

MMH should really register these similar domain names. 

 

 





 
 
 

Move to New Zealand's best fibre broadband service (affiliate link). Free setup code: R587125ERQ6VE. Note that to use Quic Broadband you must be comfortable with configuring your own router.
Nate001
677 posts

Ultimate Geek
+1 received by user: 465


  #3458095 2-Feb-2026 16:11
Send private message quote this post

turtleattacks:

 

MMH should really register these similar domain names. 

 

 

But that costs money! /s

 

On a serious note - goes to show the operation they are running... 


sampler
468 posts

Ultimate Geek
+1 received by user: 126

ID Verified
Trusted
Lifetime subscriber

  #3458096 2-Feb-2026 16:12
Send private message quote this post

turtleattacks:

 

I was just having a look, joking around with my friends and noticed how easy it would be to register a domain, clone their login and send out 1000's of known NZ emails from a previous leak 

Forget DKIM, DMARC, SPF etc... I would almost guarantee that this wouldn't be 0% effective. 

 

MMH should really register these similar domain names. 

 

 

 

 

Cereus Health Group (owners of the ManageMyHealth platform) do have a number of domains registered (mmh.nz for example). However trying to stop typo squatting would be very hard and just a ongoing battle.


turtleattacks
1008 posts

Uber Geek
+1 received by user: 305

Trusted

  #3458097 2-Feb-2026 16:12
Send private message quote this post

Nate001:

 

turtleattacks:

 

MMH should really register these similar domain names. 

 

 

But that costs money! /s

 

On a serious note - goes to show the operation they are running... 

 

 

But didn't they just get independently audited by security experts?

Wouldn't this be raised? Surely? 





turtleattacks
1008 posts

Uber Geek
+1 received by user: 305

Trusted

  #3458099 2-Feb-2026 16:14
Send private message quote this post

sampler:

 

turtleattacks:

 

I was just having a look, joking around with my friends and noticed how easy it would be to register a domain, clone their login and send out 1000's of known NZ emails from a previous leak 

Forget DKIM, DMARC, SPF etc... I would almost guarantee that this wouldn't be 0% effective. 

 

MMH should really register these similar domain names. 

 

 

Cereus Health Group (owners of the ManageMyHealth platform) do have a number of domains registered (mmh.nz for example). However trying to stop typo squatting would be very hard and just a ongoing battle.

 

 

Not really typo squatting. They can set up a domain, with https, and mail server that can send out password reset emails with all the right authentications and checks by Gmail/Outlook/Yahoo!/Hotmail/Rocketmail. 

 

And, a page that looks exactly like their login. 





1 | ... | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29
Filter this topic showing only the reply marked as answer View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.