Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


boosacnoodle

963 posts

Ultimate Geek


#319696 22-May-2025 23:07
Send private message quote this post

I just now logged into Mighty Ape and, concerningly, on every other page refresh it is logging me in as someone else. It's given me several different user accounts.

 

Not only is it concerning that I could potentially place an order on their account, but I can see their credit card details, home addresses, emails and full order history.


View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2 | 3 | 4 | 5
freitasm
BDFL - Memuneh
79263 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3375803 22-May-2025 23:15
Send private message quote this post

Not good. Contacted them yet? 





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup




michaelmurfy
meow
13242 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #3375804 22-May-2025 23:22
Send private message quote this post

I just verified this. 

 

I never use Mightyape so wasn’t logged in, however I was. I could see everything including name, address and there was a credit card linked. There was nothing stopping me from potentially placing an order. 

 

This is bad… I’ve tried a few email addresses now to let them know but just get bounce backs. Appears to be somewhat resolved now. 





Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


michaelmurfy
meow
13242 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #3375807 23-May-2025 01:43
Send private message quote this post

And just now I got an email from somebody random who was logged into my account and also provided me screenshots of my account showing personal information. I went ahead and treated this account as compromised, changed my password and logged out hopefully invalidating all session cookies. We’ve both raised a case with Mightyape and I’ll contact CERT.

 

Same thing applied with him - he was fully logged into my account and could see anything along with potentially place orders. 





Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.




rscole86
4973 posts

Uber Geek

Moderator
Trusted
Lifetime subscriber

  #3375808 23-May-2025 06:10
Send private message quote this post

Tried my two accounts, no problem at 530 this morning. 


Qazzy03
478 posts

Ultimate Geek


  #3375810 23-May-2025 06:35
Send private message quote this post

I just logged into my account, and it was successful. 

 

I did remove my saved payment information information though.


xpd

xpd
Geek @ Coastguard NZ
13765 posts

Uber Geek

Retired Mod
ID Verified
Trusted
Lifetime subscriber

  #3375865 23-May-2025 08:20
Send private message quote this post

Wow.... be highly surprised if they publicly admit it within the next 24hrs. 

 

 

 

 





       Gavin / xpd / FastRaccoon / Geek of Coastguard New Zealand

 

                      LinkTree

 

 

 


networkn
Networkn
32350 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #3375872 23-May-2025 08:41
Send private message quote this post

xpd:

 

Wow.... be highly surprised if they publicly admit it within the next 24hrs. 

 

 

I'd expect them not to, until they complete an investigation into what is wrong, what caused it, and what data has been accessed so they can actually make a disclosure. 

 

Their website redesign has been a pretty sad tale of woe. 

 

Quite a shame as they were actually doing pretty well prior to that, I thought things were actually on par or slightly better than before Kogan bought Mighty Ape. 

 

 


 
 
 
 

Shop now for Lenovo laptops and other devices (affiliate link).
  #3375874 23-May-2025 08:46
Send private message quote this post

We knew the mighty have fallen for quite some time now.. oh it's still falling?

 

Just falsified info on my mighty account. It also doesn't help when changing the email address, they send out the email verification to the current one saying "Your Mighty Ape email address has just been changed to [current email address]." instead of showing what email address it's being changed to.


freitasm
BDFL - Memuneh
79263 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3375875 23-May-2025 08:49
Send private message quote this post

And this, people, is why I never click the "Save the credit card info for faster checkout next time" on any service.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


freitasm
BDFL - Memuneh
79263 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3375878 23-May-2025 09:02
Send private message quote this post

I reached out to someone at Mighty Ape. I explained how this happens to some people when logged in, but it's unknown how many people have their information leaked.

 

I pointed out to this thread and mentioned your case specifically @michaelmurfy, based on the details you passed (email).

 

This is being investigated.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


Jizah
236 posts

Master Geek


  #3375879 23-May-2025 09:04
Send private message quote this post

freitasm:

 

And this, people, is why I never click the "Save the credit card info for faster checkout next time" on any service.

 

 

 

 

This still won't stop me. It might if I used a Debit Plus.


michaelmurfy
meow
13242 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #3375882 23-May-2025 09:10
Send private message quote this post

I've also notified CERT NZ (despite it being a privacy issue) along with the Privacy Commissioner as I've got verification my own account was compromised in this incident. Yet to hear back from Mightyape.





Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


RockCartel
17 posts

Geek


  #3375885 23-May-2025 09:17
Send private message quote this post

freitasm:

 

And this, people, is why I never click the "Save the credit card info for faster checkout next time" on any service.

 

 

This 100% , it's not worth the minor convenience. 


freitasm
BDFL - Memuneh
79263 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3375888 23-May-2025 09:24
Send private message quote this post

RockCartel:

 

freitasm:

 

And this, people, is why I never click the "Save the credit card info for faster checkout next time" on any service.

 

 

This 100% , it's not worth the minor convenience. 

 

 

Look, I might be wrong and something happens tomorrow. But I have had credit cards since 1989 and never had to cancel or change a number.

 

I know some people who cancel cards every quarter because there's always a "strange transaction". This causes a lot of problems when they have energy, broadband, mobile and other services on auto-payment from credit cards. Not even thinking of the actual possibility of fraudulent transactions.

 

No joke. Really.





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


 1 | 2 | 3 | 4 | 5
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.