Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 
MikeB4
MikeB4
18775 posts

Uber Geek
+1 received by user: 12766

ID Verified
Trusted
Subscriber

  #3414110 12-Sep-2025 12:34
Send private message

I received the email this morning. I am not feeling that comfortable with this answer from Mercury. I am going to follow up





Here is a crazy notion, lets give peace a chance.




turtleattacks

1008 posts

Uber Geek
+1 received by user: 305

Trusted

  #3414113 12-Sep-2025 12:36
Send private message

MikeB4:

 

I received the email this morning. I am not feeling that comfortable with this answer from Mercury. I am going to follow up

 

 

You are right to feel so. 

 

Obviously some data were downloaded by scammers - from reddit: 

 

So I work in security among other areas and started getting weird scam calls about my Mercury account recently. Got suspicious and decided to poke around their API to see what was going on.





tardtasticx
3084 posts

Uber Geek
+1 received by user: 483


  #3414298 12-Sep-2025 18:30
Send private message

We believe it’s unlikely your rewards profile has been accessed, and we continue to strengthen our rewards security.

 

if I got this message I’d assume “unlikely” means they have no definitive proof either way. Likely that means the API has inadequate logging and they’ve made some assumptions.




freitasm
BDFL - Memuneh
80652 posts

Uber Geek
+1 received by user: 41044

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3414300 12-Sep-2025 18:36
Send private message

What other information was available through the API? Could anyone enumerate users and emails? That alone would be a big deal.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


MadEngineer
4591 posts

Uber Geek
+1 received by user: 2570

Trusted

  #3414677 13-Sep-2025 23:41
Send private message

Try interacting with AI and ask it to use python to do something with a documented API for website that you use.  It doesn't take much to have it lead you down the path of pressing f12 and looking through the data source to find an ID number or other useful goodies.

 

Any normal person would then wonder what happens if they change that number.  It's literally child's play, even more so now with AI helping anyone to make simple queries.





You're not on Atlantis anymore, Duncan Idaho.

k1w1k1d
1713 posts

Uber Geek
+1 received by user: 1311


  #3414741 14-Sep-2025 10:35
Send private message

So, should all Mercury clients change their passwords?

 

 


 
 
 

Stream your favourite shows now on Apple TV (affiliate link).
freitasm
BDFL - Memuneh
80652 posts

Uber Geek
+1 received by user: 41044

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3414742 14-Sep-2025 10:37
Send private message

@MadEngineer:

 

Try interacting with AI and ask it to use python to do something with a documented API for website that you use.  It doesn't take much to have it lead you down the path of pressing f12 and looking through the data source to find an ID number or other useful goodies.

 

Any normal person would then wonder what happens if they change that number.  It's literally child's play, even more so now with AI helping anyone to make simple queries.

 

 

I know how to do it. I asked in the event someone have already done and it was known or part of a post-mortem by now.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


turtleattacks

1008 posts

Uber Geek
+1 received by user: 305

Trusted

  #3414745 14-Sep-2025 10:46
Send private message

k1w1k1d:

 

So, should all Mercury clients change their passwords?

 

 

 

 

No, the only (supposedly) exposed data fields are name, address and rewards. 

As far as I know (likely hashed) passwords and emails are not leaked (according to their disclosure). 





freitasm
BDFL - Memuneh
80652 posts

Uber Geek
+1 received by user: 41044

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #3414746 14-Sep-2025 11:08
Send private message

turtleattacks:

 

k1w1k1d:

 

So, should all Mercury clients change their passwords?

 

 

No, the only (supposedly) exposed data fields are name, address and rewards. 

As far as I know (likely hashed) passwords and emails are not leaked (according to their disclosure). 

 

 

Still a big deal. If people have email addresses and a list of leaked passwords from somewhere else, they don't have to do a password spray and spend days trying to login, they can just try the leaked password for each email address once, making the whole process a lot faster.

 

This could validate email/password is being reused and try that combination again in higher value targets, for example banks.

 

This is good for them because banks are usually resistant to password sprays thanks to throtthling, but single attempts with correct username/email and password would not trigger some rules.





Referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies 

 

Support Geekzone by subscribing (browse ads-free), or making a one-off or recurring donation through PressPatron.

 


MadEngineer
4591 posts

Uber Geek
+1 received by user: 2570

Trusted

  #3415248 15-Sep-2025 20:10
Send private message

freitasm:

 

@MadEngineer:

 

Try interacting with AI and ask it to use python to do something with a documented API for website that you use.  It doesn't take much to have it lead you down the path of pressing f12 and looking through the data source to find an ID number or other useful goodies.

 

Any normal person would then wonder what happens if they change that number.  It's literally child's play, even more so now with AI helping anyone to make simple queries.

 

 

I know how to do it. I asked in the event someone have already done and it was known or part of a post-mortem by now.

 

Sorry, my post wasn’t an answer to your previous one. It’s in agreement at how their response is a bit naff. 





You're not on Atlantis anymore, Duncan Idaho.

fe31nz
1294 posts

Uber Geek
+1 received by user: 423


  #3415276 16-Sep-2025 01:19
Send private message

Yesterday I got a phishing email that was pretending to be Mercury.  The link to click on was not Mercury, but they did pretty well in simulating a Mercury email.  So I am suspecting that someone is using the data leaked from the bad API to target Mercury customers like me.


 
 
 

Stream your favourite shows now on Apple TV (affiliate link).

xpd

xpd
Geek of Coastguard
14116 posts

Uber Geek
+1 received by user: 4578

Retired Mod
ID Verified
Trusted
Lifetime subscriber

  #3415318 16-Sep-2025 11:38
Send private message

fe31nz:

 

Yesterday I got a phishing email that was pretending to be Mercury.  The link to click on was not Mercury, but they did pretty well in simulating a Mercury email.  So I am suspecting that someone is using the data leaked from the bad API to target Mercury customers like me.

 

 

I got one too, but don't think it was directly related as it went to an account I don't use for anything except gaming. And I don't use Mercury. So more coincidence or someone just trying to "cash" in on the news. 

 

 

 





XPD / Gavin

 

LinkTree

 

 

 


richms
29098 posts

Uber Geek
+1 received by user: 10209

Trusted
Lifetime subscriber

  #3415321 16-Sep-2025 11:40
Send private message

Feel left out. No spam at all about it.





Richard rich.ms

geek3001
220 posts

Master Geek
+1 received by user: 331

ID Verified
Subscriber

  #3419911 30-Sep-2025 08:24
Send private message

MadEngineer:

 

Anyone with Mercury able to request access logs to their account?  That will answer two questions - the obvious but also if they’re even logging API access at all.

 

 

I made a request based upon the Privacy Act for logs, and they have not provided that, yet, so I have asked again.

 

They have however replied with this:

 

 

 


geek3001
220 posts

Master Geek
+1 received by user: 331

ID Verified
Subscriber

  #3420633 2-Oct-2025 12:15
Send private message

@MadEngineer:

 

Anyone with Mercury able to request access logs to their account?  That will answer two questions - the obvious but also if they’re even logging API access at all.

 

 

They tell me this:

 

 

Not much use if we find out there was a problem prior to that, as they would be unable to confirm any activity on any accounts.


1 | 2 
View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.