{"id":274397,"date":"2024-03-30T10:41:15","date_gmt":"2024-03-30T05:11:15","guid":{"rendered":"https:\/\/dripp.zone\/news\/?p=274397"},"modified":"2024-03-30T10:41:15","modified_gmt":"2024-03-30T05:11:15","slug":"phishing-scam-targeted-decrypt-newsletter-subscribers-heres-the-latest-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/phishing-scam-targeted-decrypt-newsletter-subscribers-heres-the-latest-crypto-news\/","title":{"rendered":"Phishing Scam Targeted Decrypt Newsletter Subscribers\u2014Here\u2019s the Latest &#8211; Crypto News"},"content":{"rendered":"<div style=\"position:relative;overflow:visible;font-size:1.2em;line-height:1.58\">\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\"><span style=\"font-weight:400\">Early in the morning of March 27, hackers impersonating <\/span><i><span style=\"font-weight:400\">Decrypt<\/span><\/i><span style=\"font-weight:400\"> sent an email to our newsletter subscribers announcing a fictitious token airdrop. As soon as we got wind of the phishing attempt, we sent a follow-up email notifying our readers of the scam.\u00a0<\/span><\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\"><span style=\"font-weight:400\">However, in our haste to warn our subscribers, and because of <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.mailerlite.com\/newsroom\/securityincidentnotice\" class=\"sc-adb616fe-0 bJsyml\"><span style=\"font-weight:400\">a similar phishing attempt<\/span><\/a><span style=\"font-weight:400\"> that occurred in January, we incorrectly blamed our email service provider, MailerLite, for this attack. In fact, the hackers had apparently obtained our password key to the service from someone on <\/span><i><span style=\"font-weight:400\">Decrypt<\/span><\/i><span style=\"font-weight:400\">\u2019s side\u2014MailerLite was not at fault.\u00a0<\/span><\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\"><span style=\"font-weight:400\">\u201c<\/span><span style=\"font-weight:400\">Due to security reasons, MailerLite does not store information on API keys, therefore, it is not possible to access it in MailerLite\u2019s admin panel or the account in general,\u201d a MailerLite spokesperson told us today. \u201cIt means that even though Decrypt Media\u2019s account was affected during the data breach that happened at MailerLite on the 23rd January, 2024, perpetrators were not able to access API keys that could lead to sending of phishing campaigns on 27th March, 2024.\u201d<\/span><\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\"><span style=\"font-weight:400\">So shame on us for jumping to the wrong conclusion, and we sincerely apologize to MailerLite.<\/span><\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\"><span style=\"font-weight:400\">We\u2019ve been digging into what happened and will be working with law enforcement. According to MailerLite, <\/span><span style=\"font-weight:400\">\u201cthe phishing campaigns were orchestrated via the MailerLite API, originating from the IP address &#8220;69.4.234.86&#8221; and utilizing the user agent &#8220;python-requests\/2.31.0.&#8221; After the intruders accessed our email list, they removed any addresses that ended in decrypt.co or decryptmedia.com so that our staffers wouldn\u2019t be immediately alerted, and sent out their bogus email.<\/span><\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\"><span style=\"font-weight:400\">Luckily, the vast majority of our readers are wary of these sorts of phishing attempts; only one person attempted to connect their wallet to the bogus address.<\/span><\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\"><span style=\"font-weight:400\">But that is one too many. <\/span><span style=\"font-weight:400\">As mentioned in our earlier email, crypto scams are all too prevalent in our industry, and getting more sophisticated all the time. <\/span><i><span style=\"font-weight:400\">Decrypt<\/span><\/i><span style=\"font-weight:400\">, along with nearly every other crypto firm, has been <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/bovyzb.clicks.mlsend.com\/tf\/cl\/eyJ2Ijoie1wiYVwiOjEyMTA1OSxcImxcIjoxMTY5MzI0MDAxNjE3NTI4MDcsXCJyXCI6MTE2OTMyNDA1MTI3ODA4NTgyfSIsInMiOiJiNmY5NmZlZTAxMjUwYTNmIn0\" class=\"sc-adb616fe-0 bJsyml\"><span style=\"font-weight:400\">impersonated or otherwise used as an attack vector<\/span><\/a><span style=\"font-weight:400\">. Hackers have even gone as far as to set up entirely separate websites, <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/bovyzb.clicks.mlsend.com\/tf\/cl\/eyJ2Ijoie1wiYVwiOjEyMTA1OSxcImxcIjoxMTY5MzI0MDAxNjY5OTU2ODgsXCJyXCI6MTE2OTMyNDA1MTI3ODA4NTgyfSIsInMiOiJjMzkxZWZjZDFjZDI0OWM2In0\" class=\"sc-adb616fe-0 bJsyml\"><span style=\"font-weight:400\">fake Discord servers<\/span><\/a><span style=\"font-weight:400\">, and social media accounts impersonating our staff. (Note that we have only two domains: decrypt.co and decryptmedia.com\u2014if someone directs you to another domain, beware!)<\/span><\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\"><b>So please be careful out there<\/b><span style=\"font-weight:400\">. And we will, too. Thank you as always for reading <\/span><i><span style=\"font-weight:400\">Decrypt<\/span><\/i><span style=\"font-weight:400\">.<\/span><\/p>\n<div class=\"my-4 border-b border-decryptGridline\">\n<div class=\"text-start p-8 md:py-12 md:px-12 max-w-prose relative\"><span class=\"border-t-4 border-l-4 w-4 h-4 md:border-t-[6px] md:border-l-[6px] md:w-6 md:h-6 border-decryptPurple dark:border-decryptNeon gg-dark:border-cc-pink-2 absolute top-4 left-4 md:top-6 md:left-6\" \/><span class=\"border-t-4 border-l-4 w-4 h-4 md:border-t-[6px] md:border-l-[6px] md:w-6 md:h-6 border-decryptPurple dark:border-decryptNeon gg-dark:border-cc-pink-2 absolute rotate-180 bottom-4 right-4 md:bottom-6 md:right-6\" \/><\/p>\n<h3 class=\"font-akzidenz-grotesk font-bold text-xl md:text-3xl mb-6 md:text-center gg-dark:text-white\">Stay on top of crypto news, get daily updates in your inbox.<\/h3>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Early in the morning of March 27, hackers impersonating Decrypt sent an email to our newsletter subscribers announcing a fictitious token airdrop. As soon as we got wind of the phishing attempt, we sent a follow-up email notifying our readers of the scam.\u00a0 However, in our haste to warn our subscribers, and because of a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":274398,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[230,225,221,227,226,228,229,60,223,224,222],"class_list":["post-274397","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency","tag-brave","tag-coinbase","tag-crypto","tag-decentralised","tag-decentralized","tag-decentralized-exchange","tag-erc-20","tag-featured","tag-meme-coin","tag-robinhood","tag-solana"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/274397","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=274397"}],"version-history":[{"count":2,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/274397\/revisions"}],"predecessor-version":[{"id":274400,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/274397\/revisions\/274400"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/274398"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=274397"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=274397"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=274397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}