Money Watch – Personal Finance Blog

MoneySavingExpert Forums Hacked?

MoneySavingExpert Forums Hacked?

According to a  growing thread on MoneySavingExpert, it appears that certain users’ email addresses and usernames may have been harvested and used to spread spam.

The email purports to be from MoneyExpert (a different company to MoneySavingExpert, but legitimate), and also links to defaqto.com – again a legitimate website, although MoneyExpert and Defaqto are unlikely to have anything to do with this and are just used to make the email look official. Here’s the text of the email:

Hi XXXXX,
MoneyExpert: News-Tool.
At MoneyExpert, we believe it’s only fair that you can compare products from the whole of the marketplace. After all, it’s the only way to be sure you’re not missing that perfect deal. That’s why we insist on being independent, which means we’re never biased towards any particular company. We provide details on every product from all of the major providers in the market. We partner with Defaqto, the people who deliver product data to the FSA, to ensure that our tables are accurate and complete. You can find out more about Defaqto at www.defaqto.com.
Download “MoneyExpert News-Tool”:
[link removed]
_________
MoneyExpert is VAT registered. Our VAT registration number is 825281335.

This apparent hack follows another breach last year, which took advantage of a security flaw  found in the forum software that MSE uses, and there are some suggestions that the data used may have been harvested during that attack – no recent breaches have yet to be identified.

It provides a reminder of some of the measures you should take to keep your details secure:

Whilst there will be the usual moans and groans from forum members about the security of the site, hacking is unfortunately one of the problems facing large, popular websites, where there is valuable data for spammers. And it is a constant battle that technical teams face to keep hackers out. Whilst they should certainly try to ensure that their systems take security very seriously, I believe that we as users also have a responsibility to minimise the effects of any breaches by using measures such as those suggested above.

Exit mobile version