Potential email address leak?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- :
- Potential email address leak?
Potential email address leak?
19-03-2016 1:30 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
They both have the same source IP address in Vietnam.
Do we have a problem?

Re: Potential email address leak?
19-03-2016 1:39 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
... which Plusnet have not made any comment on, in an entire month !

If you look at your email headers, do they also contain other Plusnet customers email addresses, particularly mailbox names that look to be associated with the Usergroup forum ?
Re: Potential email address leak?
19-03-2016 1:49 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Potential email address leak?
21-03-2016 8:28 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I am surprised that I seem to be the only one posting about this, given the furore in late 2014.
So I contacted Plusnet support, where it was suggested I keep posting here or call tomorrow during office hours. That latter suggestion is not practical for me, so I will post again. I will also post a single message on the end of the old topic, in case someone spots it there who is interested.
Re: Potential email address leak?
21-03-2016 10:24 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator

Re: Potential email address leak?
21-03-2016 10:45 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator

Re: Potential email address leak?
23-03-2016 10:59 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I've just checked my server logs (obviously I can now only see attempted deliveries to a mailbox that doesn't exist) and sure enough, there have been some more attempts to deliver to that address:
Quote swoofe.ru
149.154.68.194
webmastermg-spb.ru
Mar 14, 2016 1:04:01 AM
nschwmtas03p.mx.bigpond.com
61.9.189.143
grimreepabigpond.com
Feb 5, 2016 11:59:11 AM
mail-am1hn0245.outbound.protection.outlook.com
157.56.112.245
Thorstein.Olafssonomega.no
Feb 3, 2016 4:37:16 PM
Crying emoticon in the sending addresses (possibly not falsified in the case of the second one) replacing the obvious character,
James
Re: Potential email address leak?
31-03-2016 7:46 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Potential email address leak?
31-03-2016 5:38 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
The Plusnet Service Status address is still working, as it received a couple of genuine messages today.
Re: Potential email address leak?
31-03-2016 11:50 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Potential email address leak?
15-04-2016 6:40 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I just received a pair of 'test' messages, with the same content as the initial ones a month ago. This time from a Mali IP address.
If Plusnet are ignoring this, hoping it will go away, it ain't working.
Re: Potential email address leak?
23-04-2016 2:47 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@Anotherone wrote:
And still no comment from Plusnet!
And that's after a couple of PMs to one of the management team.
Sadly after the pasting @bobpullen got last time he tried to be up front and honest about matters such as this, I'm not surprised (even though it saddens me) that there is no response here from the front line team. Sadly I suspect that PN towers is being run by the BT legal lads these days, rather than honest engineers of days long time past.
In another browser tab, login into the Plusnet user portal BEFORE clicking the fault & ticket links
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
If this post helped, please click the Thumbs Up and if it fixed your issue, please click the This fixed my problem green button below.
Re: Potential email address leak?
26-04-2016 6:37 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I received a repeat of the initial messages again, on 24/04/16.
So I have submitted a question to Plusnet.
What's the betting the first response is a link to spam advice, instead of an actual answer to my question...
Re: Potential email address leak?
30-04-2016 1:51 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I had a 24 minute online chat about this today.
info: You are now chatting with C. C: Good afternoon, I'm C. How can I help? Me: Hi C C: Hi J. Me: I have a problem that I have posted on the community forum at https://community.plus.net/t5/Email/Potential-email-address-leak/m-p/1329269 C: Okay. Me: Do you want to look at the forum or for me to repeat stuff here? C: I'm just having a look at the post myself. C: What mailboxes are the messages received by, are they targeted at random addresses? C: If you have 'catch all' enabled on your account then this might indicate the cause of the problem. C: I am aware of this issue and have previously discussed the issue with security and data protection officers but we haven't found any evidence of a genuine leak of information. Me: I will disregard your first two responses as they are meaningless in the light of my posting. The targeted mailboxes were only ever together within Plusnet and are the only mailboxes being targeted. The latter is evidence that they were harvested together and the former is the only place they could have been harvested. This supports the only possible conclusion that they were leaked from data held by Plusnet. C: The Plusnet User Group service is in fact operated by a third party and not as part of Plusnet. So this is not indication of a security breach within Plusnet's organisation. Me: Can you explain any other connection between the usergroup email address data and the status email address data? C: I don't unfortunately have any more information on this specific problem. My advice at this stage is to enable the 'catch all' and if you are receiving spam mail to use our spam filter. Me: I already have catchall enabled but, as I am careful with my email addresses, I receive approximately 7 spam emails per week (plus the two I have received due to this problem). I therefore do not need a third party spam filter. Thanks for your suggestion, but it does not have any bearing on determining the cause or source of the leaked data. C: Okay, then at this stage I would advise to wait a further response in regards to this issue on the community forum page. Me: Does that mean that Plusnet will be continuing to investigate? C: We will work closely with those who moderate the user group, user tools and community forum to investigate the issue and provide an appropriate investigation and response. Me: Thanks C, I will post further responses to the forum. C: No problem. Is there anything further that I might be able to help you with? Me: No, thanks. C: It's been great chatting to you today. I really appreciate your time and would love to hear any feedback that you might have. Please click this link to close the chat and answer a few questions about the experience you have had with me today. Don't forget to subscribe to <a href="www.youtube.com/user/plusnethelp target=" _blank="">Plusnet Help on YouTube for further help and support. Enjoy the rest of your day!
The info I gleaned from that was that somewhere, sometime, usergroup email address data and Plusnet service status email addresses existed together in the same place and that was the point of vulnerability..
PS. The only changes I made to the above chat were the names and my typos (to make it easier to read).
Re: Potential email address leak?
30-04-2016 5:27 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
OK so from the above, a simple question: in who's domain / control / environment is the pug service hosted?
The chat agent's response does not seek to deny that these emai addresses have been leaked, only denial is that anything has been leaked from PlusNET controlled services. That being the case, the implication in the response is that PlusNET has no breach case to answer.
So now that the forums are hosted by a third party, holding customer email addresses provided by PlusNET, who assumes responsibility for the security of that data? PlusNET who acquired the data or lithium into whose hands it has been entrusted.
it seems to me that on each of the recent occasions where an email address used exclusively in association with a user's PlusNET account ir associated servuce has escaped into the wild, a third party has been involved. What is it going to take for PlusNET to realise that the only way they can properly control access to client information is to keep it and the systems which use it in house behind their own security systems?
I wonder how long before the exclusive email address I setup for my forum identity (prior to this data being passed to lithium) escapes into the wild?
If you want to protect the integrity of your primary email address, make sure that's not the email address used on this forum.
PlusNET users can have email addresses in the form of anything1@username.plus.com.
If you have catch-all switched on, they will arrive in your default mailbox, if you prefer to have catch-all switched off, make anything1 an alias of the mailbox you want to receive those emails.
In another browser tab, login into the Plusnet user portal BEFORE clicking the fault & ticket links
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
If this post helped, please click the Thumbs Up and if it fixed your issue, please click the This fixed my problem green button below.
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page