Front Page Blog: iStock is Back. Please Read.

1|2|3|4 of 11
Displaying 1 to 20 of 219 matches.
Author
Message
Posted Tue Mar 3, 2009 8:22PM
On 2009-03-03 20:10:11, kkthompson wrote:

This afternoon a phishing attack was conducted in the forums and through sitemail. This attack created a fake istockphoto.com login screen, prompted the user for a username & password, saved them to a malicious server, then redirected the user back to the iStockphoto main page.

Some Q&A:

Is my credit card information safe?
iStockphoto does not store any credit card information, so there is no financial information to breach.

Is your site secure?
Our site is secure. We detected this attempted breach within minutes and implemented our security protocol: because we weren't sure how far-reaching it was, we took the site down to eliminate further exposure.

What should I do now?
Step 1: Please reset your iStock Password
Step 2: As a precaution, please make sure you reset all your online passwords on other sites if they happen to be the same as the one you use on iStockphoto.


(Edited on 2009-03-03 20:30:14 by kkthompson)
Posted Tue Mar 3, 2009 8:23PM
Thanks Kelly!
Posted Tue Mar 3, 2009 8:26PM

thank you, good to know that you guys are top of things as usual!


i thought it was BM 2.0 getting implemented!
Posted Tue Mar 3, 2009 8:26PM
Thanks istock for the efficiency in site security!
Posted Tue Mar 3, 2009 8:27PM
Thanks! Glad you all are on the ball against these losers! thank you thank you!
Posted Tue Mar 3, 2009 8:27PM
Scary as h*ck!
Posted Tue Mar 3, 2009 8:28PM
Thanks for being so quick to act. Probably just as well they didn't do it on a weekend or something, it might have taken longer to catch.
Posted Tue Mar 3, 2009 8:29PM
Awesome work, you'se guys! Also thanks for the updates via Twitter - that really helps!
Posted Tue Mar 3, 2009 8:29PM
Thanks for keeping us informed! Kudos to the IT guys!
Posted Tue Mar 3, 2009 8:30PM
Do we really have to change our password as well as all other related passwords on other sites even if we did not follow the phishing link(s)?
Posted Tue Mar 3, 2009 8:32PM
Where do you go to change your password? I can't find it.
Posted Tue Mar 3, 2009 8:32PM
There is a problem with JS on the site now. I can't open CN request for example.. Does it have anything to do with this attack? And yes, thanks for dealing with this so quickly.
Posted Tue Mar 3, 2009 8:32PM
Yes, I would like to know that too!
Posted By appleuzr:
Do we really have to change our password as well as all other related passwords on other sites even if we did not follow the phishing link(s)?
Posted Tue Mar 3, 2009 8:33PM
I would like to thank our security team who caught it right away--they did a really outstanding job. You can imagine things are hopping around here.

appleuzr: if you don't use the same password on all sites, you're fine.
Posted Tue Mar 3, 2009 8:33PM
Thanks Kelly! We really appreciate it
Posted Tue Mar 3, 2009 8:33PM
on the "account" tab on the top bar
Posted Tue Mar 3, 2009 8:34PM

Posted By FreeTransform:
Where do you go to change your password? I can't find it.


Go to your profile page - it's on the right hand side, under 'Tools'.
Posted Tue Mar 3, 2009 8:34PM
To change your password, go to your page and look to the right column (under your downloads). You'll see Tools and under that "change my password."
Posted Tue Mar 3, 2009 8:35PM
Uuuurgh! I've a feeling I got phished as I had to unexpectedly log in when I checked the site just before it went down. Password all changed now. (And I've got to work out where else I used that one - a few places I think, but as far as I can remember not for anything where they can get hold of my money! It's about time I changed it anyway, I guess.)
Posted Tue Mar 3, 2009 8:38PM
you are right susan, i was like why do i have to login at this hour... out of place... good catch
This thread has been locked.
1|2|3|4 of 11
Displaying 1 to 20 of 219 matches.