Discussion Forum: Thread 354673

 Author: CE_Tanja View Messages Posted By CE_Tanja
 Posted: Mar 4, 2024 15:25
 Subject: Phishing email
 Viewed: 585 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

CE_Tanja

Location:  USA, California
Member Since Contact Type Status
Feb 17, 2021 Contact Member Admin
Buying Privileges - OKSelling Privileges - OK
BrickLink Administrator
Dear all,

We have been made aware that phishing emails have been sent to some of our members,
asking them to log in to "Bricklinks.net" (note the s in the name)

This is an attempt to get people to share their BrickLink login information.
Please do not try to log on as there is a risk that the information will be
used to illegally access your BrickLink account.


We would like to remind you that we have implemented OTP (One-Time PIN) which
is an additional security that even if they have gotten access to your username
and password, they will not be able to access your account if you have turned
on OTP
.

If you have not chosen to use OTP, we advise that you consider doing so in the
future. You can read more about how to turn on OTP here:
https://www.bricklink.com/help.asp?helpID=2615&q=OTP

Please update your BrickLink password regularly and make sure to use different
passwords for different platforms.

The BrickLink Team
 Author: BricksThatStick View Messages Posted By BricksThatStick
 Posted: Mar 4, 2024 15:29
 Subject: Re: Phishing email
 Viewed: 82 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

BricksThatStick (6355)

Location:  United Kingdom, England
Member Since Contact Type Status
Jan 10, 2005 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: Bricks That Stick
BrickLink Catalog Administrator (?)
In Administrative, CE_Tanja writes:
  Dear all,

We have been made aware that phishing emails have been sent to some of our members,
asking them to log in to "Bricklinks.net" (note the s in the name)

This is an attempt to get people to share their BrickLink login information.
Please do not try to log on as there is a risk that the information will be
used to illegally access your BrickLink account.


We would like to remind you that we have implemented OTP (One-Time PIN) which
is an additional security that even if they have gotten access to your username
and password, they will not be able to access your account if you have turned
on OTP
.

If you have not chosen to use OTP, we advise that you consider doing so in the
future. You can read more about how to turn on OTP here:
https://www.bricklink.com/help.asp?helpID=2615&q=OTP

Please update your BrickLink password regularly and make sure to use different
passwords for different platforms.

The BrickLink Team

Thanks for this Tanja...

Is this information also being sent as a genuine email to the whole userbase?
(the 99.9% of members who won't see this forum message)
 Author: CE_Tanja View Messages Posted By CE_Tanja
 Posted: Mar 4, 2024 17:04
 Subject: Re: Phishing email
 Viewed: 92 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

CE_Tanja

Location:  USA, California
Member Since Contact Type Status
Feb 17, 2021 Contact Member Admin
Buying Privileges - OKSelling Privileges - OK
BrickLink Administrator
Yes, there will be an email too.

In Administrative, BricksThatStick writes:
  In Administrative, CE_Tanja writes:
  Dear all,

We have been made aware that phishing emails have been sent to some of our members,
asking them to log in to "Bricklinks.net" (note the s in the name)

This is an attempt to get people to share their BrickLink login information.
Please do not try to log on as there is a risk that the information will be
used to illegally access your BrickLink account.


We would like to remind you that we have implemented OTP (One-Time PIN) which
is an additional security that even if they have gotten access to your username
and password, they will not be able to access your account if you have turned
on OTP
.

If you have not chosen to use OTP, we advise that you consider doing so in the
future. You can read more about how to turn on OTP here:
https://www.bricklink.com/help.asp?helpID=2615&q=OTP

Please update your BrickLink password regularly and make sure to use different
passwords for different platforms.

The BrickLink Team

Thanks for this Tanja...

Is this information also being sent as a genuine email to the whole userbase?
(the 99.9% of members who won't see this forum message)
 Author: ErwinNL View Messages Posted By ErwinNL
 Posted: Mar 4, 2024 15:29
 Subject: Re: Phishing email
 Viewed: 75 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

ErwinNL (621)

Location:  Netherlands, Overijssel
Member Since Contact Type Status
Oct 27, 2019 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: TheBug
I have seen it on Facebook and some Discord groups, be careful.
 Author: The_Boyz_Bricks View Messages Posted By The_Boyz_Bricks
 Posted: Mar 4, 2024 15:31
 Subject: Re: Phishing email
 Viewed: 56 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

The_Boyz_Bricks (108)

Location:  USA, Idaho
Member Since Contact Type Status
Nov 6, 2022 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: Red Bolt Bricks
In Administrative, CE_Tanja writes:
  Dear all,

We have been made aware that phishing emails have been sent to some of our members,
asking them to log in to "Bricklinks.net" (note the s in the name)

This is an attempt to get people to share their BrickLink login information.
Please do not try to log on as there is a risk that the information will be
used to illegally access your BrickLink account.


We would like to remind you that we have implemented OTP (One-Time PIN) which
is an additional security that even if they have gotten access to your username
and password, they will not be able to access your account if you have turned
on OTP
.

If you have not chosen to use OTP, we advise that you consider doing so in the
future. You can read more about how to turn on OTP here:
https://www.bricklink.com/help.asp?helpID=2615&q=OTP

Please update your BrickLink password regularly and make sure to use different
passwords for different platforms.

The BrickLink Team

Thanks for the heads up!
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Mar 4, 2024 15:36
 Subject: Re: Phishing email
 Viewed: 52 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Nubs_Select (3734)

Location:  Canada, Ontario
Member Since Contact Type Status
Mar 15, 2016 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: Nub's Select
suspicious indeed!
 
 Author: Bricklone View Messages Posted By Bricklone
 Posted: Mar 4, 2024 15:44
 Subject: Re: Phishing email
 Viewed: 60 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Bricklone (7)

Location:  France, Île-de-France
Member Since Contact Type Status
Jan 19, 2024 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: EarthBrick
In Administrative, CE_Tanja writes:
  Dear all,

We have been made aware that phishing emails have been sent to some of our members,
asking them to log in to "Bricklinks.net" (note the s in the name)

This is an attempt to get people to share their BrickLink login information.
Please do not try to log on as there is a risk that the information will be
used to illegally access your BrickLink account.


We would like to remind you that we have implemented OTP (One-Time PIN) which
is an additional security that even if they have gotten access to your username
and password, they will not be able to access your account if you have turned
on OTP
.

If you have not chosen to use OTP, we advise that you consider doing so in the
future. You can read more about how to turn on OTP here:
https://www.bricklink.com/help.asp?helpID=2615&q=OTP

Please update your BrickLink password regularly and make sure to use different
passwords for different platforms.

The BrickLink Team

Enabling OTP with a phone number could eventually be great!
 Author: The_Boyz_Bricks View Messages Posted By The_Boyz_Bricks
 Posted: Mar 4, 2024 15:55
 Subject: Re: Phishing email
 Viewed: 63 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

The_Boyz_Bricks (108)

Location:  USA, Idaho
Member Since Contact Type Status
Nov 6, 2022 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: Red Bolt Bricks
In Administrative, Bricklone writes:
  In Administrative, CE_Tanja writes:
  Dear all,

We have been made aware that phishing emails have been sent to some of our members,
asking them to log in to "Bricklinks.net" (note the s in the name)

This is an attempt to get people to share their BrickLink login information.
Please do not try to log on as there is a risk that the information will be
used to illegally access your BrickLink account.


We would like to remind you that we have implemented OTP (One-Time PIN) which
is an additional security that even if they have gotten access to your username
and password, they will not be able to access your account if you have turned
on OTP
.

If you have not chosen to use OTP, we advise that you consider doing so in the
future. You can read more about how to turn on OTP here:
https://www.bricklink.com/help.asp?helpID=2615&q=OTP

Please update your BrickLink password regularly and make sure to use different
passwords for different platforms.

The BrickLink Team

Enabling OTP with a phone number could eventually be great!

+1
 Author: Leonardo_S View Messages Posted By Leonardo_S
 Posted: Mar 4, 2024 15:46
 Subject: Re: Phishing email
 Viewed: 62 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Leonardo_S (19)

Location:  USA, Michigan
Member Since Contact Type Status
Jan 30, 2024 Contact Member Buyer
Buying Privileges - OK
Thank you for the info Tanja.

Leo
 Author: Saitobricks.ca View Messages Posted By Saitobricks.ca
 Posted: Mar 4, 2024 16:06
 Subject: Re: Phishing email
 Viewed: 74 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Saitobricks.ca (36)

Location:  Canada, Ontario
Member Since Contact Type Status
Aug 28, 2021 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store Closed Store: Unlicensed Bricks
Thanks for the heads up!

We wouldn't want another hacking.
 Author: sasquatch_eater View Messages Posted By sasquatch_eater
 Posted: Mar 4, 2024 17:11
 Subject: Re: Phishing email
 Viewed: 55 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

sasquatch_eater (78)

Location:  USA, Ohio
Member Since Contact Type Status
Oct 12, 2022 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: The Baboon's repository
In Administrative, Saitobricks.ca writes:
  Thanks for the heads up!

We wouldn't want another hacking.

That's suspicious! Suspend his store!

--Claude
 Author: Saitobricks.ca View Messages Posted By Saitobricks.ca
 Posted: Mar 4, 2024 17:30
 Subject: Re: Phishing email
 Viewed: 59 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Saitobricks.ca (36)

Location:  Canada, Ontario
Member Since Contact Type Status
Aug 28, 2021 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store Closed Store: Unlicensed Bricks
In Administrative, sasquatch_eater writes:
  In Administrative, Saitobricks.ca writes:
  Thanks for the heads up!

We wouldn't want another hacking.

That's suspicious! Suspend his store!

--Claude

Says some one who eats sasquatch's and runs a baboon repository
 Author: sasquatch_eater View Messages Posted By sasquatch_eater
 Posted: Mar 4, 2024 18:14
 Subject: Re: Phishing email
 Viewed: 60 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

sasquatch_eater (78)

Location:  USA, Ohio
Member Since Contact Type Status
Oct 12, 2022 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: The Baboon's repository
In Administrative, Saitobricks.ca writes:
  In Administrative, sasquatch_eater writes:
  In Administrative, Saitobricks.ca writes:
  Thanks for the heads up!

We wouldn't want another hacking.

That's suspicious! Suspend his store!

--Claude

Says some one who eats sasquatch's and runs a baboon repository

I bet you've never even tried sasquatch.

--Claude
 Author: Saitobricks.ca View Messages Posted By Saitobricks.ca
 Posted: Mar 4, 2024 18:49
 Subject: Re: Phishing email
 Viewed: 40 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Saitobricks.ca (36)

Location:  Canada, Ontario
Member Since Contact Type Status
Aug 28, 2021 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store Closed Store: Unlicensed Bricks
In Administrative, sasquatch_eater writes:
  In Administrative, Saitobricks.ca writes:
  In Administrative, sasquatch_eater writes:
  In Administrative, Saitobricks.ca writes:
  Thanks for the heads up!

We wouldn't want another hacking.

That's suspicious! Suspend his store!

--Claude

Says some one who eats sasquatch's and runs a baboon repository

I bet you've never even tried sasquatch.

--Claude

Where do you get yours?
 Author: sasquatch_eater View Messages Posted By sasquatch_eater
 Posted: Mar 4, 2024 21:43
 Subject: Re: Phishing email
 Viewed: 43 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

sasquatch_eater (78)

Location:  USA, Ohio
Member Since Contact Type Status
Oct 12, 2022 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: The Baboon's repository
In Administrative, Saitobricks.ca writes:
  In Administrative, sasquatch_eater writes:
  In Administrative, Saitobricks.ca writes:
  In Administrative, sasquatch_eater writes:
  In Administrative, Saitobricks.ca writes:
  Thanks for the heads up!

We wouldn't want another hacking.

That's suspicious! Suspend his store!

--Claude

Says some one who eats sasquatch's and runs a baboon repository

I bet you've never even tried sasquatch.

--Claude

Where do you get yours?

I grow 'em in my garden, where else would I get 'em?
 Author: BrickDeals View Messages Posted By BrickDeals
 Posted: Mar 4, 2024 22:17
 Subject: Re: Phishing email
 Viewed: 75 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

BrickDeals (2778)

Location:  USA, Virginia
Member Since Contact Type Status
Jan 13, 2004 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store Closed Store: Brick Deals©
In Administrative, CE_Tanja writes:
  Dear all,

We have been made aware that phishing emails have been sent to some of our members,
asking them to log in to "Bricklinks.net" (note the s in the name)

This is an attempt to get people to share their BrickLink login information.
Please do not try to log on as there is a risk that the information will be
used to illegally access your BrickLink account.


We would like to remind you that we have implemented OTP (One-Time PIN) which
is an additional security that even if they have gotten access to your username
and password, they will not be able to access your account if you have turned
on OTP
.

If you have not chosen to use OTP, we advise that you consider doing so in the
future. You can read more about how to turn on OTP here:
https://www.bricklink.com/help.asp?helpID=2615&q=OTP

Please update your BrickLink password regularly and make sure to use different
passwords for different platforms.

The BrickLink Team


Why doesn't a multi-billion dollar company buy up all domains similar to
Bricklink and then just redirect them all to Bricklink.com?
 Author: 1001bricks View Messages Posted By 1001bricks
 Posted: Mar 4, 2024 22:32
 Subject: Re: Phishing email
 Viewed: 65 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

1001bricks (52267)

Location:  France, Provence-Alpes-Côte d'Azur
Member Since Contact Type Status
Sep 6, 2005 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: 1001bricks
  Why doesn't a multi-billion dollar company buy up all domains similar to
Bricklink and then just redirect them all to Bricklink.com?

Because they would've to buy hundreds of domains, like bricklinks.net, bricklinka.com,
brick-link.net, bricklinkk.net, bricklinks.org...

Plus some may already be taken and put for sale at $100,000 ea - so no, it's
not easy.
 Author: rtzx9r View Messages Posted By rtzx9r
 Posted: Mar 4, 2024 23:05
 Subject: Re: Phishing email
 Viewed: 68 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

rtzx9r (1037)

Location:  USA, Arizona
Member Since Contact Type Status
Apr 1, 2002 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store Closed Store: Sunshine Builders Supply
In Administrative, 1001bricks writes:
  
  Why doesn't a multi-billion dollar company buy up all domains similar to
Bricklink and then just redirect them all to Bricklink.com?

Because they would've to buy hundreds of domains, like bricklinks.net, bricklinka.com,
brick-link.net, bricklinkk.net, bricklinks.org...

Plus some may already be taken and put for sale at $100,000 ea - so no, it's
not easy.

The official Bricklink strategy is to simply link all the similar websites. Just
need to be patient as they are already a bit behind on projects.
 Author: SylvainLS View Messages Posted By SylvainLS
 Posted: Mar 5, 2024 01:39
 Subject: Re: Phishing email
 Viewed: 77 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

SylvainLS (46)

Location:  France, Nouvelle-Aquitaine
Member Since Contact Type Status
Apr 25, 2014 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store Closed Store: BuyerOnly
BrickLink Discussions Moderator (?)
In Administrative, rtzx9r writes:
  In Administrative, 1001bricks writes:
  
  Why doesn't a multi-billion dollar company buy up all domains similar to
Bricklink and then just redirect them all to Bricklink.com?

Because they would've to buy hundreds of domains, like bricklinks.net, bricklinka.com,
brick-link.net, bricklinkk.net, bricklinks.org...

Plus some may already be taken and put for sale at $100,000 ea - so no, it's
not easy.

The official Bricklink strategy is to simply link all the similar websites.

You mean “merge” I think


   Just
need to be patient as they are already a bit behind on projects.
 Author: Macaronis View Messages Posted By Macaronis
 Posted: Mar 5, 2024 09:22
 Subject: Re: Phishing email
 Viewed: 64 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Macaronis (725)

Location:  USA, New York
Member Since Contact Type Status
Jun 13, 2002 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store Closed Store: Midnight Leftovers
In Administrative, SylvainLS writes:
  In Administrative, rtzx9r writes:
  In Administrative, 1001bricks writes:
  
  Why doesn't a multi-billion dollar company buy up all domains similar to
Bricklink and then just redirect them all to Bricklink.com?

Because they would've to buy hundreds of domains, like bricklinks.net, bricklinka.com,
brick-link.net, bricklinkk.net, bricklinks.org...

Plus some may already be taken and put for sale at $100,000 ea - so no, it's
not easy.

The official Bricklink strategy is to simply link all the similar websites.

You mean “merge” I think


   Just
need to be patient as they are already a bit behind on projects.


HAHAH Thanks for the laugh!
 Author: yorbrick View Messages Posted By yorbrick
 Posted: Mar 5, 2024 10:09
 Subject: Re: Phishing email
 Viewed: 60 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

yorbrick (1182)

Location:  United Kingdom, England
Member Since Contact Type Status
Apr 11, 2011 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: Yorbricks
In Administrative, 1001bricks writes:
  
  Why doesn't a multi-billion dollar company buy up all domains similar to
Bricklink and then just redirect them all to Bricklink.com?

Because they would've to buy hundreds of domains, like bricklinks.net, bricklinka.com,
brick-link.net, bricklinkk.net, bricklinks.org...

Plus some may already be taken and put for sale at $100,000 ea - so no, it's
not easy.

Dan Bricklin might also object. I dread to think how many times I have been to
his personal website due to an error.
 Author: Adjour View Messages Posted By Adjour
 Posted: Mar 5, 2024 15:59
 Subject: Re: Phishing email
 Viewed: 47 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Adjour (2452)

Location:  USA, Tennessee
Member Since Contact Type Status
Aug 1, 2016 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: The Chili is a Bit Spicy
In Administrative, 1001bricks writes:
  
  Why doesn't a multi-billion dollar company buy up all domains similar to
Bricklink and then just redirect them all to Bricklink.com?

Because they would've to buy hundreds of domains, like bricklinks.net, bricklinka.com,
brick-link.net, bricklinkk.net, bricklinks.org...

Plus some may already be taken and put for sale at $100,000 ea - so no, it's
not easy.


agreed.

Also I don't think it would really stop the phishing. I mean, I don't
think 100% of people glance at the url when they hit a link. I know I don't.
It could be www.yourvebeenhacked.com after you click the link and it would still
get a decent number of victims IMO because I doubt the average user checks these
things.

Crystal
 Author: peregrinator View Messages Posted By peregrinator
 Posted: Mar 11, 2024 19:43
 Subject: Re: Phishing email
 Viewed: 38 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

peregrinator (767)

Location:  USA, New Jersey
Member Since Contact Type Status
Jan 21, 2003 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: Faber Family Bricks
In Administrative, 1001bricks writes:
  
  Why doesn't a multi-billion dollar company buy up all domains similar to
Bricklink and then just redirect them all to Bricklink.com?

Because they would've to buy hundreds of domains, like bricklinks.net, bricklinka.com,
brick-link.net, bricklinkk.net, bricklinks.org...

bricquelinque.côm
 Author: 1001bricks View Messages Posted By 1001bricks
 Posted: Mar 11, 2024 20:19
 Subject: Re: Phishing email
 Viewed: 68 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

1001bricks (52267)

Location:  France, Provence-Alpes-Côte d'Azur
Member Since Contact Type Status
Sep 6, 2005 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: 1001bricks
In Administrative, peregrinator writes:
  In Administrative, 1001bricks writes:
  
  Why doesn't a multi-billion dollar company buy up all domains similar to
Bricklink and then just redirect them all to Bricklink.com?

Because they would've to buy hundreds of domains, like bricklinks.net, bricklinka.com,
brick-link.net, bricklinkk.net, bricklinks.org...

bricquelinque.côm

That sounds like a French hacker!
 Author: Peter711 View Messages Posted By Peter711
 Posted: Mar 5, 2024 00:23
 Subject: Re: Phishing email
 Viewed: 68 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Peter711 (16)

Location:  Canada, British Columbia
Member Since Contact Type Status
Jul 27, 2023 Contact Member Buyer
Buying Privileges - OK
In Administrative, CE_Tanja writes:
  Dear all,

We have been made aware that phishing emails have been sent to some of our members,
asking them to log in to "Bricklinks.net" (note the s in the name)

This is an attempt to get people to share their BrickLink login information.
Please do not try to log on as there is a risk that the information will be
used to illegally access your BrickLink account.


We would like to remind you that we have implemented OTP (One-Time PIN) which
is an additional security that even if they have gotten access to your username
and password, they will not be able to access your account if you have turned
on OTP
.

If you have not chosen to use OTP, we advise that you consider doing so in the
future. You can read more about how to turn on OTP here:
https://www.bricklink.com/help.asp?helpID=2615&q=OTP

Please update your BrickLink password regularly and make sure to use different
passwords for different platforms.

The BrickLink Team

Will this option (OTP) be available to sellers only?
 Author: theoryzero View Messages Posted By theoryzero
 Posted: Mar 5, 2024 08:36
 Subject: Re: Phishing email
 Viewed: 81 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

theoryzero (596)

Location:  USA, Iowa
Member Since Contact Type Status
Jan 22, 2002 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: Bionicle Bob's Part Shop
I got the phishing email yesterday and it was within 60 seconds of a brand new
user placing an order. I’m guessing they do this to get your email address to
send the phishing email to it.

Anyhow, my question is what do I do with what I assume is a bogus order? Invoice
it anyway?

In Administrative, CE_Tanja writes:
  Dear all,

We have been made aware that phishing emails have been sent to some of our members,
asking them to log in to "Bricklinks.net" (note the s in the name)

This is an attempt to get people to share their BrickLink login information.
Please do not try to log on as there is a risk that the information will be
used to illegally access your BrickLink account.


We would like to remind you that we have implemented OTP (One-Time PIN) which
is an additional security that even if they have gotten access to your username
and password, they will not be able to access your account if you have turned
on OTP
.

If you have not chosen to use OTP, we advise that you consider doing so in the
future. You can read more about how to turn on OTP here:
https://www.bricklink.com/help.asp?helpID=2615&q=OTP

Please update your BrickLink password regularly and make sure to use different
passwords for different platforms.

The BrickLink Team
 Author: yorbrick View Messages Posted By yorbrick
 Posted: Mar 5, 2024 10:06
 Subject: Re: Phishing email
 Viewed: 60 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

yorbrick (1182)

Location:  United Kingdom, England
Member Since Contact Type Status
Apr 11, 2011 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: Yorbricks
In Administrative, theoryzero writes:
  I got the phishing email yesterday and it was within 60 seconds of a brand new
user placing an order. I’m guessing they do this to get your email address to
send the phishing email to it.

Anyhow, my question is what do I do with what I assume is a bogus order? Invoice
it anyway?

Yeah, invoice it. If they pay, you were wrong and it was a real order (it could
be coincidence). If they don't pay, start the NPB.
 Author: Admin_Russell View Messages Posted By Admin_Russell
 Posted: Mar 5, 2024 12:05
 Subject: Re: Phishing email UPDATE March 5
 Viewed: 272 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Admin_Russell

Location:  USA, California
Member Since Contact Type Status
May 9, 2017 Contact Member Admin
Buying Privileges - OKSelling Privileges - OK
BrickLink Administrator
Hello again everyone,

Our security team was able to get the original bricklinks.net site taken
down, but we got reports this morning of a new bricklinks.org site and
evidence that phishing emails have been sent to our users, directing people to
this new site. The new site is much more realistic (see image below).

Please log in ONLY to bricklink.com and be aware that an effort is being
made to steal your BrickLink credentials. We will keep you updated if this problem
persists.

The BrickLink Team
 
 Author: 1001bricks View Messages Posted By 1001bricks
 Posted: Mar 5, 2024 13:08
 Subject: Re: Phishing email UPDATE March 5
 Viewed: 108 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

1001bricks (52267)

Location:  France, Provence-Alpes-Côte d'Azur
Member Since Contact Type Status
Sep 6, 2005 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: 1001bricks
In Administrative, Admin_Russell writes:
  Our security team was able to get the original bricklinks.net site taken
down, but we got reports this morning of a new bricklinks.org site

It opens directly to a pseudo login page...
Now people will be crazy again about Security

Maybe a good idea not to loose focus on Help Desk and BrickLink communication
(Notifications with confirmation and history on site!) for instance?
 Author: Adjour View Messages Posted By Adjour
 Posted: Mar 5, 2024 16:04
 Subject: Re: Phishing email UPDATE March 5
 Viewed: 75 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Adjour (2452)

Location:  USA, Tennessee
Member Since Contact Type Status
Aug 1, 2016 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: The Chili is a Bit Spicy
In Administrative, 1001bricks writes:
  In Administrative, Admin_Russell writes:
  Our security team was able to get the original bricklinks.net site taken
down, but we got reports this morning of a new bricklinks.org site

It opens directly to a pseudo login page...
Now people will be crazy again about Security

Maybe a good idea not to loose focus on Help Desk and BrickLink communication
(Notifications with confirmation and history on site!) for instance?


yeah its a typical scam site. Nothing works but the "login"


My browser wants to translate it from French (despite everything visible being
English) so I guess theres french somewhere on the backend of this garbage. I
guess scammers out of Canada or France. *shrug*
 Author: 1001bricks View Messages Posted By 1001bricks
 Posted: Mar 5, 2024 16:16
 Subject: Re: Phishing email UPDATE March 5
 Viewed: 69 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

1001bricks (52267)

Location:  France, Provence-Alpes-Côte d'Azur
Member Since Contact Type Status
Sep 6, 2005 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: 1001bricks
In Administrative, Adjour writes:
  In Administrative, 1001bricks writes:
  In Administrative, Admin_Russell writes:
  Our security team was able to get the original bricklinks.net site taken
down, but we got reports this morning of a new bricklinks.org site

It opens directly to a pseudo login page...
Now people will be crazy again about Security

Maybe a good idea not to loose focus on Help Desk and BrickLink communication
(Notifications with confirmation and history on site!) for instance?


yeah its a typical scam site. Nothing works but the "login"

My browser wants to translate it from French (despite everything visible being
English) so I guess theres french somewhere on the backend of this garbage. I
guess scammers out of Canada or France. *shrug*

Canada! We know who, it's Nubs!!!

He was practicing Javascript recently (in short: copy/paste from chatGPT)
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Mar 5, 2024 19:02
 Subject: Re: Phishing email UPDATE March 5
 Viewed: 44 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Nubs_Select (3734)

Location:  Canada, Ontario
Member Since Contact Type Status
Mar 15, 2016 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: Nub's Select
In Administrative, 1001bricks writes:
  In Administrative, Adjour writes:
  In Administrative, 1001bricks writes:
  In Administrative, Admin_Russell writes:
  Our security team was able to get the original bricklinks.net site taken
down, but we got reports this morning of a new bricklinks.org site

It opens directly to a pseudo login page...
Now people will be crazy again about Security

Maybe a good idea not to loose focus on Help Desk and BrickLink communication
(Notifications with confirmation and history on site!) for instance?


yeah its a typical scam site. Nothing works but the "login"

My browser wants to translate it from French (despite everything visible being
English) so I guess theres french somewhere on the backend of this garbage. I
guess scammers out of Canada or France. *shrug*

Canada! We know who, it's Nubs!!!

He was practicing Javascript recently (in short: copy/paste from chatGPT)

can it really be called practicing if its just
copy and paste?
 Author: Saitobricks.ca View Messages Posted By Saitobricks.ca
 Posted: Mar 5, 2024 19:04
 Subject: Re: Phishing email UPDATE March 5
 Viewed: 47 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Saitobricks.ca (36)

Location:  Canada, Ontario
Member Since Contact Type Status
Aug 28, 2021 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store Closed Store: Unlicensed Bricks
In Administrative, Nubs_Select writes:
  In Administrative, 1001bricks writes:
  In Administrative, Adjour writes:
  In Administrative, 1001bricks writes:
  In Administrative, Admin_Russell writes:
  Our security team was able to get the original bricklinks.net site taken
down, but we got reports this morning of a new bricklinks.org site

It opens directly to a pseudo login page...
Now people will be crazy again about Security

Maybe a good idea not to loose focus on Help Desk and BrickLink communication
(Notifications with confirmation and history on site!) for instance?


yeah its a typical scam site. Nothing works but the "login"

My browser wants to translate it from French (despite everything visible being
English) so I guess theres french somewhere on the backend of this garbage. I
guess scammers out of Canada or France. *shrug*

Canada! We know who, it's Nubs!!!

He was practicing Javascript recently (in short: copy/paste from chatGPT)

can it really be called practicing if its just
copy and paste?


I think the correct term is “testing”
 Author: Nubs_Select View Messages Posted By Nubs_Select
 Posted: Mar 5, 2024 19:12
 Subject: Re: Phishing email UPDATE March 5
 Viewed: 48 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Nubs_Select (3734)

Location:  Canada, Ontario
Member Since Contact Type Status
Mar 15, 2016 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: Nub's Select
In Administrative, Saitobricks.ca writes:
  In Administrative, Nubs_Select writes:
  In Administrative, 1001bricks writes:
  In Administrative, Adjour writes:
  In Administrative, 1001bricks writes:
  In Administrative, Admin_Russell writes:
  Our security team was able to get the original bricklinks.net site taken
down, but we got reports this morning of a new bricklinks.org site

It opens directly to a pseudo login page...
Now people will be crazy again about Security

Maybe a good idea not to loose focus on Help Desk and BrickLink communication
(Notifications with confirmation and history on site!) for instance?


yeah its a typical scam site. Nothing works but the "login"

My browser wants to translate it from French (despite everything visible being
English) so I guess theres french somewhere on the backend of this garbage. I
guess scammers out of Canada or France. *shrug*

Canada! We know who, it's Nubs!!!

He was practicing Javascript recently (in short: copy/paste from chatGPT)

can it really be called practicing if its just
copy and paste?


I think the correct term is “testing”

"testing" for several hours to increase the efficiency of
1 function by 1/1000 of a second
 Author: Saitobricks.ca View Messages Posted By Saitobricks.ca
 Posted: Mar 5, 2024 19:16
 Subject: Re: Phishing email UPDATE March 5
 Viewed: 62 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

Saitobricks.ca (36)

Location:  Canada, Ontario
Member Since Contact Type Status
Aug 28, 2021 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store Closed Store: Unlicensed Bricks
In Administrative, Nubs_Select writes:
  In Administrative, Saitobricks.ca writes:
  In Administrative, Nubs_Select writes:
  In Administrative, 1001bricks writes:
  In Administrative, Adjour writes:
  In Administrative, 1001bricks writes:
  In Administrative, Admin_Russell writes:
  Our security team was able to get the original bricklinks.net site taken
down, but we got reports this morning of a new bricklinks.org site

It opens directly to a pseudo login page...
Now people will be crazy again about Security

Maybe a good idea not to loose focus on Help Desk and BrickLink communication
(Notifications with confirmation and history on site!) for instance?


yeah its a typical scam site. Nothing works but the "login"

My browser wants to translate it from French (despite everything visible being
English) so I guess theres french somewhere on the backend of this garbage. I
guess scammers out of Canada or France. *shrug*

Canada! We know who, it's Nubs!!!

He was practicing Javascript recently (in short: copy/paste from chatGPT)

can it really be called practicing if its just
copy and paste?


I think the correct term is “testing”

"testing" for several hours to increase the efficiency of
1 function by 1/1000 of a second

“it’s just barely better! But it is still better! Barely!”
 Author: SanPlomB View Messages Posted By SanPlomB
 Posted: Mar 11, 2024 17:55
 Subject: Re: Phishing email UPDATE March 5
 Viewed: 61 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

SanPlomB (202)

Location:  France, Auvergne-Rhône-Alpes
Member Since Contact Type Status
Nov 25, 2016 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: SPBricks
Hello,

Today I received 4 phishing emails from site brickslink.org. This new site looks
like exactly that your screenshot of bricklinks.org.


In Administrative, Admin_Russell writes:
  Hello again everyone,

Our security team was able to get the original bricklinks.net site taken
down, but we got reports this morning of a new bricklinks.org site and
evidence that phishing emails have been sent to our users, directing people to
this new site. The new site is much more realistic (see image below).

Please log in ONLY to bricklink.com and be aware that an effort is being
made to steal your BrickLink credentials. We will keep you updated if this problem
persists.

The BrickLink Team
 Author: dartiss View Messages Posted By dartiss
 Posted: Mar 6, 2024 02:25
 Subject: Re: Phishing email
 Viewed: 79 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

dartiss (0)

Location:  United Kingdom, England
Member Since Contact Type Status
Jun 12, 2022 Contact Member Buyer
Buying Privileges - OK
You really need to add OTP for all users, not just sellers, for better security.
You sent me the email to tell me about this, despite me not having a seller account,
and finding I'm unable to do it.

Also, to the person asking for SMS 2FA - this is insecure (as is email, tbh).
Bricklink should really implement 2FA via authentication app for proper security.
 Author: 1001bricks View Messages Posted By 1001bricks
 Posted: Mar 6, 2024 12:10
 Subject: Re: Phishing email
 Viewed: 65 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

1001bricks (52267)

Location:  France, Provence-Alpes-Côte d'Azur
Member Since Contact Type Status
Sep 6, 2005 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: 1001bricks
In Administrative, dartiss writes:
  You really need to add OTP for all users, not just sellers, for better security.
You sent me the email to tell me about this, despite me not having a seller account,
and finding I'm unable to do it.

Also, to the person asking for SMS 2FA - this is insecure (as is email, tbh).
Bricklink should really implement 2FA via authentication app for proper security.

Please NO - apart if it's optional.
 Author: chriselliottart View Messages Posted By chriselliottart
 Posted: Mar 20, 2024 23:25
 Subject: Re: Phishing email
 Viewed: 65 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

chriselliottart (562)

Location:  USA, Pennsylvania
Member Since Contact Type Status
Dec 30, 2012 Contact Member Buyer
Buying Privileges - OK
In Administrative, CE_Tanja writes:
  Dear all,

We have been made aware that phishing emails have been sent to some of our members,
asking them to log in to "Bricklinks.net" (note the s in the name)

This is an attempt to get people to share their BrickLink login information.
Please do not try to log on as there is a risk that the information will be
used to illegally access your BrickLink account.


We would like to remind you that we have implemented OTP (One-Time PIN) which
is an additional security that even if they have gotten access to your username
and password, they will not be able to access your account if you have turned
on OTP
.

If you have not chosen to use OTP, we advise that you consider doing so in the
future. You can read more about how to turn on OTP here:
https://www.bricklink.com/help.asp?helpID=2615&q=OTP

Please update your BrickLink password regularly and make sure to use different
passwords for different platforms.

The BrickLink Team

I also got one of these today from policyking dot net. Besides that, the links
go to a wix site. But the email at a glance without hovering the links or checking
the sender looks pretty legit. Bricklink logo and all.
 Author: yorbrick View Messages Posted By yorbrick
 Posted: Mar 21, 2024 06:11
 Subject: Re: Phishing email
 Viewed: 91 times
 Topic: Administrative
Cancel Message
Cancel
Reply to Message
Reply
BrickLink
ID Card

yorbrick (1182)

Location:  United Kingdom, England
Member Since Contact Type Status
Apr 11, 2011 Contact Member Seller
Buying Privileges - OKSelling Privileges - OK
Store: Yorbricks
The OTP codes are going to be useless to combat scammers.

The current phishing scam is asking people to sign in with their user name and
password. Once those are entered, on the next page they are asking for the OTP
code that bricklink has sent.

No doubt they are automating logins so the user enters their username and password
on the fake site and then the scammers attempt a login at the real bricklink,
generating the real OTP email and the user then enters this on the fake site.
The scammer then has the username, password and real (and unused) OTP code which
they can use on the real bricklink.