Possible data breach at Nicotine River

Son of a bitch I got it too.

6 Likes

No, but this was posted a few hours ago, NR is active on reddit I believe and they have been tagged

I will update if/when they respond.

7 Likes

I’m sure they’ll chime in.

4 Likes

Hey everyone, we’re aware of the situation. This is not confirmed and we are currently working closely with Shopify as all of our stores data goes 100% through their platform. In order for any data to be stolen from our site, it would have to be stolen from Shopify which is home to over a thousand e-commerce stores.

As of now, do not respond to the email. It is purely spam and is intended to scare you by threatening your privacy, it’s a commonly used method explained here: https://www.merchantfraudjournal.com/sextortion-email-scam/

Thank you, when I have further details I will convey them here.

18 Likes

@Nicotine_River as a customer, I appreciate your fast response here. Realizing RSC and Shopify are different entities, any info is always greatly appreciated.

9 Likes

@Nicotine_River, and all, I want to take this time to pass something on, that MAY offer an ALTERNATE possibility. I run typically 12 different email accounts (or more), and have received the above sexdortion emails before. I would like to HIGHLY recommend checking all of your EMAIL accounts to see if THEY have been compromised, and/or INVOLVED in a breach AS WELL.

https://haveibeenpwned.com/

This site is legit, and has been doing this for over 6 years now. I HIGHLY RECOMMEND you check ALL of your emails. Let’s be honest, breaches are happening now with increasing regularity. I had one email account (trasher account, not used for anything secure) contained in TEN different breaches, so it IS HAPPENING, and YOU should check.

Don’t think it’s legit, leery, not sure who they are ??

Also, if you want to be 1337 (Leet, Elite), you should sign up (for free), and with NO personal information needed, to MONITOR ALL of your email accounts, as Firefox/Mozilla have partnered with HaveIBeenPwnd.

I do a LOT of research, AND test myself before I recommend ANYTHING, just so you know. Knowledge is power, so DON’T be left out here.

10 Likes

I check regularly. Never had it happen.

4 Likes

You’re one of the LUCKY ones @Silhouette. I had a client who I was advising who kept noticing suspect activities, and kept ignoring them. Time went on, and he finally asked me to help, and we dug around, and found he (accounts/email/logins/passwords) had been involved in no less than 20 different breaches (he had multiple accounts, and it was unclear exactly what info was compromised PER breach). Knowledge is power.

4 Likes

I’m freakishly paranoid online. My names, are mostly fake, like Jim Bob MacGruber. Freakishly paranoid. Hugely. Just saying. Some places, it has to be right, but most often I lie.

4 Likes

F****
I’ve been pwnd!
2 breached sites!
to make it worse I even used my real name as my email
I have noticed lots of weird things happening too like my EA and ubisoft account being used all over the world and bliZZard password being reset

I don’t use them anymore really so I ignored them
My bank and email is safe though but I’m not taking any chances time for a new email
Thanks drummer!

The next world war is cyber

7 Likes

Hehe, nothing wrong with lying @Silhouette. I’m not saying this is what happened regarding the OP here, BUT, you guys deserve to know what IS going on out there, regardless of any possible Shopify issues not withstanding.

Here’s an example of a client who does small web design contract work. He was bumble-fucked when he saw his …

3 Likes

Well look guys, I didn’t mean to pour GAS on a FIRE, I just want you to be AWARE, that’s all. NOW, what does it mean IF you’ve been pwnd ?? Well, might NOT be a bad time to change some passwords, especially on the email accounts, if that password is shared or similar to others, maybe change them up to. Sure it’s a pain, but not as painful as other things. Just because you’ve been involved in a breach, doesn’t mean you’re guaranteed to get web raped, BUT, it COULD be a nice friendly little reminder, time to change some passwords, security questions, I mean, it never hurts.

Sorry for any possible derail of the OP.

5 Likes

@Silhouette you had me at …

4 Likes

For those who are skeptical regarding their payment information. Payment information submitted to a Shopify store is kept in a securely encrypted, entirely separate location and cannot be accessed. We do not keep any payment information on file and never will due to these reasons.

I will respond here when I discover further information regarding this matter. As of this moment, this is still under investigation.

Thank you

10 Likes

@Nicotine_River thanks bunches for responding! If I could fist bump through the screen, I would.

:grinning:

10 Likes

I got your back @Silhouette.

Imgur

5 Likes

Damn I know it wasn’t my fist bump to take but I did it anyhow - I should have been more careful :grinning:

hqdefault

9 Likes

Son of a bitch got one of the emails this morning, never opened it. I ordered from River supply about a week ago

4 Likes

@Jmars Check all of your emails …

3 Likes

I only have one email, and it’s not really not used for much. The email posted at 3:40am from a Sabrina Lang just to get some more info out.

5 Likes