Status
Not open for further replies.
Hi guys,

An important mail has been sent out to DSL customers from us and will require your action. Please take note of it and do not ignore it or your account may stop working on your next re-connection attempt. If you haven't yet received the mail, yours is on its way. Hold tight.

More information to follow from official sources using official communication platforms.

Regards

Crystal Web

DJ...

This CrystalWeb e-mail that has gone out about the compromised accounts, is this legit? I have difficulty believing they are so as they seem rather... unprofessional? The new passwords I was given scream of a scam or some sort of phish; they are fairly odd and have several invectives and obscenities in them :P Sure nothing CrystalWeb side has been compromised?

Just wanted to make sure.

Many thanks!

New password is randomly generated and can be changed if need be...
 
Alright, thanks DJ... I must have got your auto-gen computer when it was feeling really grumpy about something... :P
 
Last edited:
Alright, thanks DJ... I must have got your auto-gen computer when it was feeling really grumpy about something...

We'd have loved to have had a bit more time to do this in, but alas. My apologies for the auto-bot's grumpiness. As we'll discover in the coming decades, even machines can have feelings...:D
 
Always knew Crystal Web would be responsible for the Singularity! :P

Thanks for taking the steps, so quickly then, to counter the breach in your provider. Hope the attack wasn't too severe.
 
Thanks for being proactive.
Pretty sure that other ISPs hush things up when they happen...
 
Is the suspicious activity mentioned in the email from an upstream provider?

If so, how come other ISP's are quiet?
 
It seems you read something entirely different than what I wrote.

They sent out my (forced new) password in plain text. They did this at the same time as their portal being down, so now I can't go and change it to something that hasn't been sent in plain text. It's the latter part I'm complaining about. If blowing up your portal is being "being proactive about something" in your world, then boy, you live in a funny world.
 
Is the suspicious activity mentioned in the email from an upstream provider?

If so, how come other ISP's are quiet?

The compromised provider has not yet been identified, investigations are underway.
 
It seems you read something entirely different than what I wrote.

They sent out my (forced new) password in plain text. They did this at the same time as their portal being down, so now I can't go and change it to something that hasn't been sent in plain text. It's the latter part I'm complaining about. If blowing up your portal is being "being proactive about something" in your world, then boy, you live in a funny world.

Or you can just go chat to support and have it changed there. That's what I plan to do later this morning. Obviously if all systems were up, sending out the passwords in plaintext wouldn't have been necessary.
 
Crystal Web Service Provider - Security Breach

Crystal Web email reads:

"In our continued efforts to remain pro-active in areas relating to your security, we have amended your password accordingly.

If you make use of our portal, your password for that has been changed to:

This action was taken as a precautionary measure after suspicious activity was detected at a service provider utilised by Crystal Web. Considering that Crystal Web is not the only client of this service provider, we suggest that you take this opportunity to amend your passwords as a whole, as a part of an effort to mitigate risk on your part. This incident is currently being investigated comprehensively and we do not wish to speculate on the matter at this time. We condemn malicious actions taken by any and all groups and individuals.

Such activities have become more commonplace in recent years, and while no Crystal Web systems have been compromised or hacked, sufficient evidence exists that a service provider we rely on may have been compromised, and we therefore suggest that you too proactively amend your related passwords for other cloud services where you may utilise a similar or same password.

We feel it is imperative to inform you of this and take the appropriate steps to avoid it becoming an issue for your account. We do not believe in remaining quiet and leaving you at risk in this regard, even where fault lies with other providers. We do also firmly believe in the benefits of white-hacking, and have employed such services in the past with respect to some forms of security. However, in this case the service provider in question was not contacted in any manner, nor did they employ such services, which indicates purely malicious activity and one we take a very dim view of. And while we are not the service provider in question, we can confirm that at no point was Crystal Web contacted by the parties responsible, which further indicates that these actions were not conducted with good intentions.

We can assure you that no financial information, such as debit order details or credit card details are at risk at all, and there is no need to be concerned that any such information could be compromised by the provider in any manner, as this data is not stored nor relayed via these providers in any manner.

Please afford us your patience if you contact a support channel over the next 24 hours on account of any increase in activity that this may result in, however all additional information will be communicated by us in an official capacity from an executive level. If you have trouble amending your new password or getting connected as a result, please do let us know on live chat or email so that we can assist further.

Kind regards
Crystal Web Management "
 
I actually haven't received any email from CW with regards to this password changes? If I didn't check the forums i probably wouldn't have known about it. I take it everyone's password have been changed?
 
I got a "Crystal Web Security Update" email with a new username and password.

Thanks.

But ... I'm not a CW customer?!
 
I actually haven't received any email from CW with regards to this password changes? If I didn't check the forums i probably wouldn't have known about it. I take it everyone's password have been changed?

As far as I understand it, not all account details were compromised.
 
You think I should use this account? It's not mine ... ;)

Hey when in Rome do as the Roman's do, afterall, we have a very large population that freely takes what does not belong to them ... Will be interesting to see how long they take to catch up with you ....

Seriously, I would send a PM to DJ with the details, it would be an interesting case study for CW to do ....

Cancel this it seems you have forgotten what you have??
 
Last edited:
Sorry being a bit blond here does this mean I should change my password details on my router? Also please advise how I can change my e-mail address
Thanks
 
Status
Not open for further replies.
Top
Sign up to the MyBroadband newsletter
X