pmcnamara
News Editor

Black Hat blames phishy email on volunteer’s error

Opinion
Jul 23, 20123 mins

Security conference attendees smelled something wrong right away

Black hat hacker that working from deep dark web from cyberpunk world.
Credit: isarisphotography / Shutterstock

A phishy looking email sent over the weekend to attendees of this week’s Black Hat security conference turns out to have been an innocent mistake by a volunteer, according to the event organizer.

The email read in part:

This is a note from BlackHat 2012.

You have requested a new password. Here are your details:

Username:

Password:

To sign in, please go to this URL:

https://svel1023/BH12/Admin

Had it been an actual phishing attempt, it wasn’t likely to fool even the moderately savvy recipient, never mind the Black Hat crowd, but it did generate a buzz, as typified by this tweet:

tweet

Yesterday Black Hat explained the errant email, with general manager Trey Ford writing in a blog post:

Our most valued assets at Black Hat are our delegates and their privacy. We work very hard to maintain that. We want everyone to come to Black Hat to learn and enjoy their time without fear of having their personal or professional information compromised. We are happy to report there are no signs of compromise.

The email this morning was an abuse of functionality by a volunteer who has been spoken to. This feature has since been removed as a precautionary measure.

This reminds me of the time a public relations company representing an anti-spam vendor violated the first rule doing PR for an anti-spam vendor: don’t spam.

Welcome regulars and passersby. Here are a few more recent buzzblog items.