COPEAC Hacked

papajohn56

New member
Jun 16, 2008
7,254
211
0
SC
Looks like the entire publisher list was stolen, this big scary email with a fake link to copeactracking.co.tv in it:

It has been a pleasure to have you on board marketing with us. It has become evident to us that you have reached a level now that you have shown you can be very very beneficial for our network and advertisers! We are proud to now “graduate” you and gave you a chance to be the first to use our enhanced tracking system which can increase your commissions dramatically and gave you an in-depth (like never before) reports about your traffic to help you make better decisions and monitor real-time stats on the fly.

You can signup here - *redacted*...


We appreciate your business and hope to continue the success.


We know you could use any network and we appreciate that you chose to use COPEAC.

Jessica Johnson
Network Manager
__ ______ __________
IMM Interactive
135 Crossways Park Drive
Woodbury, New York 11797
2010 Inc. 500 Honoree
Work: 631.719.1250 x9950
Fax: 516.837.8154
IM: jessksatimk
Connect: FB Twitter LinkedIn

Followed a while after by:

If you recently received an email with the subject line, “Invitation to use latest Copeac's Advanced Tracking System.” Asking you to login to your COPEAC account, please disregard. Do not follow the link in that correspondence and access your account. If you already have, please change your password immediately.


We sincerely apologize for the inconvenience. If you have any questions please contact your Account Manager.


Thank you.
 


You guys kidding? Clickbooth and Copeac's accounts and pws compromised? Are ssns, and taxids compromised? And the clickbooth didn't go public? Wtf?
 
The passwords are probably hashed so they're safe(unless you used an easy to crack password) but contact info, financial details, bank info...I bet that's all stored plaintext and accessible to hackers.
 
mkrongel,

Where you at on this? Is this how our e-mails were leaked?

P.S...Not doing business with Copeac anymore.
 
I didn't get that email. But I got the one from Copeac saying to change your password.

I searched for "Invitation to use latest Copeac" and found an email from August 2010 where it looks like the same exact thing happened, only a virus was attached to the email I guess.

I'm guessing someone is using an exploit to mail affiliates in their database.
 
I got the email from COPEAC that warns of the email but I did not receive a phishing email so it seems the hackers didnt get all of the publisher data.
 
A heads up

It might not even be clickbooth or copeac.

The phishers, could just be using their names as a lot of affiliates have joined them. The emails could have come from anywhere (Here for instance)

Unless you used a specific email and never used it elsewhere.
 
The headers in the email go to this Host Gator account: News6Health.com - Diet Trends: A look at America's Top Diets
.

Jumps incase he takes the page down for affiliate id pwnage

+ 0.000 0.157 641 411 POST 302 Redirect to http://partners.cpaprosperity.com/z/3462/CD735/ Geo Redirect | CPAClickz
+ 0.158 0.225 519 420 GET 301 Redirect to http://partners.cpaprosperity.com/z/3693/CD735/ http://partners.cpaprosperity.com/z/3462/CD735/
+ 0.383 0.067 519 420 GET 301 Redirect to http://partners.cpaprosperity.com/z/3839/CD735/ http://partners.cpaprosperity.com/z/3693/CD735/
+ 0.451 4 0.094 519 1233 GET 200 html http://partners.cpaprosperity.com/z/3839/CD735/
+ 0.579 1 0.205 545 368 GET 200 html https://partners.cpaprosperity.com/ch
5 0.784 2743 2852 5 requests
00:00:02.320 Acai
+ 0.000 1 0.303 492 773 GET 302 Redirect to Acai Acai
+ 0.304 3 0.208 432 805 GET 302 Redirect to Acai Acai