And back to the beginning.....(plus hacking fun!)
Trip Start Jan 19, 2006
332Trip End Jan 19, 2007
Map your own trip!
Show trip route
We were planning on seeing some friends on the way up, but Emma wasn't feeling great last week and had a stint of antibiotics to contend with, so we decided it would be best to chill a bit longer to aid recovery.
After a brief detour via Walthamstow for a few hours, we drove up to Tynemouth where we are staying with Lorna & Bill.
Anyway, the main battle we've been having over the last few days relates to Dave's email account which someone somehow managed to get the password for (probably in some internet cafe around the world). We first realised something was amiss about 1 week ago when PayPal sent an email to say that the account had been put on hold due to suspicious activity - upon checking it looked like somone had tried to spend about 700quid! Luckily PayPal had spotted suspicious activity and put the account on hold and contacted us.
During the week it was strange that after thinking I had reset the password, it was back to the old one - I assumed that it was a glitch with gmail or it was slow in updating, more on this later.
Anyway, it basically came to a head on Tuesday, when I noticed that someone had used our Skype to make a couple of phone calls to a Turkish mobile. Sensing that it was all related, I changed the skype password and gmail one again before we went around to meet Jo & Ricardo.
When we returned home, I was completely locked out of gmail and Skype. Obviously they still had access to my gmail account somehow and as a result were able to 'reset' skype password by using the 'forgot my password' procedure which sends you a temporary one via email.
We went into damage limitation mode, informed Skype and Gmail that someone unauthorised had accessed the accounts (there are no phone numbers) - still haven't heard anything! Changed the email associated with the PayPal account to be Emma's, put the PayPal account on hold and changed our internet banking logon details. However we were still unable to access gmail or Skype.
On Wednesday, whilst online on a friends computer, we noticed that the hacker had come online on Skype and we had the following interesting chat with them (remember, we are William Hill and the hacker is Dave & Emma Lees!).
[27/02/2007 23:02:08] William Hill says: hi there
[27/02/2007 23:02:13] William Hill says: you online?
[12:20:50] Dave & Emma Lees says: sorry i'm hacker no david
[12:21:03] Dave & Emma Lees says: :)
[12:22:19] William Hill says: this is actually David here. Please can you tell me why you hacked my account?
[12:22:42] Dave & Emma Lees says: yes hill i'm ka realy hacker david account hacked okey
[12:22:49] Dave & Emma Lees says: my english veryy bad.
[12:22:58] William Hill says: will you please give me back access to my email and my skype?
[12:23:07] William Hill says: I am David
[12:23:19] William Hill says: Just using my friends account as cannot get into mine obviously.
[12:23:29] Dave & Emma Lees says: hmm okey david send me 500 $ my bank account
[12:23:44] William Hill says: really?
[12:23:47] Dave & Emma Lees says: yes
[12:23:58] William Hill says: How can I trust you?
[12:24:27] Dave & Emma Lees says: my english speak verry bad
[12:24:46] Dave & Emma Lees says: my bank account send me western union transfer 500 $
[12:24:49] Dave & Emma Lees says: okey
[12:24:56] William Hill says: Why should I believe you will give me my account back if I pay $500
[12:25:03] William Hill says: How did you hack it?
[12:25:15] Dave & Emma Lees says: dostum turkish speak please
[12:25:21] Dave & Emma Lees says: translate
[12:25:30] Dave & Emma Lees says: i'm location turkey
[12:25:59] Dave & Emma Lees says: benim paraya ihtiyacim var senin hesabina hiç bir sey yapmadim butun hesaplarini geri vericem
[12:26:06] Dave & Emma Lees says: eksiksiz ve sorunsuz bir sekilde
[12:26:20] Dave & Emma Lees says: yalniz senden istedigim bana sadece 500 $ göndermen
[12:26:33] Dave & Emma Lees says: bunlarin cevirisini yaptir tercüman ayarla konusalim
[12:26:39] Dave & Emma Lees says: translating ok.
[12:27:21] William Hill says: how can I translate?
[12:27:38] Dave & Emma Lees says: turkish english translating
[12:27:39] Dave & Emma Lees says: okey
[12:28:56] William Hill says: we are trying to translate might take a few minutes
[12:29:01] Dave & Emma Lees says: okey
[12:29:18] Dave & Emma Lees says: david my ip address full anonyomuse okey
[12:30:23] William Hill says: can't find site to translate
[12:30:28] William Hill says: do you know any?
[12:30:34] Dave & Emma Lees says: hmm
[12:30:56] Dave & Emma Lees says: no site translate local tercuman translate turkish
[12:31:16] William Hill says: i dont know how
[12:31:56] Dave & Emma Lees says: sorry translate please.
[12:32:13] William Hill says: we don't know how to translate English to Turkish
[12:32:49] Dave & Emma Lees says: hmm okey send to ramazan colak westerm union transfer
[12:32:54] Dave & Emma Lees says: 500 $ okey
[12:33:09] William Hill says: what is Ramazan Colak? and where?
[12:33:10] Dave & Emma Lees says: you all gmail hotmail skype account back to send
[12:33:24] Dave & Emma Lees says: ramazan colak antalya turkey
[12:33:28] Dave & Emma Lees says: deniz bank
[12:33:36] Dave & Emma Lees says: okey
[12:33:41] William Hill says: what name?
[12:33:47] Dave & Emma Lees says: name : ramazan colak
[12:33:53] Dave & Emma Lees says: city : antalya
[12:33:59] Dave & Emma Lees says: country : turkey
[12:34:06] Dave & Emma Lees says: okey ?
[12:34:15] William Hill says: above you said your name was "ka"
[12:34:21] Dave & Emma Lees says: send money and wu number paste okey
[12:34:34] Dave & Emma Lees says: now fake name ka
[12:34:38] Dave & Emma Lees says: fake name ramazan
[12:34:46] Dave & Emma Lees says: my name is anyone
[12:34:52] William Hill says: i don't understand
[12:34:57] William Hill says: I do not have $500 - please just give me back my account
[12:35:02] Dave & Emma Lees says: yesss
[12:35:10] Dave & Emma Lees says: noww
[12:35:32] Dave & Emma Lees says: send wu transfer 500 $ back you all account okey
[12:35:42] William Hill says: If we pay how do we know you will give us back gmail, skype, etc
[12:36:08] Dave & Emma Lees says: ok ok send me wu transfer and wu tranfers number
[12:36:15] Dave & Emma Lees says: you all account back to
[12:36:16] Dave & Emma Lees says: okey
[12:36:30] Dave & Emma Lees says: i'm waitting
[12:36:34] William Hill says: No, we do not have $500 and do not trust you
[12:36:44] Dave & Emma Lees says: sorry no back to all account
[12:37:02] William Hill says: We will find you
[12:37:08] Dave & Emma Lees says: :)
[12:37:19] Dave & Emma Lees says: okey come here to turkey antalya my home
[12:37:47] William Hill says: please, I am asking nicely
[12:37:53] Dave & Emma Lees says: you travel boss
[12:37:53] William Hill says: I have done nothing to hurt you!
[12:37:57] William Hill says: why do this?
[12:38:12] Dave & Emma Lees says: noww send me 500 $ okey
[12:38:18] Dave & Emma Lees says: i'm sorry
Yes, most people are surprised we did not swear but we tried to have the moral high ground.
In the meantime, I informed the police of the identity theft and arranged for someone to take a statement.
At this stage, we had basically to wait for Google or Skype companies to come back to us with a way of recovering the accounts if possible as we didn't see what the police could realistically do.
Bizarrely, last night, we received a reply to the message Emma sent, appealing to the hackers sense of goodness to give us the accounts back, and he did! We received an email including the passwords and were able to recover the accounts and reset everything.
It was whilst resetting all of the security information in the accounts that we realised the way in which he was continually retaking control of the accounts, was that he had put his email address in as the secondary email address in Google. This basically lets you send a password reminder to another email address if you "forget" your password. So even when I was changing the passwords, he was able to reset them each time. (Make sure yours are set to your back up or partner, friend or whatever just in case!)
The police came round this morning to take a statement and all of the information I was able to gather. I was able to trace via an email address in one of the earlier PayPal purchases to a website and think that we have the name and phone number of the hacker, including the numbers of the phone calls he made to phones in Turkey listed in Skype - all of this has been passed to the police, so I guess we can wait to see what happens! Fingers crossed they will get the bxxxxxx
Anyway - its an exciting time being back!
Finally, to avoid this from happening to you, I would suggest doing the following :
- Use different passwords for Gmail, Skype, Paypal from other internet passwords
- Ensure that your secondary email address (the one which receives your password if you forget it) is set-up correctly. Its not in the most obvious place :
1 - Go to https://www.google.com/accounts/ManageAccount
2 - Click on Change Secret Question
3 - Change your secret question and also ensure the Secondary email is valid
- Back-up important emails/bookmarks/.. in case you ever lose access to your account
- Report and deal with ANY suspicious activity asap
- Hope it doesn't happen to you. It has been an incredibly stressful and sleep-free couple of days!