Spammers expose over a billion email addresses after failed backup | TechCrunch (2024)

Table of Contents
Slow Loris Flatline FAQs

At its height, River City Media, run by Alvin Slocombe and Matt Ferris, sent out a billion emails a day, slamming Gmail servers with fragmented traffic in order to ensure all of its email went out on time. After failing to password-protect a remote backup, however, the company has exposed its nearly 1.4 billion email records, some of which contain real names and addresses. The company, for all intents and purposes, is sunk but the privacy implications of this trove of data are staggering.

Discovered by a security researcher for MacKeeper, Chris Vickery, the leaked data appeared as a result of a failed rsync backup – essentially a remote backup gone wrong. The data sat on an exposed server for months, allowing Vickery – and anyone else – access to chat logs, emails, and, most important, the company’s massive email list.

Vickery feels, well, victorious.

“I found an rsync server on port 873 that they had not put any password or security of any sort on and it has led to he downfall of a criminal enterprise,” he said. “I’m hoping that they’ll be out of business soon but that would largely depend on actions by law enforcement. If you’re sitting behind bars it’s hard to spam.”

He also found the list to be quite unruly.

“I’m still struggling with the best software solution to handle such a voluminous collection, but I have looked up several people that I know and the entries are accurate,” Vickery told CSO Online. “The only saving grace is that some are outdated by a few years and the subject no longer lives at the same location.”

Slow Loris

The multiple RCM spam techniques were extraordinary. The company would first send out tens of thousands of “warm-up emails” to their own email addresses on Gmail and other servers. Because these emails would never bounce or send complaints – they were owned by RCM after all – the security systems wouldn’t notice the rest of the emails exploding out of the servers.

Further, the spammers would send fragmented data slowly – technically a “slowloris” attack – while requesting multiple connections under the guise of error correction. Then, when all the servers were accepting data, they would “stuff as much packet data” into the servers as they could before disconnection.

Spammers expose over a billion email addresses after failed backup | TechCrunch (1)

Vickery has spent the last few days going through the massive data dump and has found the weapons spammers use to attack mail servers.

“There are scripts in here for all sorts of nefarious things that may or may not be patched already. I will go into more detail after I talk to Gmail, Microsoft, and Yahoo,” he said. He estimates that the company had only twenty actual hardware servers and instead used “backroom dealings” with friends and affiliates to send out the bulk of their spam, partners who are now refusing to work with RCM. Ad partner Amobee, for example, has disowned the company.

“They have tons of developed software for hiding their own mail servers, making themselves look like other people, and spoofing email address,” said Vickery. They called these “Projects” and there were hundreds of them.

Flatline

RCM has always been on The Register of Known Spam Operations (ROKSO) and has used over 2,199 IP addresses to send out email making it wildly difficult to block. It has done campaigns for Nike, Gillette, Victoria’s Secret, Covergirl, and AT&T, among others although these big names didn’t use RCM directly but were shunted onto the spammers by other, presumably legitimate, marketing firms.

Vickery believes this leak and the associated data will put RCM out of business indefinitely.

“As far as the RCM email spam empire goes it’s going to be very hard for them to operate in the near future,” he said. But this won’t stop all spam forever. This, in the end, is a major victory in an ongoing war.

“I’m sure somebody else will step into the void they left,” Vickery said.

Update: Several weeksafter our initial report on thisstory, River City Media delivered the following statement to TechCrunch via legal representation:

River City Media disputes and disagrees with any accusation or suggestion that the company engaged in unlawful or illegal activity. The statements made by third parties that suggested otherwise are false. It is lawful to send email advertisem*nts on behalf of digital brands and agencies in the United States, andRiver City Media has always complied with all laws and regulations governing email marketing, including the CAN-SPAM Act of 2003. To be clear, River City Media did not hijack IPs, leave its backup server exposed, send 1 billion email messages in a day, nor use any delivery scripts provided by third parties to deliver email. River City Media has always had a stellar reputation within the affiliate marketing industry and was able to obtain this by upholding the highest business standards. River City Media’s business has suffered catastrophic damages from an unwarranted and malicious security breach, which has negatively impacted the company’s employees, vendors, business associates and families. We appreciate the overwhelming amount of support we have received from the email and affiliate marketing communities.

Spammers expose over a billion email addresses after failed backup | TechCrunch (2024)

FAQs

Spammers expose over a billion email addresses after failed backup | TechCrunch? ›

After failing to password-protect a remote backup, however, the company has exposed its nearly 1.4 billion email records, some of which contain real names and addresses. The company, for all intents and purposes, is sunk but the privacy implications of this trove of data are staggering.

How many email addresses before considered spam? ›

If you haven't been sending emails but suddenly start sending 500 emails daily, email providers will consider them spam. Send a consistent volume of emails daily to reach your audience's inbox.

How do spammers collect email addresses? ›

Email harvesters

Similar to search engines, spammers deploy advanced bots that methodically scan the web. However, unlike search engines, these bots, known as email harvesters, are programmed to locate harvested email addresses instead of indexing websites.

Are 85% of all emails spam? ›

How Prevalent Are Spam Emails? According to research from Symantec, nearly 85% of all emails are spam or malicious. This means that almost nine out of 10 emails were not considered legitimate messages intended for specific recipients.

Is there a limit on the number of email recipients? ›

"You have reached a limit for sending mail"

You may see this message if you send an email to a total of more than 500 recipients in a single email and or more than 500 emails sent in a day.

Does blocking spam email addresses work? ›

Blocking unwanted emails stops spam from reaching that email address permanently, but be careful how you go about doing it, because opening some spam emails can prompt a deluge of more junk emails from other spam accounts.

How do I remove my email address from spammers? ›

Unsubscribe

This is the primary step you must take in order to stop receiving spam emails from a sender. This action will ultimately remove your email address from the sender's mailing list. The unsubscribe link is usually placed at the end of the email.

What happens if a scammer has your email address? ›

Criminals who have your email address could potentially use it to impersonate you in an effort to carry out scams or phishing attacks against your friends, family, or coworkers. Especially if the email address they got is your work address.

What qualifies an email as spam? ›

Spam email is unsolicited and unwanted junk email sent out in bulk to an indiscriminate recipient list. Typically, spam is sent for commercial purposes.

How do I know if my email is considered spam? ›

Do a spam test
  1. Head to www.mail-tester.com and copy the email address in the white box.
  2. Go back to your mailing draft and send a test mailing to this email address.
  3. Navigate back to Mail Tester and click “Then check your score”
  4. The number you get is your score.

What determines if an email goes to spam? ›

Top webmail providers have stated that they look at how many emails are opened and how many are deleted as a factor in spam filtering decisions. So if you have low open or read rates, your emails are at higher risk of being flagged as spam. You need to do everything you can to increase engagement.

How many people can I bcc before it goes to spam? ›

Be aware of the BCC limit: Gmail limits the number of receivers added to the BCC area, which is 500 recipients per 24 hours. Be mindful of the limit and consider using other methods, such as a mailing list or a mail merge.

Top Articles
Bitcoin Price Blasts Past $41,500: Here Are The Reasons
Vielfältige Anlagelösungen mit iShares ETFs | iShares DE - BlackRock
Spasa Parish
Rentals for rent in Maastricht
159R Bus Schedule Pdf
Sallisaw Bin Store
Black Adam Showtimes Near Maya Cinemas Delano
Espn Transfer Portal Basketball
Pollen Levels Richmond
11 Best Sites Like The Chive For Funny Pictures and Memes
Things to do in Wichita Falls on weekends 12-15 September
Craigslist Pets Huntsville Alabama
Paulette Goddard | American Actress, Modern Times, Charlie Chaplin
Red Dead Redemption 2 Legendary Fish Locations Guide (“A Fisher of Fish”)
‘An affront to the memories of British sailors’: the lies that sank Hollywood’s sub thriller U-571
Tyreek Hill admits some regrets but calls for officer who restrained him to be fired | CNN
Haverhill, MA Obituaries | Driscoll Funeral Home and Cremation Service
Rogers Breece Obituaries
Ems Isd Skyward Family Access
Elektrische Arbeit W (Kilowattstunden kWh Strompreis Berechnen Berechnung)
Omni Id Portal Waconia
Kellifans.com
Banned in NYC: Airbnb One Year Later
Four-Legged Friday: Meet Tuscaloosa's Adoptable All-Stars Cub & Pickle
Model Center Jasmin
Ice Dodo Unblocked 76
Is Slatt Offensive
Labcorp Locations Near Me
Storm Prediction Center Convective Outlook
Experience the Convenience of Po Box 790010 St Louis Mo
Fungal Symbiote Terraria
modelo julia - PLAYBOARD
Poker News Views Gossip
Abby's Caribbean Cafe
Joanna Gaines Reveals Who Bought the 'Fixer Upper' Lake House and Her Favorite Features of the Milestone Project
Tri-State Dog Racing Results
Navy Qrs Supervisor Answers
Trade Chart Dave Richard
Lincoln Financial Field Section 110
Free Stuff Craigslist Roanoke Va
Wi Dept Of Regulation & Licensing
Pick N Pull Near Me [Locator Map + Guide + FAQ]
Crystal Westbrooks Nipple
Ice Hockey Dboard
Über 60 Prozent Rabatt auf E-Bikes: Aldi reduziert sämtliche Pedelecs stark im Preis - nur noch für kurze Zeit
Wie blocke ich einen Bot aus Boardman/USA - sellerforum.de
Infinity Pool Showtimes Near Maya Cinemas Bakersfield
Dermpathdiagnostics Com Pay Invoice
How To Use Price Chopper Points At Quiktrip
Maria Butina Bikini
Busted Newspaper Zapata Tx
Latest Posts
Article information

Author: Tuan Roob DDS

Last Updated:

Views: 5753

Rating: 4.1 / 5 (42 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Tuan Roob DDS

Birthday: 1999-11-20

Address: Suite 592 642 Pfannerstill Island, South Keila, LA 74970-3076

Phone: +9617721773649

Job: Marketing Producer

Hobby: Skydiving, Flag Football, Knitting, Running, Lego building, Hunting, Juggling

Introduction: My name is Tuan Roob DDS, I am a friendly, good, energetic, faithful, fantastic, gentle, enchanting person who loves writing and wants to share my knowledge and understanding with you.