1 min readfrom Photography

Beware photoloving.com!

Our take

Beware of photoloving.com! In my quest for a Sigma TS-21 collar mount, I stumbled upon an ishoot IS-SM720 listed as in stock. After creating an account and attempting to purchase, I encountered a frustrating 'not available' pop-up. Unfortunately, my naivety led to a barrage of 'new account created' emails, resulting in a credential stuffing attack on one of my accounts. Gemini identifies this as a classic cyberattack, revealing photoloving.com as a data-harvesting honeypot. Stay vigilant!

In the digital age, where convenience often trumps caution, the recent cautionary tale surrounding photoloving.com serves as a stark reminder of the importance of cybersecurity. An unfortunate experience shared by a user illustrates the perils of online shopping, especially when dealing with unfamiliar sites. Initially drawn in by the promise of a Sigma TS-21 collar mount, the user instead found themselves ensnared in a web of cyber deceit. This incident underscores the necessity for vigilance in our online interactions, particularly within the realms of photography and creative industries where many of us seek to enhance our craft.

The user’s ordeal began innocently enough, characterized by what seemed to be a typical online shopping experience. After creating an account to purchase an ishoot IS-SM720, they were met with a frustrating “not available” pop-up. However, the real danger lay in what followed—a relentless barrage of emails indicating unauthorized activity linked to their account. This phenomenon, known as "email bombing," is not merely an annoyance; it represents a serious breach of privacy and security. As noted by the user, this incident is indicative of a “credential stuffing” attack, a tactic that exploits previously compromised usernames and passwords to hijack accounts. Such tactics are alarmingly common, and they highlight the urgent need for enhanced cybersecurity awareness among consumers.

For those passionate about photography and the arts, the implications of this incident extend beyond mere inconvenience. Engaging with unfamiliar websites can lead to the loss of personal information, financial resources, and trust in online marketplaces. As creatives often rely on platforms to share their work and purchase necessary equipment, the potential for data harvesting poses a significant threat to their livelihoods. This situation echoes sentiments found in other discussions within our community, such as the importance of niche marketplaces, highlighted in articles like Fujifilm’s Old XF 35mm f/1.4 Is a Best-Selling Prime Lens By a Huge Margin and Seeking feedback on pricing limited edition fine art photography prints. As artists and enthusiasts, we must prioritize platforms that emphasize security and reliability.

Moving forward, this incident prompts a crucial discussion about the responsibilities of both consumers and online retailers. As consumers, we need to be proactive in safeguarding our personal information, employing unique passwords, and utilizing two-factor authentication whenever possible. Retailers, on the other hand, must prioritize the integrity of their platforms and the security of their customers. Transparency regarding security measures and prompt communication in the case of breaches can foster trust and encourage a healthier online shopping environment.

As we navigate this evolving landscape, the question remains: How can we collectively enhance our online security while continuing to foster creativity and innovation within our communities? The recent experience shared by the user is not just an isolated incident; it serves as a crucial reminder of our shared responsibility to remain vigilant in the face of digital threats. In a world where creativity and technology intersect, our commitment to safety must be as robust as our passion for artistry.

In search of a Sigma TS-21 collar mount I ended up finding an ishoot IS-SM720 at photoloving.com. Showed in stock so I created an account and clicked buy now. pop up says 'not available'. Tried again, same result. Odd, but oh, well.

Naive, I was.

About 12 hours later.... my email started to blow up (called 'email bombing') with 'new account created' emails. Another 285 emails diverted into my spam folder. Scammers did successfully get into one of my accounts and placed a rush delivery order. I was not quick enough to get that cancelled prior to delivery but got the account frozen shortly after.

Gemini tells me this is a "classic cyberattack known as a credential stuffing and fraud loop, and it confirms that photoloving.com is operating as a malicious data-harvesting honeypot."

Be safe out there!

Meanwhile, anybody know where I can find an IS-SM270?? lol

submitted by /u/Crash_Ntome
[link] [comments]

Read on the original site

Open the publisher's page for the full experience

View original article
Beware photoloving.com! | Lee LHGFX Photography