So I just got an e-mail from the bank fraud department asking if a charge over $800 is valid.
It's not, I clicked no, it said 'this e-mail has already had a response' and gave a phone number.
I checked and there's also a charge for over $1300. I called them, and they said yes, they got a response confirming the purchase four minutes after the fraud alert was sent from my account.
They also had a request to pre-approve a $2500 charge. So I had them cancel that account.
What I was curious about was how my e-mail would have been compromised. It's not an easy password to guess and I run malwarebytes from time to time to check on things like keyloggers.
One odd thing, I have been getting periodic messages for months about unauthorized login attempts that look legitimate, but ignored them - who knows. Guess there was more to it.
So I ran Malwarebytes again, nothing found, changed the password, and checked the account recent activity.
It shows every few days, some sort of login attempt from a different country, all unsuccessful - but nothing today to explain how they'd have been on my account and responded to that e-mail.
In fact here's the list below, with my e-mail removed, no successful logins (I've been logged in for months, so it doesn't show me logging in):
Protocol: IMAP
IP: 141.168.149.22
Time: 4 hours ago
Approximate location: Australia
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 2001:e68:5050:4d39:1e5f:2bff:fe00:e880
Time: 10/21/2018 3:40 PM
Approximate location: Malaysia
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 200.7.158.71
Time: 10/20/2018 11:02 AM
Approximate location: Argentina
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 223.204.198.82
Time: 10/20/2018 11:02 AM
Approximate location: Thailand
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 200.7.158.71
Time: 10/20/2018 11:02 AM
Approximate location: Argentina
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 185.138.133.65
Time: 10/20/2018 11:02 AM
Approximate location: Palestinian Authority
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 2001:e68:5087:650:12be:f5ff:fe31:28e0
Time: 10/17/2018 4:03 PM
Approximate location: Malaysia
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 2001:e68:504c:b033:12be:f5ff:fe29:29b0
Time: 10/13/2018 4:49 PM
Approximate location: Malaysia
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 36.82.101.141
Time: 10/10/2018 11:23 AM
Approximate location: Indonesia
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 125.166.116.230
Time: 10/10/2018 11:23 AM
Approximate location: Indonesia
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 27.72.73.180
Time: 10/10/2018 11:23 AM
Approximate location: Vietnam
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 223.24.22.36
Time: 10/10/2018 11:23 AM
Approximate location: Thailand
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 175.140.82.24
Time: 10/7/2018 1:33 AM
Approximate location: Malaysia
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 177.11.244.42
Time: 10/4/2018 9:09 PM
Approximate location: Brazil
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 210.210.162.51
Time: 9/27/2018 7:39 PM
Approximate location: Indonesia
Type: Unsuccessful sync
It's not, I clicked no, it said 'this e-mail has already had a response' and gave a phone number.
I checked and there's also a charge for over $1300. I called them, and they said yes, they got a response confirming the purchase four minutes after the fraud alert was sent from my account.
They also had a request to pre-approve a $2500 charge. So I had them cancel that account.
What I was curious about was how my e-mail would have been compromised. It's not an easy password to guess and I run malwarebytes from time to time to check on things like keyloggers.
One odd thing, I have been getting periodic messages for months about unauthorized login attempts that look legitimate, but ignored them - who knows. Guess there was more to it.
So I ran Malwarebytes again, nothing found, changed the password, and checked the account recent activity.
It shows every few days, some sort of login attempt from a different country, all unsuccessful - but nothing today to explain how they'd have been on my account and responded to that e-mail.
In fact here's the list below, with my e-mail removed, no successful logins (I've been logged in for months, so it doesn't show me logging in):
Protocol: IMAP
IP: 141.168.149.22
Time: 4 hours ago
Approximate location: Australia
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 2001:e68:5050:4d39:1e5f:2bff:fe00:e880
Time: 10/21/2018 3:40 PM
Approximate location: Malaysia
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 200.7.158.71
Time: 10/20/2018 11:02 AM
Approximate location: Argentina
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 223.204.198.82
Time: 10/20/2018 11:02 AM
Approximate location: Thailand
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 200.7.158.71
Time: 10/20/2018 11:02 AM
Approximate location: Argentina
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 185.138.133.65
Time: 10/20/2018 11:02 AM
Approximate location: Palestinian Authority
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 2001:e68:5087:650:12be:f5ff:fe31:28e0
Time: 10/17/2018 4:03 PM
Approximate location: Malaysia
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 2001:e68:504c:b033:12be:f5ff:fe29:29b0
Time: 10/13/2018 4:49 PM
Approximate location: Malaysia
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 36.82.101.141
Time: 10/10/2018 11:23 AM
Approximate location: Indonesia
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 125.166.116.230
Time: 10/10/2018 11:23 AM
Approximate location: Indonesia
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 27.72.73.180
Time: 10/10/2018 11:23 AM
Approximate location: Vietnam
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 223.24.22.36
Time: 10/10/2018 11:23 AM
Approximate location: Thailand
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 175.140.82.24
Time: 10/7/2018 1:33 AM
Approximate location: Malaysia
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 177.11.244.42
Time: 10/4/2018 9:09 PM
Approximate location: Brazil
Type: Unsuccessful sync
Look unfamiliar?
Secure your account
Protocol: IMAP
IP: 210.210.162.51
Time: 9/27/2018 7:39 PM
Approximate location: Indonesia
Type: Unsuccessful sync