A Discord User Hacked into a Company!

Поділитися
Вставка
  • Опубліковано 15 чер 2024
  • Imagine being a large cloud computing company. You know, computer nerd wizardry. And then kaboom, a teenager with a room temperature IQ comes out of the woodwork to go wild.
    Yep, a Discord scammer managed to hack a large company with a sophisticated technique. But was this hacking technique actually sophisticated? Or is Shadow, the company, lying to you?
    SOCIALS
    -----------------------------------------------------------------------------
    Discord Server
    / discord
    Twitter
    / notexttospeech
    TIMESTAMPS
    -----------------------------------------------------------------------------
    00:00 - Advanced level hacking
    01:16 - The scope of the breach
    02:29 - How did the hacker do it?
    04:44 - Preventable?
    05:31 - Bankruptcy?
    06:32 - How to protect yourself
  • Наука та технологія

КОМЕНТАРІ • 533

  • @vinechetti
    @vinechetti 8 місяців тому +1028

    Whenever you hear from a company that they've been a victim to a 'highly sophisticated' attack, it usually means that some dumb employee fell for a simple social engineering trick.

    • @batorerdyniev9805
      @batorerdyniev9805 8 місяців тому +9

      Very true

    • @yeawassah
      @yeawassah 8 місяців тому +5

      W statement

    • @victoralexandervinkenes9193
      @victoralexandervinkenes9193 8 місяців тому +28

      Or an employee could deliberately download something that is obviously a virus to take down the company for... various reasons COUGH COUGH scamming people COUGH COUGH.

    • @UnitedYetDivided
      @UnitedYetDivided 8 місяців тому

      @@victoralexandervinkenes9193insider attacks are surprisingly common

    • @techwhipped
      @techwhipped 8 місяців тому +4

      Yeah the employee fell for the most known discord malware by accepting a file from a friend of there that was hacked.

  • @dogeimpala
    @dogeimpala 8 місяців тому +622

    I'm shocked shadow didn't implode much sooner. That was by far one of the dumbest breaches imaginable. A 12 year old could of compromised that company.

    • @kacperkonieczny7333
      @kacperkonieczny7333 8 місяців тому +23

      One of the most important things I learnt on the internet that the common person is not even half as intelligent as you think they are

    • @cesj1
      @cesj1 8 місяців тому +16

      You're way too optimistic. Also "could of"?? Contractions are not hard.

    • @mcburn_
      @mcburn_ 8 місяців тому +8

      @@cesj1 It's also not that hard to avoid correcting other people online, where formality isn't as commonplace or required. Yet, we have plenty of people doing that same exact thing, so I guess it's an urge just to point them out? xD

    • @cesj1
      @cesj1 8 місяців тому +10

      @@mcburn_ You're acting as if that's the only thing I said. Simple contractions truly aren't hard. Also footnote: I do whatever I want to.

    • @jerejere-qv7xk
      @jerejere-qv7xk 8 місяців тому +3

      No, a 12 years wouldn't have been able to hack a steam developper account and then use that to hack shadow.
      The game was not sent as a .exe on discord, it was a steam link to a compromised game. It's just as much steam fault here for putting virus on their plateform.

  • @krizcold
    @krizcold 8 місяців тому +339

    yea, the reality is, a surprisingly high amount of companies have very poor security, you'll be surprised how many companies genuinely use "123" type of passwords. But the fact that this was a Cloud virtual machine related company and not a regular restaurant or something it's outrageous

    • @kevinwebster7868
      @kevinwebster7868 8 місяців тому +1

      No. Not really.

    • @Silver0Crow
      @Silver0Crow 8 місяців тому

      u mean `1qaz!QSX`?

    • @thedarkdragon1437
      @thedarkdragon1437 8 місяців тому +3

      atleast not 0000 type of passwords

    • @krizcold
      @krizcold 8 місяців тому +2

      @@kevinwebster7868 At least in my experience, a lot of small businesses have old people on top that don't know or care about security (some young people not excluded), "123" type of password was more of a hyperbole.
      Maybe more like "Very poor security practices"
      But yea, I've actually seen "myCompany123" more than once

    • @maiyannah
      @maiyannah 8 місяців тому +7

      Reminder that Sony was storing passwords in plaintext. Not even weak hashed.

  • @jd-raymaker
    @jd-raymaker 8 місяців тому +203

    Incredible! Imagine running a business providing virtual machines in the cloud, YET an employee decided to run a random EXE on their own production machine...

    • @jerejere-qv7xk
      @jerejere-qv7xk 8 місяців тому +14

      It wasn't a .exe sent on discord but a link to a compromised steam game.
      Doesn't excuse bad security tho

    • @jd-raymaker
      @jd-raymaker 8 місяців тому

      @@jerejere-qv7xk still an executable binary.

    • @frelift
      @frelift 8 місяців тому

      @@jerejere-qv7xk source?

    • @carlissou
      @carlissou 8 місяців тому

      Bruh you realise lowest employees have usually 0 trainings in companies they're only train to answer customers
      It's the issue of companies, they think only IT people should be trained on this and non-IT people don't see the point in receiving those trainings
      The problem is that any smart guy will take his shot on the most careless employees that will guarantee his chances to succeed
      It's like the rubber ducky hack, it all relies on the guy who will pick it up and be curious enough to see what's inside without precaution
      Look up to Ulcan, he's a crazy french hacker that mostly succeeded through social engineering, he even freed random people from jail just by calling 2 cops who he knew weren't on the same floor and still had to interact with each other. He just learnt the day before how cops are used to talk together.

    • @starsnipe-yp5hx
      @starsnipe-yp5hx 8 місяців тому

      ​@@jerejere-qv7xkthats even worse

  • @halb-acht
    @halb-acht 8 місяців тому +130

    You'd just think Shadow the Hedgehog would have a stronger sense of internet safety. A shame, really

    • @Bloomkyaaa
      @Bloomkyaaa 8 місяців тому +5

      Dude... Shadow is an old man lol.

    • @Gemdation
      @Gemdation 8 місяців тому +5

      I bet Sonic hacked it

    • @MustaDev
      @MustaDev 8 місяців тому +6

      We live and learn, that's what matters.

    • @gamerperson_epik
      @gamerperson_epik 8 місяців тому +1

      yea such a shame

    • @JRPGLOVER
      @JRPGLOVER 8 місяців тому +6

      He should've used 70 alternative accounts, like Eggman.

  • @oxymore13
    @oxymore13 8 місяців тому +36

    As soon as i read "social engineering" i immediately knew what happened. A friend recently fell for it lol

  • @maiyannah
    @maiyannah 8 місяців тому +40

    I would compare the security of these companies to swiss cheese, but that's insulting perfectly good cheese.

    • @kacperkonieczny7333
      @kacperkonieczny7333 8 місяців тому +4

      Those defenses aren't even paper width

    • @Jenner_IIC
      @Jenner_IIC 8 місяців тому +1

      A fun fact is that in aviation and increasingly safety overall a "swiss cheese" model is used

    • @erikkonstas
      @erikkonstas 8 місяців тому

      ​@@kacperkonieczny7333They're probably very strong, it's the, uh, PEBKACs that ruin everything...

  • @EnBunk
    @EnBunk 8 місяців тому +24

    A naked man fears no pickpocket.

    • @Turtle69696
      @Turtle69696 8 місяців тому +2

      that's why I don't fear pickpockets at the grocery store

    • @pepsonpepson988
      @pepsonpepson988 8 місяців тому +2

      A collage student is like naked man

    • @2006HondaCivicD
      @2006HondaCivicD 8 місяців тому +1

      Pickpocket is the least of his worries when m o l e s t e r s exist.

  • @gabbieblue
    @gabbieblue 8 місяців тому +15

    as someone who works in IT, youre right, we do in fact assume that everyone is an idiot
    and people _still_ manage to do worse than i could ever have thought of
    also, love the privacy and security tips!

  • @ewenlau727
    @ewenlau727 8 місяців тому +9

    I used to have shadow, and I stopped because not only is the product garbage (6 years old hardware), the support is beyond imaginable, like they take 5 days to send a mail saying "We'll get back to you". Never subscribe to it.

  • @Wicked_Knight
    @Wicked_Knight 8 місяців тому +8

    I've encountered more adults, generally boomer and older, that will trustingly download and run programs that lead to them infecting their PCs.

  • @libalance
    @libalance 8 місяців тому +12

    The 2021 bankruptcy story is well-known: They charged too cheap for the service at that time, but the processing load exceeded the benefits. They almost got ruined. They have been acquired after this bad move.
    For the rest, it's exactly why I agreed with the tech company where I worked where they were **decent** protection measures. Not good, only decent, because I don't think this is at all common. The regular users only saw, "Our service is so bad. We can't do anything easily!" In a purely non-tech company, it isn't even possible to explain to someone why giving them my session password is a bad idea. "I'm not going to steal your account, you know?" That was a very competent colleague of mine, (I'm not being ironic, her job was different) looking at me like I was being stupid. Computers and good practices are something people view as something absolutely unimportant... "Until they get burned." To quote a famous social engineering book.

  • @BlessedSeal
    @BlessedSeal 8 місяців тому +7

    I wish they were more active with helping compromised accounts, poor people waiting weeks for a reponse

  • @Toei-Rei
    @Toei-Rei 8 місяців тому +33

    I own a domain and I run a ton of email addresses - basically giving each service their unique one. And to be honest, it's shocking to see how many services are sharing data - willingly or unwillingly.

    • @sippingthepeachsoda
      @sippingthepeachsoda 8 місяців тому +4

      catch all?

    • @Toei-Rei
      @Toei-Rei 8 місяців тому +3

      no, as a lot of scammers do typos or invalid addresses to catch that as well.

    • @erikkonstas
      @erikkonstas 8 місяців тому

      Why does it sound like you're snooping...?

    • @Toei-Rei
      @Toei-Rei 8 місяців тому +1

      @@erikkonstas not sure what you're trying to say.

    • @erikkonstas
      @erikkonstas 8 місяців тому

      @@Toei-Rei How do you know what your customers do with their emails?

  • @Silver0Crow
    @Silver0Crow 8 місяців тому +16

    Holy frick, how gullible you have to be to have cloud-based company and not having InfoSec dept. Is this Shadow some fresh startup or something?

    • @agentcripper
      @agentcripper 8 місяців тому +3

      I don’t think they are a new company considering they have such a large userbase

    • @erikkonstas
      @erikkonstas 8 місяців тому +3

      That department can't do much when the evil is manually invited inside...

  • @Marxally
    @Marxally 8 місяців тому +16

    I wrote a news post regarding this incident and I had to stop for 5 minutes because I couldn't stop laughing at the "sophisticated method". 😂

  • @hooting-ton5215
    @hooting-ton5215 8 місяців тому +23

    If Shadow is a french company then the GDPA is going to slap them hard for this kind of breach

    • @yayaguest666fire
      @yayaguest666fire 8 місяців тому +1

      le truc le plus vrai du jour

    • @redstone0234
      @redstone0234 8 місяців тому +7

      Thé GDPR Is a Law
      Is thé CNIL that will slap their ass

    • @Bashiroo
      @Bashiroo 8 місяців тому +4

      No. GDPR isn't going to do anything since they've told their customers very *very* fast about the data breaches and gave an explaination (although quite blurry) of how the breach happened.
      A lot company will have their customer's data breached at some point or another. And the CNIL doesn't beat companies' asses just because they got hacked, even if it was as stupid as that.
      Source: I worked with GDPR and the CNIL for a bit of time.

    • @maiyannah
      @maiyannah 8 місяців тому

      @@BashirooThen what you're telling me is that these organizations meant to enforce the laws are not actually completing the purpose the law was designed to achieve.

    • @Liggliluff
      @Liggliluff 8 місяців тому +1

      ​@@maiyannahGDPR allows you to store customers' data, but customers have the right to have their data deleted.

  • @GaIaxyxvr
    @GaIaxyxvr 8 місяців тому +7

    its like discord is in a land field, and just keeps stepping on mines.

  • @7heMech
    @7heMech 8 місяців тому +14

    I'm surprised so many companies don't implement the zero trust model.

  • @pchris
    @pchris 8 місяців тому +34

    Remember: don't shame individuals for falling for scams. It's ok to make fun of a large company for not having good IT but the practice of shaming idividuals makes people not want to talk about this kind of thing out of fear of being shamed and so we A.) don't get to learn as much from other people's mistakes because they won't want to share and B.) people won't ask questions they think are "stupid" and will try harder to just figure things out themself which is more likely to get them scammed. We need openness and that can't happen if we're shaming people for things that are only obvious in retrospect or with existing knowledge not everyone has.

  • @kmemz
    @kmemz 8 місяців тому +2

    Well then, I guess I'm glad I only ever put one of my throwaway emails into Shadow and no real info.

  • @bnanik
    @bnanik 8 місяців тому +13

    imagine getting hacked by a discord user

    • @agentcripper
      @agentcripper 8 місяців тому

      Nah fr discord users are all skids

    • @SwordfighterRed
      @SwordfighterRed 8 місяців тому

      cringe

    • @SunnyXck
      @SunnyXck 7 місяців тому

      ​@@SwordfighterRedfor myself

  • @extrominus5678
    @extrominus5678 8 місяців тому +10

    Love your content man, keep the hard work up!

  • @adamtheman17
    @adamtheman17 8 місяців тому +5

    I' an IT Tech and i do notice a lot of companies don't have things locked on the computer from letting users installing things onto the pc

  • @kray9927
    @kray9927 8 місяців тому +8

    no joke, my pc broke a few days ago and i was about to go buy a cloud computer from SHADOW. its safe now, but the coincidence is amazing lol. (didnt see the full video yet only the first minute).
    and also, they mentioned steam in the video, a few days ago a situation occured on steam where people managed to bypass steams antivirus and upload games with malware onto steam. i think they might be linked? i dunno me stupid

  • @lil-hannah
    @lil-hannah 8 місяців тому +4

    This happend to me, (Also in September), like got a message from a friend for testing a game
    It is a pain to communicate with the Discord Support

  • @RedEndermanDJ
    @RedEndermanDJ 8 місяців тому +9

    when did 4chan migrate to discord

    • @kacperkonieczny7333
      @kacperkonieczny7333 8 місяців тому +5

      _Long ago, beyond the ages, pass the mountains and rivers the council of the 4chan decided to migrate to a new platform_

  • @HongKongZ
    @HongKongZ 8 місяців тому +1

    Bruh they literally straight download the malware, the only trickery was renaming a file and making a crappy website. I had no idea about this, keep up the great work!

  • @PumpkinFox
    @PumpkinFox 8 місяців тому +3

    Dang, I fell for this like a few weeks ago. Secured everything except for my discord account at this point, so don't worry about that. I'm an idiot that sits at their computer all day, these are supposed to be professional workers.

  • @subanark
    @subanark 8 місяців тому +5

    Where I work, we are allowed to download and run anything that isn't forbidden by IT. We do however need to keep our personal stuff on a separate account from our work stuff if using a personal computer. For accessing customer data we have a secure laptop that restricts what programs we can run and what websites we can visit.

    • @DarkGob
      @DarkGob 8 місяців тому

      Wow, you're allowed to do anything that isn't not allowed?

    • @subanark
      @subanark 8 місяців тому

      Yea, we are told what we can't do, not what we can.@@DarkGob

  • @casualamber
    @casualamber 8 місяців тому +1

    Companies will never take accountability unless they are forced to either from damning evidence or legally

  • @not3128
    @not3128 8 місяців тому +5

    discord needs to hire this man

  • @TheGoldenSplatRoller
    @TheGoldenSplatRoller 8 місяців тому +2

    How the FUCK, does a 500k+ customer company. NOT take security seriously??

  • @ShrimpsUseful
    @ShrimpsUseful 8 місяців тому +14

    We love NTTS content!

  • @curious_banda
    @curious_banda 8 місяців тому +2

    In India it is now illegal to store CC info, you have to tokenise it. Now they have introduced direct tokenisation at bank's website, so you just use token at other websites.

    • @erikkonstas
      @erikkonstas 8 місяців тому

      Um WTF... and how would most websites work then? I don't think they are designed to accept some random "token" instead of normal CC info...

    • @curious_banda
      @curious_banda 8 місяців тому

      They are forced to. Once you realise you just need a way to link back to the bank account, you don't really need CC info. A unique identifier works. Payment gateway implementation is easier as the complexity is on the bank's side.
      Payment data of Indian customers are also mandated to be stored only inside India.

    • @erikkonstas
      @erikkonstas 8 місяців тому

      @@curious_banda I feel like that would harm Indians more than it would help them... imagine if they want to pay for something at a non-Indian site without a server in India, what are they supposed to do? Is this basically capital controls?

    • @curious_banda
      @curious_banda 8 місяців тому

      @@erikkonstas Which card network doesn't have a server in India? You need to realise transactions happen via payment gateways of these networks (Visa is a network), the website doesn't actually handle it. By payment data and processing there is specific data involved, it doesn't just mean the bill generated by a merchant.
      MasterCard cried to the US government about it. Nothing happened, they were forced to do else all MasterCards were going to get blocked in India. New signups were already blocked due to their non-compliance and cards of domestic rival started getting issued.
      Plus as of now tokenisation isn't enforced on international files (though they should be), it is domestic mandate only. Fortunately, relatively (on scale) the number of international transactions is not big compared to domestic.
      Also, card transactions require OTP in India. Same is not the case for international transactions as the mandate is for domestic gateways.

  • @jerejere-qv7xk
    @jerejere-qv7xk 8 місяців тому +7

    What happened is that they send a link to a steam game that was compromised. So the employee trusted the steam platform where they downloaded the game from.
    It is linked to a earlier hack of a steam developer account.
    They went bankrupt 2 years ago but were bought back buy ovh owner, nothing lost by the users.

    • @Zeda1002
      @Zeda1002 8 місяців тому +1

      why did they download it on work computer

    • @jerejere-qv7xk
      @jerejere-qv7xk 8 місяців тому +1

      @@Zeda1002 shadow pc is mostly sold as a gloud gaming subscription. He probably wanted to test if the game would run on actual shadow hardware. But yeah it's still stupid.

    • @Minecon724
      @Minecon724 8 місяців тому

      ​@@jerejere-qv7xk "test if the game would run on actual shadow hardware" by playing it on their work pc?

    • @jerejere-qv7xk
      @jerejere-qv7xk 8 місяців тому +2

      @@Minecon724 I'm guessing their work pc was shadow hardware. But like I said it's still stupid. The fact that the employee could have access to all of that was a clear lack of security too.

    • @liquidmagma0
      @liquidmagma0 8 місяців тому

      @@jerejere-qv7xk lmao testing on prod instead of making a safe test system

  • @vbad0
    @vbad0 8 місяців тому +5

    Truly a master at work

  • @triggermydigger
    @triggermydigger 8 місяців тому +1

    love the content keep it up mr

  • @rando521
    @rando521 8 місяців тому +6

    i expect cloud computing to be insanely sophisticated because all the tokens usually expire in 2-3hours sometimes a week and refresh is easy to build.
    all the cloud providers i have worked with have a special token for each service. these tokens are huge strings of letters almost impossible to crack.
    and we the users of these services are requested to be careful in our production environment.

    • @erikkonstas
      @erikkonstas 8 місяців тому

      I would be so fed up if my token expired every "2-3 hours"...

  • @TheBenSanders
    @TheBenSanders 8 місяців тому +3

    I had Shadow before the OVH buy out. It was a great service sucks this happened for sure.

  • @BlueMoon1890
    @BlueMoon1890 7 місяців тому +1

    I used to use shadow pre bankruptcy, it was handy for playing PC VR games on my oculus quest remotely. I've been slowly watching them circle the toilet drain since then, my subscription was long cancelled in 2020 and account since deleted, but as someone who's been keeping an eye on them this isn't surprising really. On the bright side, none of the information I used for shadow is up to date anymore since I signed up before coming out lol

  • @xAbdulRhmanX
    @xAbdulRhmanX Місяць тому

    As an Incident Responder a I see this a lot. Less than 1% of cases are actually "sophisticated", most of the cases are dump stuff like this and they add the "highly sophisticated" just to safe face

  • @_Cardio
    @_Cardio 8 місяців тому +1

    Bro I was waiting for you to say "but this could have been prevented by today's sponsor guardio"

  • @Idamok
    @Idamok 8 місяців тому

    Wow, I am very surprised I avoided this exact malware problem without knowing I was right.

  • @abdullapgofficial
    @abdullapgofficial 8 місяців тому +5

    imagine when discord is not safety💀

    • @aw_dev
      @aw_dev 8 місяців тому

      When discord not is trust and not is safety

    • @creepralt.5694
      @creepralt.5694 8 місяців тому

      whn dacad no hayp nd hker gt ip adares

  • @bendysans1473
    @bendysans1473 8 місяців тому +2

    So the company had an "idiot" on the computer that day
    So this is why you dont do that on work computers

  • @MysticMylesZ
    @MysticMylesZ 8 місяців тому +1

    1:08 ay finally someone giving a hint as to how much it fucking is

  • @jakeywakey_ow
    @jakeywakey_ow 7 місяців тому

    A lot of people don’t take cyber security seriously, they always think “I don’t care if my stuff gets leaked, why would anyone target some random dude like me”

  • @TheHotRodJayden
    @TheHotRodJayden 8 місяців тому

    People finally talk about shadow and it's about the data breach. Lovely

  • @CursedAlfie
    @CursedAlfie 8 місяців тому

    imagine being a "hacker" and going thru their website to only find yourself?

  • @alvindms4660
    @alvindms4660 8 місяців тому

    truly when company that got hacked

  • @rkiller645
    @rkiller645 3 місяці тому

    Funny fact: I tried naming my little studio Shadow Studios as a child but I saw this logo and I was like nope we can't do that

  • @austinlipnicki7761
    @austinlipnicki7761 8 місяців тому +2

    oh hey i got hacked like that, i am really glad i am one of the people that got to keep my account :)

  • @ikillbiganimal92
    @ikillbiganimal92 8 місяців тому +2

    Poor Cookie Monster gonna get his cookies stolen 😂

  • @Bubby_Le_Wubby
    @Bubby_Le_Wubby 8 місяців тому +3

    This, Actually sucks.
    I am own/rent a computer from their site, listining to this from NTTS is just mind blowing.
    (I also received the email, and I thought I was safe, it seems that I am not. I still dont know if I should cancel my plan, as I use my computer as a gaming pc, due to me not owning a gaming pc, so I am kinda stuck in a tough spot)

    • @frelift
      @frelift 8 місяців тому

      I cancelled it, gonna get my own PC and as for gaming use GeForce Now with fake details. This was the final straw for me, billing address, full name and DOB isn't like a credit card that can be terminated.

  • @Dante1282
    @Dante1282 8 місяців тому +1

    Revolut offers virtual cards with costume limits (x € one time, per month, or x times only) too

  • @Liggliluff
    @Liggliluff 8 місяців тому +2

    Jokes on you, I don't have a credit score

  • @user-ut5gy5qt5k
    @user-ut5gy5qt5k 8 місяців тому

    imagine seeing the same thing happen to discord

  • @tomascz9874
    @tomascz9874 8 місяців тому +2

    7:38 This is the best idea! Especially if after a year you forget your password and the site asks for your date of birth and takes it as a security question and you're screwed (it happened to me on two sites)

    • @erikkonstas
      @erikkonstas 8 місяців тому +1

      And that's why we use something called a *password manager* , as long as its name is NOT LastPass...

  • @yamo511
    @yamo511 8 місяців тому

    Total Cloud Computing Destruction

  • @123warsie
    @123warsie 8 місяців тому

    Love Your Videos No Text To Speech!

  • @shedfakballsinurjaw
    @shedfakballsinurjaw 8 місяців тому +10

    i liked my own comment too

  • @hipy-tz3qt
    @hipy-tz3qt 8 місяців тому +1

    I always lie about my birth haha.
    These Videos are so important!
    Good Content, keep up the good work!

  • @staar78
    @staar78 7 місяців тому

    me, a ceo entrusting that my employee that used chatgpt to apply wont download viruses on his work computer

  • @kathras
    @kathras 7 місяців тому +1

    Social Engineering and Highly Sophisticated dont go in the same sentence.

  • @rishibellam738
    @rishibellam738 8 місяців тому +2

    if you are going to make up a DOB make sure it is same across different services because oauth2 might give a service acess to your DOB and if they arent same they might seem suspicous

    • @oxymore13
      @oxymore13 8 місяців тому +1

      like, just have a similar DOB for dumb shit, and your real one for actual gov shit

    • @rishibellam738
      @rishibellam738 8 місяців тому

      @@oxymore13 yeah

    • @erikkonstas
      @erikkonstas 8 місяців тому

      OAuth2 is the authentication protocol, not a service, it's one site connecting to another via it that could do that.

    • @rishibellam738
      @rishibellam738 8 місяців тому

      @@erikkonstas yeah

  • @Null-FR
    @Null-FR 8 місяців тому

    And they didn't even clear their cache...

  • @vinxmusic_
    @vinxmusic_ 8 місяців тому

    Good that I don´t have Shadow anymore since they raised their prices

  • @llayered
    @llayered 8 місяців тому +1

    Shadow should have used shadow to run the game lol

  • @Sunsoons
    @Sunsoons 8 місяців тому +1

    whenever you post a video i am almost always eating pasta
    is this a coincidence

  • @laeven_
    @laeven_ 8 місяців тому

    As someone who works in the industry, you should assume all security is a slice of swiss cheese. You should have multiple layers of different systems designed to catch out many types of attacks. It's not really surprising about any new data breach. Corperations will never take security seriously because that would eat too much into their bottom line. You build a wall around your business but didn't bother to add multiple inner walls with tighter checking at each gate. Social Engineering will always be an exploitable attack vector if the employee has too much access to the internal systems they use.
    The real way to stop your data getting leaked is to just never give it to them in the first place. If there is no legitimate need for information, give them fake information. Use burner emails or email aliases you can create and destroy. Companies are only looking at the front door and thinking its the only way in, unbenounced to the many holes and cracks others have found in their wall.

  • @michal_cz17
    @michal_cz17 8 місяців тому

    Wait, virtual cc isnt standard in other countries? In Czechia, even banks offer you to create Virtual CC, that will last for few years, or one time Virtual CC that will expire after 30 minutes and you can add limit, that can be withdrawn from it

  • @BuiHieuDong
    @BuiHieuDong 8 місяців тому +7

    This Discord hacker is literally so advanced they could even work for the FBI or something similar to that instead of scamming people around.

    • @TheProxyd
      @TheProxyd 8 місяців тому

      Hello nigga

    • @nubidubi23
      @nubidubi23 8 місяців тому +3

      💀

    • @kacperkonieczny7333
      @kacperkonieczny7333 8 місяців тому +2

      ​@@nubidubi23Your profile picture is literally a perfect reaction to that comment

  • @subpoenas
    @subpoenas 8 місяців тому

    A hint for whats to come.

  • @dragodite
    @dragodite 8 місяців тому +1

    bro got god rank in a hacking site 💀

  • @FreonSB
    @FreonSB 8 місяців тому +1

    Sophisticated. Not only are companies now getting scammed by the most basic scams in history, but they also lie about them being “sophisticated”. Now hear me out: Just telling that stupid truth straight isn’t easy, so understand them a bit. But I still do agree that it is very, very, very disappointing. Other big companies should prevent this ASAP.

    • @jerejere-qv7xk
      @jerejere-qv7xk 8 місяців тому

      It was quite sophisticated, ntts was missinformed on what happened because of the stupidly written press release.
      - Hijack of a steam developper account
      - Upload of a malware specific for shadow disguised as a game update on steam
      - Send an employee the link to the game on steam
      - Classic cookie attack to access the server without credentials. (Not sure about this part)
      Still there should have been system in place to prevent that.

  • @Themanofgas
    @Themanofgas 8 місяців тому

    Bro’a dental care really fell down

  • @Shadow8797_YT
    @Shadow8797_YT 8 місяців тому

    THIS IS A SIGN FOR ME 😭😭😭

  • @m4rt_
    @m4rt_ 7 місяців тому

    Ahh Windows 7, how I have missed you.

  • @Hamvpter
    @Hamvpter 8 місяців тому +1

    Dayum im surprised with how that even happened 🤓

  • @djispro4272
    @djispro4272 7 місяців тому

    You might say, "Shadow is a rather shadow-y company"!

  • @shrimpaerospace
    @shrimpaerospace 8 місяців тому

    This isn't the first time a young man has breached the data of a large company

    • @erikkonstas
      @erikkonstas 8 місяців тому

      LOL I think I know what you're talking about... 😂

    • @shrimpaerospace
      @shrimpaerospace 8 місяців тому

      @@erikkonstas Tell me

    • @erikkonstas
      @erikkonstas 8 місяців тому

      @@shrimpaerospace Well, NTTS had made a video a while back, about how some youngster with access to military classified data exposed it in the name of War Thunder...

  • @ScriptingBacon
    @ScriptingBacon 8 місяців тому +1

    I just got my discord account hacked by one of these, Everyone please be aware of this hack, It may look easy to point out but I fell right through it, Please be careful!

  • @Kyrelossaw
    @Kyrelossaw 8 місяців тому

    Hello. Every time I try to log in to Discord, I can't log in. The discord icon in the middle keeps turning around and saying "we are investigating an issue with twitter links not getting embedded" and it says this. Could you help ?

  • @Linkman8912
    @Linkman8912 4 місяці тому

    Ahh, it's fine. They should just change all of that information, change your address, credit card expiration, all of that. Easy.

  • @JBLZFTW
    @JBLZFTW 8 місяців тому

    I'm so over the defeatist attitude of "oh everyone has my data anyway so who cares" like I got so much shit from people when I ditched windows for Linux like "who cares dude they already have all your info anyway what's it matter now?" It's such a garbage mindset I can't even waste brainpower arguing against it

  • @Mario583a
    @Mario583a 8 місяців тому

    Where is that *D A M N* cookie!? ~ Shadow, not the company.

  • @ShadowWolfe
    @ShadowWolfe 8 місяців тому

    I thought about using Shadow PC at some point in the past... glad I didn't, considering their IT and employees are that incompetent.

  • @kbhasi
    @kbhasi 8 місяців тому

    (0:26) Ouch. I immediately recognised Shadow as they, like Discord, originally marketed their service to PC gamers, but much like the latter, the former branched out.
    I had considered subscribing to their service, but ended up not doing so as they didn't have a server location in the region I live in, and had since moved on to a DIY solution.
    (0:56) I think Shadow were competing with Microsoft's own Azure Virtual Desktop and Windows 365 services with that. Wow.
    (1:05) I remember I first heard about them through a "My Mate VINCE" video where they loaned the host an account on a server in France and one of their preconfigured thin clients.

  • @Legendarysucks
    @Legendarysucks 8 місяців тому +5

    this is just a normal discord group chat

  • @bandiddums
    @bandiddums 7 місяців тому

    I've been looking into getting a virtual credit card to prevent this sort of stuff but unfortunately I don't think there's any that are available for my country

  • @HeyLyfe
    @HeyLyfe 8 місяців тому +1

    i think i lost 2 brain cells

  • @xxonixzz1743
    @xxonixzz1743 8 місяців тому

    You should make a video about the discord vulnerability. Discord has a CSAM detection system , which is kinda obvious. If you post an image and discord detects CSAM from any frame, it'll ban you instantly. I think you can guess where this is going; some creep had a video of CSAM, the frame starting with a dark skinned guy eating popcorn. If you take a screenshot of that frame, which does not include any inappropriate content, discord will detect it and instantly ban you.

  • @voxan24
    @voxan24 8 місяців тому

    Shadow is now owned by OVH but yeah that a big weird company even today

  • @Klarthin
    @Klarthin 8 місяців тому

    Speaking of hacking, I think I may have a virus, as I keep getting the connection refused error, however my internet is fine, I've checked it all, and it's only with my computer account, all my other accounts are fine. I've deleted my memes folder, mp3 songs, and downloads, what should I do next?

  • @ikillbiganimal92
    @ikillbiganimal92 8 місяців тому +1

    The email thing so true lmao

  • @Aklinwert
    @Aklinwert 8 місяців тому

    as a 15 year old and never fell for a scam this is just sad

  • @rebok232
    @rebok232 8 місяців тому +1

    1. make API safe from the public
    2. make API allow you to acess everything in the comany's private network cause why not

    • @U20E0
      @U20E0 8 місяців тому

      2!

  • @pistolk1
    @pistolk1 8 місяців тому

    Last year I tried shadow and got sick of it because of the monthly price, doged a bullet giving them up so soon

  • @gdplayer1035
    @gdplayer1035 8 місяців тому

    seytonic 2: electric boogaloo