Bumhug360 Posted January 21, 2020 Posted January 21, 2020 support.capitasoftware.com is their customer support portal, it looks like they are migrating to a new system over there, yesterday I could log calls in mycapita today its pointing me to there 1
MrMat Posted January 21, 2020 Posted January 21, 2020 I got one to that was addressed to ~100 recipients My boss got one that was addressed to ~100 different recipients Our public enquiry mailbox got one that was addressed to ~100 different recipients again Someone did an oops. Yup, same here! 3 of us just checked and exactly the same. We're a team of 12, so that's 1188 exposed email address sent to us! Ohhhhh dear Capita.
Popular Post IrritableTech Posted January 21, 2020 Popular Post Posted January 21, 2020 Steve Ainsley here, has anyone seen my call?! Anyone up for printing 'I'm Steve Ainsley' t-shirts for Bett this week? 10
DJ-1701 Posted January 21, 2020 Posted January 21, 2020 Anyone up for printing 'I'm Steve Ainsley' t-shirts for Bett this week? Wouldn't it be cheaper just to get that name for their BETT badges for Capita to scan? 2
DrCheese Posted January 21, 2020 Posted January 21, 2020 Just in time for BETT haha, they're hiding again this year. Just as well!
Popular Post SpaceInvader83 Posted January 21, 2020 Popular Post Posted January 21, 2020 Anyone up for printing 'I'm Steve Ainsley' t-shirts for Bett this week? hahaha 11
atcoates Posted January 21, 2020 Posted January 21, 2020 All my schools got this today. Someone clicked the box and it sent them through to a Google page to log in with their Google credentials. 100% a phishing scam. 1
MrMat Posted January 21, 2020 Posted January 21, 2020 hahaha [ATTACH=CONFIG]56424[/ATTACH] Ohhh we definitely need these printing for the next User Group!! 1
supportman Posted January 21, 2020 Posted January 21, 2020 All my schools got this today. Someone clicked the box and it sent them through to a Google page to log in with their Google credentials. 100% a phishing scam. Does that mean Supportnet has been hacked?
atcoates Posted January 21, 2020 Posted January 21, 2020 Our user was prompted for a password change when they clicked it. 1
synaesthesia Posted January 21, 2020 Posted January 21, 2020 (edited) All my schools got this today. Someone clicked the box and it sent them through to a Google page to log in with their Google credentials. 100% a phishing scam. Odd - took us to the My Account login page (real one) when testing. Are we all getting the same link - did the URL or a forwarder change at a certain time or amount of clicks? Edited January 21, 2020 by synaesthesia
SpaceInvader83 Posted January 21, 2020 Posted January 21, 2020 Odd - took us to the My Account login page (real one) when testing. Are we all getting the same link - did the URL or a forwarder change at a certain time or amount of clicks? Same here.
atcoates Posted January 21, 2020 Posted January 21, 2020 Information my user gave me was, they clicked the link, that took them to a google page that then asked for a sign and then a password change. They might have some of info mixed up but it looks similar to the blue box emails from last year with a very vague message. Add in the fact they've emailed 100 people at a time at intervals exposing the addresses etc. INC0017274 - BUG 60401 An incident has been assigned to DO NOT USE. Additional Details: Caller: Steve Ainsley Category: Inquiry / Help Severity: 3 - Low Priority: 3 - Moderate You can view all the details of the incident by following the link below: Take me to the Incident (DODGY BLUE BOX) Thank you. Ref:MSG0347706_E6GdnmRo280qtRVUR4N8
MrMat Posted January 21, 2020 Posted January 21, 2020 Information my user gave me was, they clicked the link, that took them to a google page that then asked for a sign and then a password change. They might have some of info mixed up but it looks similar to the blue box emails from last year with a very vague message. Add in the fact they've emailed 100 people at a time at intervals exposing the addresses etc. INC0017274 - BUG 60401 An incident has been assigned to DO NOT USE. Additional Details: Caller: Steve Ainsley Category: Inquiry / Help Severity: 3 - Low Priority: 3 - Moderate You can view all the details of the incident by following the link below: Take me to the Incident (DODGY BLUE BOX) Thank you. Ref:MSG0347706_E6GdnmRo280qtRVUR4N8 SIMS ID perhaps? Using Google Login?
synaesthesia Posted January 21, 2020 Posted January 21, 2020 Same email, but nothing about Google here. The incident link we have is https://support.capitasoftware.com/incident.do?sys_id=7773d960dbe60450003c4872ba96194c&sysparm_stack=incident_list.do?sysparm_query=active=true The code all looks correct, all forwarding and scripts as they should be.
CHiLL Posted January 21, 2020 Posted January 21, 2020 When I click the button it takes me to a Capita software services login page, powered by ServiceNow.
JRowley Posted January 21, 2020 Posted January 21, 2020 ServiceNow are their new helpdesk provider, they've been merging all of their separate ones (26 in all I believe) into one mega helpdesk.
FragglePete Posted January 21, 2020 Posted January 21, 2020 I got it too - couple of staff members did then ask the question .... is it dodgy? I said, "Yes, it's from Capita....." Lol Pete
DrCheese Posted January 21, 2020 Posted January 21, 2020 All my schools got this today. Someone clicked the box and it sent them through to a Google page to log in with their Google credentials. 100% a phishing scam. Are you sure? If that's the case it's somewhat scary that someone has got access to all these email addresses, that could have only come from Capita
jthompson Posted January 21, 2020 Posted January 21, 2020 Got it here, too. The email doesn't look phishy to me. It seems genuine in that it does seem to have come from Capita's new support system. It's the bit where the incident was assigned to a group named "DO NOT USE", a group that seemingly includes all client users, that suggests an internal snafu. Perhaps it's happened whilst they were doing some migration work from the old MyAccount system to the new Capita Software Support system.
MrMat Posted January 21, 2020 Posted January 21, 2020 GDPR isn't my strong point but, surely this is considered a data breach under GDPR? As email addresses are considered as Personal Data?
synaesthesia Posted January 21, 2020 Posted January 21, 2020 Depends on the format of the addresses, [email protected] for instance would be full personal data and could be used to locate a person to a place of employment, in itself dangerous. They're in for a fine (or do Capita do the fining on ICO's behalf? How'd that work? )
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now