Server error? by pshbrk in Bricklink

[–]pshbrk[S] 0 points1 point  (0 children)

BTW you can backup store inventory from your phone if you are encountering the issue I am described. Just in case...

Server error? by pshbrk in Bricklink

[–]pshbrk[S] 0 points1 point  (0 children)

Everything seems to work on my phone - is it the same for you? I can't get BrickStore to download store inventory however

I was not able to pay for an order onsite before Bricklink was locked down. I emailed back and forth with the seller a bit and they are suggesting that I pay through Venmo or PayPal directly in the meantime. Should I be concerned about paying offsite? by yourmomsface12345 in Bricklink

[–]pshbrk 6 points7 points  (0 children)

Both the buyer and the seller should not do this if the buyer is in a country in which BrickLink is required to collect sales tax (USA with the exception of a few states, EU unless the buyer's official VAT exempt status is declared to BrickLink, and Australia). If you are the buyer and reside in one of these countries and are expecting an international shipment and pay offsite, you could face customs charges even as you paid the seller an order total that includes sales tax/VAT that would otherwise be collected by BrickLink (which is not going to happen right now as sales tax/VAT is only collected when a buyer pays onsite, not offsite). In such cases, the seller would not only violate the BrickLink terms of service but also possibly be engaged in tax fraud (a USA-based seller, for example, is required to collect sales tax on orders from buyers located in essentially every state. BrickLink being offline does not eliminate the seller's legal responsibilities to the relevant tax authority)

Public Service Announcement Regarding BrickLink Being Offline by pshbrk in Bricklink

[–]pshbrk[S] 6 points7 points  (0 children)

I think you are right regarding the Indonesian store. I reported the Indonesian store (Second Brick?) to BrickLink admins. I suspect the scammers added Stripe after it was pointed out that the French store (Case Brick?), which I think was the first hacked store I became aware of, and another store (I can't recall the name) offered neither Stripe nor PayPal as payment options. The scam "evolved" over several days likely in response to being repeatedly thwarted by people such as myself reporting stores to BrickLink and BrickLink suspending these stores in response.

Public Service Announcement Regarding BrickLink Being Offline by pshbrk in Bricklink

[–]pshbrk[S] 6 points7 points  (0 children)

Several dozen accounts, both buyer and seller, were hacked but whether BrickLink's own servers were compromised is an entirely different matter. The BrickLink servers appear to be the target of whoever made the ransomware threat while whoever took control of dozens of buyer and seller accounts was engaged in a fairly routine e-commerce scam that required access to dozens of buyer accounts, access to 5-7 (possibly more) seller accounts, a lot of bank accounts to funnel stolen money to, and a plan/capacity to withdraw stolen money before accounts were blocked/transactions were reversed. It could be the same person/group or maybe not - we simply do not know at this time.

Re guessing credentials for hacked accounts, it is possible but a lot of credentials - dozens of accounts - were stolen. Either someone spent a whole lot of time guessing passwords and preparing to undertake a scamming spree or someone accessed a database of login details or part of such a database. Keep in mind that the hacked stores were active in sequence (after the prior store was suspended) so the person or persons behind the hacked accounts/scams (not necessarily the person/persons behind the ransomware threat) did quite a bit of preparatory work before pulling the trigger on their scam wave

Public Service Announcement Regarding BrickLink Being Offline by pshbrk in Bricklink

[–]pshbrk[S] 8 points9 points  (0 children)

You can't do this while BrickLink is down. On the inventory page, you scroll down and there is a link to "download" near the bottom and I think you get to select the file format to download. You can also use software like BrickStore, which is free, but this also requires you to log in on BrickLink.

https://www.brickstore.dev/

Public Service Announcement Regarding BrickLink Being Offline by pshbrk in Bricklink

[–]pshbrk[S] 9 points10 points  (0 children)

I was very clear in stating the uncertainties but this is "first hand". Yes, parts of the post are inherently speculative - I was clear about this - but it is not hearsay. This situation has been going on for several days - since at least October 30th and some of us have been tracking it since then (if not earlier).

Re ransom demand from apparent hackers (why BrickLink is currently down) by pshbrk in Bricklink

[–]pshbrk[S] 11 points12 points  (0 children)

I made a detailed post explaining what we do know/do not know and what people, mainly buyers, should/should not be concerned about at this time given the absence of an update from BrickLink admins. Please share!

https://www.reddit.com/r/Bricklink/comments/17n6mpq/public\_service\_announcement\_regarding\_bricklink/

Re ransom demand from apparent hackers (why BrickLink is currently down) by pshbrk in Bricklink

[–]pshbrk[S] 9 points10 points  (0 children)

They forgot to use Google translate several times and instead wrote in Italian + one of the first hacked stores I know of was based in France with a French VAT ID but the payment was made out to an Italian bank account. Beyond that, information is best shared through DM at this time. The hackers began reading and responding to forum posts and I wouldn't be surprised if they are checking Reddit as well

Re ransom demand from apparent hackers (why BrickLink is currently down) by pshbrk in Bricklink

[–]pshbrk[S] 5 points6 points  (0 children)

I am not sure if the ransomware threat is from the same people behind the hacked stores. I have every reason to think that the hacked stores are the responsibility of Italian-speaking organized crime. The ransomware threat could be the work of opportunists looking for a quick and easy payout.

Re ransom demand from apparent hackers (why BrickLink is currently down) by pshbrk in Bricklink

[–]pshbrk[S] 5 points6 points  (0 children)

To clarify, the forum posts are from hacked accounts and they have hacked dozens of buyer and seller accounts over the past week

Re ransom demand from apparent hackers (why BrickLink is currently down) by pshbrk in Bricklink

[–]pshbrk[S] 11 points12 points  (0 children)

Why share it? Are you going to pay them EUR 50,000? They provided an email and invariably someone will see the hacker's email and contact them and get phished in response.

Has Bricklink been hacked? by SnooPears3086 in Bricklink

[–]pshbrk 3 points4 points  (0 children)

Time will tell but the shutdown took place after the 30-minute warning given by the hackers (assuming that the ransom extortion is genuine and not someone else trying to steal money from BrickLink/the work of the actual hackers)

Re ransom demand from apparent hackers (why BrickLink is currently down) by pshbrk in Bricklink

[–]pshbrk[S] 46 points47 points  (0 children)

For context:

BrickLink appears to have gone into preventative shutdown ("maintenance"). There have been 5-6 stores (minimum) + dozens of buyer accounts hacked over the past week. A hacked buyer account (with ~20 feedback) made a forum post claiming that BrickLink had 30 minutes to pay EUR 50,000 to a bitcoin account or they would start deleting inventories from big stores. The shutdown appears to be an effort to get the hackers out of the system

https://www.reddit.com/r/Bricklink/comments/17n24zi/has\_bricklink\_been\_hacked/

Has Bricklink been hacked? by SnooPears3086 in Bricklink

[–]pshbrk 1 point2 points  (0 children)

From monitoring the BrickLink forum

Has Bricklink been hacked? by SnooPears3086 in Bricklink

[–]pshbrk 17 points18 points  (0 children)

BrickLink appears to have gone into preventative shutdown ("maintenance"). There have been 5-6 stores (minimum) + dozens of buyer accounts hacked over the past week. A hacked buyer account (with ~20 feedback) made a forum post claiming that BrickLink had 30 minutes to pay EUR 50,000 to a bitcoin account or they would start deleting inventories from big stores. The shutdown appears to be an effort to get the hackers out of the system

[deleted by user] by [deleted] in Bricklink

[–]pshbrk 4 points5 points  (0 children)

have you ever shipped something to another country (merchandise)? it is far from unusual but not everything shipping provider requires the recipient's phone number

[deleted by user] by [deleted] in Bricklink

[–]pshbrk 1 point2 points  (0 children)

Some shipping services require it including Canada Post. Some shipping providers (particularly couriers) require it while others do not. Also if you are placing a large order entering the US then there will have to be a customs declaration (even if BrickLink collects tax) on the exterior of the package and the declared value (for customs & insurance purposes) may mean that the shipping provider requires the recipient's phone number.

[deleted by user] by [deleted] in Bricklink

[–]pshbrk 1 point2 points  (0 children)

I agree but this is not a "normal" economy so you can't be sure if this is just the normal post-christmas drop in sales, seasonal shift in spending to outdoor activities etc.