The Rolex Forums   The Rolex Watch

ROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEX


Go Back   Rolex Forums - Rolex Watch Forum > Classifieds > WatchOut!!!

Reply
 
Thread Tools Display Modes
Old 5 October 2019, 07:13 AM   #1
Aututto
Banned
 
Join Date: Jun 2014
Location: USA
Posts: 126
Be cautious of Aututto messages

Hello all,

It appears my account was hacked sometime around the beginning of September and has been used in a few instances that I know of to complete a scam. Most recent was a hacked account on timezone (jhmessing) which stated me as a reference, the the hacker used my account here to send messages to a user reaching out stating that the account on timezone was valid. Pretty elaborate! I have been told the scammer tries to deal through email and not pm or phone.

I have notified TRF admins, but in the meantime be cautious of strange messages demanding email communication from my account. Hopefully this is fixed soon.

I also have promptly changed my password.
Aututto is offline   Reply With Quote
Old 5 October 2019, 07:25 AM   #2
Welshwatchman
"TRF" Member
 
Welshwatchman's Avatar
 
Join Date: Apr 2006
Real Name: Paul
Location: Wales, UK
Posts: 14,578
Quote:
Originally Posted by Aututto View Post
Hello all,

It appears my account was hacked sometime around the beginning of September and has been used in a few instances that I know of to complete a scam. Most recent was a hacked account on timezone (jhmessing) which stated me as a reference, the the hacker used my account here to send messages to a user reaching out stating that the account on timezone was valid. Pretty elaborate! I have been told the scammer tries to deal through email and not pm or phone.

I have notified TRF admins, but in the meantime be cautious of strange messages demanding email communication from my account. Hopefully this is fixed soon.

I also have promptly changed my password.
Fixed how?

Also, it is likely that you clicked a phishing link and gave up your password.

Please don't list anything for sale for at least 3 months else a mod may ban the account pending proof of identity. All we have is your word that you reset your password.
__________________
..33
Welshwatchman is offline   Reply With Quote
Old 5 October 2019, 07:46 AM   #3
Aututto
Banned
 
Join Date: Jun 2014
Location: USA
Posts: 126
Quote:
Originally Posted by Welshwatchman View Post
Fixed how?



Also, it is likely that you clicked a phishing link and gave up your password.



Please don't list anything for sale for at least 3 months else a mod may ban the account pending proof of identity. All we have is your word that you reset your password.


I’m not sure how that’s why I reached out to the admins about this.

I never clicked a link giving up my password ever which is what baffles me. I’m a systems engineer so I’m well aware of internet safety and potential scams to steal a password.

Luckily I have nothing I plan to sell at all so you should not see any FS listings from me. My recent sale and feedback from ZoJaJ regarding the 114270 is the only legit sale completed here.


Sent from my iPhone using Tapatalk
Aututto is offline   Reply With Quote
Old 5 October 2019, 09:11 AM   #4
77T
2024 Pledge Member
 
77T's Avatar
 
Join Date: Dec 2010
Real Name: PaulG
Location: Georgia
Posts: 40,574
What other online passwords were lifted? If the TRF uid was compromised, many others would likely have gone out the door too.


Sent from my iPhone using Tapatalk Pro
__________________


Does anyone really know what time it is?
77T is offline   Reply With Quote
Old 5 October 2019, 11:32 AM   #5
GLADIATOR
"TRF" Member
 
GLADIATOR's Avatar
 
Join Date: Mar 2010
Real Name: Adam
Location: Costa Blanca,
Watch: YMII,GMTII,DAYTONA
Posts: 5,288
Quote:
Originally Posted by Aututto View Post
Hello all,

It appears my account was hacked sometime around the beginning of September and has been used in a few instances that I know of to complete a scam. Most recent was a hacked account on timezone (jhmessing) which stated me as a reference, the the hacker used my account here to send messages to a user reaching out stating that the account on timezone was valid. Pretty elaborate! I have been told the scammer tries to deal through email and not pm or phone.

I have notified TRF admins, but in the meantime be cautious of strange messages demanding email communication from my account. Hopefully this is fixed soon.

I also have promptly changed my password.
"promptly"
Seems about 1 month??
__________________
The truth is incontrovertible. Malice may attack it, ignorance may deride it, but in the end, there it is. Winston Churchill
"We judge ourselves by what we feel capable of doing, while others judge us by what we have already done."
GLADIATOR is offline   Reply With Quote
Old 5 October 2019, 11:34 AM   #6
GLADIATOR
"TRF" Member
 
GLADIATOR's Avatar
 
Join Date: Mar 2010
Real Name: Adam
Location: Costa Blanca,
Watch: YMII,GMTII,DAYTONA
Posts: 5,288
Quote:
Originally Posted by 77T View Post
What other online passwords were lifted? If the TRF uid was compromised, many others would likely have gone out the door too.


Sent from my iPhone using Tapatalk Pro
Maybe all sellers passwords must be changed quarterly and all members yearly??
__________________
The truth is incontrovertible. Malice may attack it, ignorance may deride it, but in the end, there it is. Winston Churchill
"We judge ourselves by what we feel capable of doing, while others judge us by what we have already done."
GLADIATOR is offline   Reply With Quote
Old 5 October 2019, 11:39 AM   #7
77T
2024 Pledge Member
 
77T's Avatar
 
Join Date: Dec 2010
Real Name: PaulG
Location: Georgia
Posts: 40,574
Quote:
Originally Posted by GLADIATOR View Post
Maybe all sellers passwords must be changed quarterly and all members yearly??


I wouldn’t suggest that. It would punish the 99.9% of users for the 0.1%...

Plus, the increased “help me” admin requests could overwhelm the Mods.


Sent from my iPhone using Tapatalk Pro
__________________


Does anyone really know what time it is?
77T is offline   Reply With Quote
Old 5 October 2019, 11:51 AM   #8
Aututto
Banned
 
Join Date: Jun 2014
Location: USA
Posts: 126
Quote:
Originally Posted by GLADIATOR View Post
"promptly"

Seems about 1 month??


Ha ha yes I realize how that sounds now. I was a bit flustered earlier when I found out about all this. I actually got a PM from a user today who was verifying the time zone account. That’s when I found out about my account being used. I then went to my profile and saw some visitor messages on my page from the beginning of september that were deleted. That’s when I realized about how far back it went.


Sent from my iPhone using Tapatalk
Aututto is offline   Reply With Quote
Old 5 October 2019, 11:56 AM   #9
Aututto
Banned
 
Join Date: Jun 2014
Location: USA
Posts: 126
Quote:
Originally Posted by 77T View Post
I wouldn’t suggest that. It would punish the 99.9% of users for the 0.1%...

Plus, the increased “help me” admin requests could overwhelm the Mods.


Sent from my iPhone using Tapatalk Pro


I agree. I think this is a pretty rare case. And from what I’m seeing pretty elaborate compared to the typical TZ scams I’ve seen with stolen images and slightly changed email names. I think this is the first I’ve heard of someone fronting a TRF account.

Weirdly they didn’t use my account as a seller at all. But told people I was a reference on their fake listings at TZ.


Sent from my iPhone using Tapatalk
Aututto is offline   Reply With Quote
Old 5 October 2019, 02:22 PM   #10
Tony8959
"TRF" Member
 
Tony8959's Avatar
 
Join Date: Nov 2018
Location: NYC
Posts: 454
I’ve ran into something odd like this last winter after I first joined. Not with my profile but some others. I posted on the WTB that I was looking for a watch to buy (not knowing better). Received a message from a “seller” with details and some pics of the watch he had. He didn’t have many posts, maybe around 50 or so, but gave me some references on here. I reached out to them and all verified their transactions with him. We then went back and forth a bit by email, we exchanged info, but something about the way he was writing and somewhat pushy didn’t seem right. So I followed up once again with one of his references to make sure the info he gave me checked out.

This time the reference messaged me back not knowing what I was talking about. He said that wasn’t him that was communicating with me and had no prior dealings with this seller. We were both very surprised as to what had happened. I immediately told this person I was no longer transacting and notified the mods on TRF of what happened. They banned his profile.
Tony8959 is offline   Reply With Quote
Old 10 October 2019, 02:46 AM   #11
je302
"TRF" Member
 
Join Date: Jul 2012
Real Name: James
Location: FLUSA
Watch: EXPII Polar 216570
Posts: 95
I just received a message from a member called fconnection saying he is interested in a watch I am selling. Tells me to email him @ aaututto@gmail.com , ya right. Member for one day and 5 generic posts. Not sure if he is behind your hack but using your email. Is there a way to have this member banned?
je302 is offline   Reply With Quote
Old 10 October 2019, 02:56 AM   #12
MLW2865
"TRF" Member
 
Join Date: Dec 2012
Location: Kentucky
Posts: 103
Yep, just had the exact same thing on a FS thread I have. Need to ban for sure.

Sent from my SM-G975U using Tapatalk
MLW2865 is offline   Reply With Quote
Old 10 October 2019, 03:05 AM   #13
cap82
2024 Pledge Member
 
Join Date: Oct 2014
Real Name: Chris Paniewsk
Location: California
Posts: 13
Yeah I just got the same message. Included some link - I assume it’s some phishing scam.
cap82 is offline   Reply With Quote
Old 10 October 2019, 03:08 AM   #14
threefirstnames
2024 Pledge Member
 
threefirstnames's Avatar
 
Join Date: Aug 2011
Real Name: JT
Location: Venice Beach, CA
Posts: 32
Received email from aaututto@gmail.com as well regarding a FS thread I have - Email included broken link that wouldn’t resolve to a actual page (via mobile), however no PM from a user.

Beware.
threefirstnames is offline   Reply With Quote
Old 10 October 2019, 03:10 AM   #15
crashpad
"TRF" Member
 
crashpad's Avatar
 
Join Date: Aug 2019
Real Name: Dave Pruit
Location: Dallas, TX USA
Watch: Omega Speedmaster
Posts: 77
Received same scam email today as well.


Sent from my iPhone using Tapatalk
crashpad is offline   Reply With Quote
Old 10 October 2019, 03:11 AM   #16
Noonan
Banned
 
Join Date: Jul 2008
Location: US
Watch: 3570.50
Posts: 2,156
Quote:
Originally Posted by steeze View Post
Received email from aaututto@gmail.com as well regarding a FS thread I have - Email included broken link that wouldn’t resolve to a actual page (via mobile), however no PM from a user.

Beware.
Uh, if you clicked on the "broken" link, you may already be compromised.
Noonan is offline   Reply With Quote
Old 10 October 2019, 03:26 AM   #17
jerry017uk
Banned
 
Join Date: Jan 2017
Real Name: JEREMY
Location: USA
Posts: 38
I just got same message from (Aututto <aaututto@gmail.com>) asking to make purchase for my Rolex Daytona Steel Black Dial SG listed For Sale.
Sent this link as well.

Last edited by jerry017uk; 10 October 2019 at 03:31 AM.. Reason: I had to remove link so no one clicks it.
jerry017uk is offline   Reply With Quote
Old 10 October 2019, 04:03 AM   #18
jharris888
"TRF" Member
 
Join Date: Feb 2015
Location: Manassas, VA
Posts: 1,599
Same thing happened to me... someone was posing as me and giving fake reference checks to people. I never clicked any phishing links so unsure how my login was compromised. Hopefully this isn’t a bigger issue as it seems to have happened to quite a few the past month.
jharris888 is offline   Reply With Quote
Old 10 October 2019, 06:00 AM   #19
Stevoflurane
2024 Pledge Member
 
Join Date: Apr 2018
Location: USA
Posts: 166
same thing just happened to me, directed me to a phishing site that looked exactly like the forum. I unfortunately entered my password but realized what happened and changed my password within 2-3 min so hopefully no damage. It was at least a random password that I don't use for any real accounts of importance. BEWARE of emails from aaututto@gmail.com
Stevoflurane is offline   Reply With Quote
Old 10 October 2019, 10:10 AM   #20
tesmith2112
"TRF" Member
 
Join Date: Jun 2011
Location: United States
Posts: 256
Me too, got an email regarding sales thread.
tesmith2112 is offline   Reply With Quote
Old 11 October 2019, 12:47 PM   #21
Gprotein
"TRF" Member
 
Join Date: Jul 2019
Location: SoCal
Posts: 113
I warned the mod about this user account around 2 weeks ago, but only got banned days later. God knows many hacked messages went out to scam someone...
Gprotein is offline   Reply With Quote
Old 15 October 2019, 08:43 PM   #22
Ttnpt00
"TRF" Member
 
Join Date: Jul 2019
Location: Boston
Posts: 15
I went back and forth with the scammer for several messages when looking for an explorer II in September. He was very vague but responded from the forum direct messages as well as an outside email. Fortunately prices was way too good to be true and he was odd so I didn’t fall for it.
Ttnpt00 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Takuya Watches

Bobs Watches

My Watch LLC

OCWatches

DavidSW Watches

Coronet


*Banners Of The Month*
This space is provided to horological resources.





Copyright ©2004-2024, The Rolex Forums. All Rights Reserved.

ROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEXROLEX

Rolex is a registered trademark of ROLEX USA. The Rolex Forums is not affiliated with ROLEX USA in any way.