My email address stolen from Launchpad

Asked by Martin Kealey

I use a different email address for every service that I log into, and a few days ago I began receiving spam to the one I created for Launchpad.

(As I have not logged into Launchpad (or UbuntuOne) for over a year before today, it seems unlikely that this would be in any way related to my own activities. It also seems unlikely that someone could have "guessed" the address in question.)

Is this part of a bulk exfiltration, or is there some minor leakage of a few addresses?

I will terminate the email address as soon as your investigation is completed.

Question information

Language:
English Edit question
Status:
Expired
For:
Launchpad itself Edit question
Assignee:
No assignee Edit question
Last query:
Last reply:
Revision history for this message
Martin Kealey (from-launchpad-kurahaupo) said :
#1

This does not appear to be primarily an issue with login.ubuntuone.com, as my other UbuntuOne identities have not received any spam. I will let you know if this changes.

Revision history for this message
Colin Watson (cjwatson) said :
#2

We're not aware of a bulk exfiltration, and there's much higher-value stuff in the Launchpad database than email addresses, so if somebody had exfiltrated the database then I would expect other attacks to become obvious first.

I doubt we're going to be able to figure out very much retrospectively, but just in case, are you able to email me full headers of an example message?

Revision history for this message
Martin Kealey (from-launchpad-kurahaupo) said :
#3

Sorry, this has been going on a lot longer than "the last few days", but only recently have they been leaking through my spam filter. The earliest example I could find was almost 2 years ago.
I'll send you some headers privately.

Revision history for this message
Jürgen Gmach (jugmac00) said :
#4

Waiting for Colin to receive the email and decide what would be the next steps.

Revision history for this message
Martin Kealey (from-launchpad-kurahaupo) said :
#5

Details were sent via https://launchpad.net/~cjwatson/+contactuser

I've recently changed my contact address for launchpad,so in view of my long delay reporting this, I do not personally require a response, but I'm happy to help if you feel the need to investigate.

My address was <email address hidden>

Revision history for this message
Samuel David (sdavid-088) said (last edit ):
#6

Through the faceitfinder, players can check their faceit stats within seconds.
https://faceitaccount.com/

Revision history for this message
Launchpad Janitor (janitor) said :
#7

This question was expired because it remained in the 'Needs information' state without activity for the last 15 days.