Betfair account hacking attempt

News, chat and debate about the Betfair betting exchange.
User avatar
jamesedwards
Posts: 2324
Joined: Wed Nov 21, 2018 6:16 pm

jimibt wrote:
Fri Oct 20, 2023 10:10 am
Interestingly, i haven't logged into BF for quite some time and thought I'd check to see how many attempts had been made since i last logged in earlier in the year. The answer -zero!!


last-logins.png

not sure how some folk are targeted and others not.
This is what my security screen looks like every morning...
hack 6.PNG

My next plan is to stay logged in on all my devices for a while, which means leaving my PC on 24/7.

By logging in every day I've been undertaking a forced password change which resets my account, and gives the hackers another 4 attempts to hack in. Perhaps when they find out my account is no longer being reset it might encourage them to give up.
You do not have the required permissions to view the files attached to this post.
sionascaig
Posts: 1074
Joined: Fri Nov 20, 2015 9:38 am

For what its worth, I've left BA logged in for weeks on end and no issues (on the BA side).
User avatar
Naffman
Posts: 5644
Joined: Sun Aug 11, 2013 5:46 am

jamesedwards wrote:
Fri Oct 20, 2023 1:25 pm
jimibt wrote:
Fri Oct 20, 2023 10:10 am
Interestingly, i haven't logged into BF for quite some time and thought I'd check to see how many attempts had been made since i last logged in earlier in the year. The answer -zero!!


last-logins.png

not sure how some folk are targeted and others not.
This is what my security screen looks like every morning...

hack 6.PNG


My next plan is to stay logged in on all my devices for a while, which means leaving my PC on 24/7.

By logging in every day I've been undertaking a forced password change which resets my account, and gives the hackers another 4 attempts to hack in. Perhaps when they find out my account is no longer being reset it might encourage them to give up.
Shocking situation to be in when we have quite a lot of money tied up due to affordability checks.

And absolutely pathetic (but not surprising) that Betfair can’t let you change your Username when there’s clear evidence of someone trying to gain entry into your account.
User avatar
Kai
Posts: 6231
Joined: Tue Jan 20, 2015 12:21 pm

Naffman wrote:
Fri Oct 20, 2023 3:51 pm
Shocking situation to be in
Indeed

Thought perhaps the username wasn't obscure enough or something initially, but if these are consistent attacks that's a different matter entirely

Surely someone at BF should be able to assist, this can't possibly go on
User avatar
Derek27
Posts: 23682
Joined: Wed Aug 30, 2017 11:44 am
Location: UK

Naffman wrote:
Fri Oct 20, 2023 3:51 pm
Shocking situation to be in when we have quite a lot of money tied up due to affordability checks.

And absolutely pathetic (but not surprising) that Betfair can’t let you change your Username when there’s clear evidence of someone trying to gain entry into your account.
I'm guessing the reason why you can't change your username would be because the system won't allow it. Perhaps the username defines your account and it can only be changed with a new account. I've just looked for my Betfair account number, can't find it but I'm sure I've seen one before.
Screenshot 2023-10-20 163210.png
Can't for the life of me understand why using a username that can't be changed makes your account more secure.
You do not have the required permissions to view the files attached to this post.
foxwood
Posts: 394
Joined: Mon Jul 23, 2012 2:54 pm

jamesedwards wrote:
Fri Oct 20, 2023 1:25 pm
This is what my security screen looks like every morning...
Looking up those IP addresses they come from :

TalkTalk
BT
Cogent Communications Inc
Sky UK

Since it has started up again and they are all different providers I'm guessing you might be on a list that's passed around - unless it's one hacker with accounts at all these providers.

The hacks will prob continue while you stay logged in 24/7 - not sure of the consequences of that ?
User avatar
Derek27
Posts: 23682
Joined: Wed Aug 30, 2017 11:44 am
Location: UK

jamesedwards wrote:
Fri Oct 20, 2023 1:25 pm
My next plan is to stay logged in on all my devices for a while, which means leaving my PC on 24/7.
I recall when I had problems with a hacker I was logged out of Betfair after several login attempts. But if you want to remain logged in, you don't need to leave your devices running 24/7. Hibernating the machine maintains logins as though you haven't switched it off.
User avatar
jamesedwards
Posts: 2324
Joined: Wed Nov 21, 2018 6:16 pm

Derek27 wrote:
Fri Oct 20, 2023 7:17 pm
jamesedwards wrote:
Fri Oct 20, 2023 1:25 pm
My next plan is to stay logged in on all my devices for a while, which means leaving my PC on 24/7.
I recall when I had problems with a hacker I was logged out of Betfair after several login attempts. But if you want to remain logged in, you don't need to leave your devices running 24/7. Hibernating the machine maintains logins as though you haven't switched it off.
Thanks for that info. Will try hibernating, saves strain on my main PC plus the cost of power etc.
User avatar
jamesedwards
Posts: 2324
Joined: Wed Nov 21, 2018 6:16 pm

foxwood wrote:
Fri Oct 20, 2023 7:08 pm
jamesedwards wrote:
Fri Oct 20, 2023 1:25 pm
This is what my security screen looks like every morning...
Looking up those IP addresses they come from :

TalkTalk
BT
Cogent Communications Inc
Sky UK

Since it has started up again and they are all different providers I'm guessing you might be on a list that's passed around - unless it's one hacker with accounts at all these providers.

The hacks will prob continue while you stay logged in 24/7 - not sure of the consequences of that ?
Despite the different IPs, I assume they originate from the same place because they always come as a set group within the space of a couple of hours.

The benefit of me of staying logged in is once they reach a max of 4 attempts they can't continue attempts until I go through the forced password reset process. If I don't log in then I'm never resetting my account.
User avatar
jamesedwards
Posts: 2324
Joined: Wed Nov 21, 2018 6:16 pm

So I contacted Betfair and they weren't able to offer any solutions to block these hacking attempts.

I received a generic email from their Security team which stated they have checked my account and have not been able to identify any successful suspicious logins. They advised me to take the following steps, all of which I have done already;
> Change email address.
> Refrain from using your email address as your username.
> Select a password with combination of digits, upper-case, and symbols.
> Switch on 2FA.

They confirmed it is not possible to set-up a whitelist or blacklist of IPs, and not possible to change my username.

They also kindly slipped in a note saying they would not be able to guarantee a refund "should this instance re-occur". :roll:
User avatar
Naffman
Posts: 5644
Joined: Sun Aug 11, 2013 5:46 am

jamesedwards wrote:
Fri Oct 20, 2023 7:51 pm
So I contacted Betfair and they weren't able to offer any solutions to block these hacking attempts.

I received a generic email from their Security team which stated they have checked my account and have not been able to identify any successful suspicious logins. They advised me to take the following steps, all of which I have done already;
> Change email address.
> Refrain from using your email address as your username.
> Select a password with combination of digits, upper-case, and symbols.
> Switch on 2FA.

They confirmed it is not possible to set-up a whitelist or blacklist of IPs, and not possible to change my username.

They also kindly slipped in a note saying they would not be able to guarantee a refund "should this instance re-occur". :roll:
So they can't do anything until someone withdraws all of your money :roll:
User avatar
LeTiss
Posts: 5386
Joined: Fri May 08, 2009 6:04 pm

Just out of interest James....do you bank online with the same device as you trade? Have you noticed any issues there? I'm wondering if you have a nasty little virus/Malware on your device, and it's targeting all of your accounts, not just Betfair
User avatar
jamesedwards
Posts: 2324
Joined: Wed Nov 21, 2018 6:16 pm

LeTiss wrote:
Sat Oct 21, 2023 7:20 am
Just out of interest James....do you bank online with the same device as you trade? Have you noticed any issues there? I'm wondering if you have a nasty little virus/Malware on your device, and it's targeting all of your accounts, not just Betfair
Thanks for the thought. I've had no other problems with any other accounts, just Betfair. I will run a full Defender virus scan just in case.
User avatar
jamesedwards
Posts: 2324
Joined: Wed Nov 21, 2018 6:16 pm

jamesedwards wrote:
Fri Oct 20, 2023 7:51 pm
So I contacted Betfair and they weren't able to offer any solutions to block these hacking attempts.

I received a generic email from their Security team which stated they have checked my account and have not been able to identify any successful suspicious logins. They advised me to take the following steps, all of which I have done already;
> Change email address.
> Refrain from using your email address as your username.
> Select a password with combination of digits, upper-case, and symbols.
> Switch on 2FA.

They confirmed it is not possible to set-up a whitelist or blacklist of IPs, and not possible to change my username.

They also kindly slipped in a note saying they would not be able to guarantee a refund "should this instance re-occur". :roll:
I guess it can only be coincidence :?:, but there have been no further hacking attempts since I raised the issue with Betfair security team on Friday. :?
User avatar
Kai
Posts: 6231
Joined: Tue Jan 20, 2015 12:21 pm

jamesedwards wrote:
Mon Oct 23, 2023 12:44 pm
jamesedwards wrote:
Fri Oct 20, 2023 7:51 pm
So I contacted Betfair and they weren't able to offer any solutions to block these hacking attempts.

I received a generic email from their Security team which stated they have checked my account and have not been able to identify any successful suspicious logins. They advised me to take the following steps, all of which I have done already;
> Change email address.
> Refrain from using your email address as your username.
> Select a password with combination of digits, upper-case, and symbols.
> Switch on 2FA.

They confirmed it is not possible to set-up a whitelist or blacklist of IPs, and not possible to change my username.

They also kindly slipped in a note saying they would not be able to guarantee a refund "should this instance re-occur". :roll:
I guess it can only be coincidence :?:, but there have been no further hacking attempts since I raised the issue with Betfair security team on Friday. :?
You can tell these hackers would make lousy traders and why they probably failed at it themselves, they have zero persistence and determination.

But that's good to hear James 👍
Post Reply

Return to “Betfair exchange”