Helpful ReplyAccount hacked?

Author
1andyf88
Max Output Level: -90 dBFS
  • Total Posts : 46
  • Joined: 2014/12/31 11:55:37
  • Status: offline
2016/03/07 16:33:13 (permalink)

Account hacked?

I've been getting random notices over the last few weeks that an attempt was made to change my password to my cakewalk account. Today I received notification that my password was changed. I did not initiate this. I was able to log on with the new password and change it again. Has anyone else had this issue?

Intel i7, 12g tri channel ram, 1.5 T disk, too many softsynths and plug-ins
#1
Leadfoot
Max Output Level: -47 dBFS
  • Total Posts : 2817
  • Joined: 2011/04/26 11:08:38
  • Location: Indiana
  • Status: offline
Re: Account hacked? 2016/03/07 16:34:48 (permalink)
That's weird.... I haven't received anything.
#2
Jeff M.
Max Output Level: -80 dBFS
  • Total Posts : 541
  • Joined: 2012/09/22 03:02:04
  • Location: RI, USA
  • Status: offline
Re: Account hacked? 2016/03/07 16:37:04 (permalink)
I haven't received any notifications, either.
 

Platinum 64
RME UCX | Studio Cat Platinum: i7 2700k @ 4.5Ghz | 16Gb DDR3 | Win 7 64
Komplete Kontrol S61
Gibson, Jackson, Parker, Suhr, Breedlove, Taylor, Lakland, Peavey, Marshall, Kemper
#3
1andyf88
Max Output Level: -90 dBFS
  • Total Posts : 46
  • Joined: 2014/12/31 11:55:37
  • Status: offline
Re: Account hacked? 2016/03/07 16:39:55 (permalink)
OK, thanks. I wasn't sure if Cakewalk was doing a "maintenance" update or something requiring a new password reset. If not, logic would then seem to lead to someone trying to access my account. Curious.

Intel i7, 12g tri channel ram, 1.5 T disk, too many softsynths and plug-ins
#4
1andyf88
Max Output Level: -90 dBFS
  • Total Posts : 46
  • Joined: 2014/12/31 11:55:37
  • Status: offline
Re: Account hacked? 2016/03/07 16:44:23 (permalink)
This is what I received as an email. I have since changed the password twice. I never initiated a password change or reset.

Cakewalk Password Reset

Cakewalk Account Management
to me
18 minutes agoDetails
Hello AndyF,

Your Cakewalk password has been reset to the following: v:lE#v*5

Please sign in and change your password here: https://www.cakewalk.com/.-Account/Change-Password

If the above password is not accepted, please try typing it in manually instead of copying and pasting it.

Best Regards,
Cakewalk Account Management

Intel i7, 12g tri channel ram, 1.5 T disk, too many softsynths and plug-ins
#5
mettelus
Max Output Level: -22 dBFS
  • Total Posts : 5321
  • Joined: 2005/08/05 03:19:25
  • Location: Maryland, USA
  • Status: offline
Re: Account hacked? 2016/03/07 16:45:48 (permalink)
I would specifically ask CW about this to get closure. With the SSO setup, someone can cause you more trouble than simply impersonating you. Check your store account too and see if anything is amiss there.

ASUS ROG Maximus X Hero (Wi-Fi AC), i7-8700k, 16GB RAM, GTX-1070Ti, Win 10 Pro, Saffire PRO 24 DSP, A-300 PRO, plus numerous gadgets and gizmos that make or manipulate sound in some way.
#6
1andyf88
Max Output Level: -90 dBFS
  • Total Posts : 46
  • Joined: 2014/12/31 11:55:37
  • Status: offline
Re: Account hacked? 2016/03/07 16:52:52 (permalink)
On the phone with them now

Intel i7, 12g tri channel ram, 1.5 T disk, too many softsynths and plug-ins
#7
1andyf88
Max Output Level: -90 dBFS
  • Total Posts : 46
  • Joined: 2014/12/31 11:55:37
  • Status: offline
Re: Account hacked? 2016/03/07 17:03:56 (permalink)
Short answer, they feel their SSL is secure. Perhaps another user with a similar user name accidently entered their information erroneously and it was sent to my email. I will say my wait time was less than a minute to get through.

Intel i7, 12g tri channel ram, 1.5 T disk, too many softsynths and plug-ins
#8
John
Forum Host
  • Total Posts : 30467
  • Joined: 2003/11/06 11:53:17
  • Status: offline
Re: Account hacked? 2016/03/07 17:07:19 (permalink)
I have gotten the same emails and told a CW person about it with no action taken. Nor did I get a good answer about it. I have since just ignored those emails. I have had no trouble in logging on. I don't know where they are coming from but I wish CW would respond with something concrete.  

Best
John
#9
Paul P
Max Output Level: -48.5 dBFS
  • Total Posts : 2685
  • Joined: 2012/12/08 17:15:47
  • Location: Montreal
  • Status: offline
Re: Account hacked? 2016/03/07 17:35:17 (permalink)
John
I don't know where they are coming from but I wish CW would respond with something concrete.  



I hope the Cakewalk accounts are secure.  While trying to authorize a free plugin, I recently got access to account product lists and their serial numbers for as many accounts as I cared to try over at iZotope (all while failing to update my own account).

Sonar Platinum [2017.10], Win7U x64 sp1, Xeon E5-1620 3.6 GHz, Asus P9X79WS, 16 GB ECC, 128gb SSD, HD7950, Mackie Blackjack
#10
John
Forum Host
  • Total Posts : 30467
  • Joined: 2003/11/06 11:53:17
  • Status: offline
Re: Account hacked? 2016/03/07 17:46:35 (permalink)
Paul P
John
I don't know where they are coming from but I wish CW would respond with something concrete.  



I hope the Cakewalk accounts are secure.  While trying to authorize a free plugin, I recently got access to account product lists and their serial numbers for as many accounts as I cared to try over at iZotope (all while failing to update my own account).


Right. Its very disconcerting. I don't think it would hurt if we all made a group protest about it. It needs to be dealt with. Or at the least we need to be reassured. 

Best
John
#11
Karyn
Ma-Ma
  • Total Posts : 9200
  • Joined: 2009/01/30 08:03:10
  • Location: Lincoln, England.
  • Status: offline
Re: Account hacked? 2016/03/07 17:50:55 (permalink)
1andyf88
Your Cakewalk password has been reset to the following: v:lE#v*5

Please sign in and change your password here: https://www.cakewalk.com/.-Account/Change-Password

That sort of message (from any web site) is usually the result of pressing the "I forgot my password" button.
 

Mekashi Futo
Get 10% off all Waves plugins.
Current DAW.  i7-950, Gigabyte EX58-UD5, 12Gb RAM, 1Tb SSD, 2x2Tb HDD, nVidia GTX 260, Antec 1000W psu, Win7 64bit, Studio 192, Digimax FS, KRK RP8G2, Sonar Platinum

#12
Ryan Munnis [Cakewalk]
Administrator
  • Total Posts : 1067
  • Joined: 2009/11/01 10:28:44
  • Status: offline
Re: Account hacked? 2016/03/07 18:00:03 (permalink) ☄ Helpfulby mettelus 2016/03/07 18:55:44
There are only two ways an account password is reset and that email is triggered.
 
1) someone clicks the one-time link generated and sent to your email address. Example:
 
Hello Ryan Munnis [Cakewalk], 

A request to reset your Cakewalk Account password has been made. To reset your password, please click the following link: 
 
[Link]

If you did not request to reset your password please discard this message. 

Best Regards, 
Cakewalk Account Management
 
2) someone on Cakewalk Support Staff does it at the request of a user
 
With that being the case, my suspicion is either Cakewalk Support Staff (I'll follow up internally), or that someone has access to your email. I'd reset your passwords for both your Cakewalk Account and Email Account (as well as disable any Email Clients / portable devices, etc. that may have access to your email address).
 
BTW John, I believe we may have discussed before, but given how common "John" is for a name, my suspicion is many people attempt to reset their account password pre-emptively by entering "John". As mentioned above, however, they cannot reset your password, only create a request to reset.

Ryan Munnis
Cakewalk
#13
mettelus
Max Output Level: -22 dBFS
  • Total Posts : 5321
  • Joined: 2005/08/05 03:19:25
  • Location: Maryland, USA
  • Status: offline
Re: Account hacked? 2016/03/07 18:10:41 (permalink)
Quick question... If I say I forgot my password does it ask me for my email, or just user name? If just user name, I can see this almost getting abused.

ASUS ROG Maximus X Hero (Wi-Fi AC), i7-8700k, 16GB RAM, GTX-1070Ti, Win 10 Pro, Saffire PRO 24 DSP, A-300 PRO, plus numerous gadgets and gizmos that make or manipulate sound in some way.
#14
Ryan Munnis [Cakewalk]
Administrator
  • Total Posts : 1067
  • Joined: 2009/11/01 10:28:44
  • Status: offline
Re: Account hacked? 2016/03/07 18:14:52 (permalink) ☄ Helpfulby mettelus 2016/03/07 18:55:48
It asks for either (by extremely popular demand of people who forget one or the other).

I followed up internally and it looks like one of our support reps did indeed initiate this and has an open email thread with the OP. Looks like there was some miscommunication.

Ryan Munnis
Cakewalk
#15
1andyf88
Max Output Level: -90 dBFS
  • Total Posts : 46
  • Joined: 2014/12/31 11:55:37
  • Status: offline
Re: Account hacked? 2016/03/07 18:23:14 (permalink)
Thanks Ryan. I did indeed, after receiving the email, change the account password and my user name,.I have also changed my email password. I however do not have an open email thread with anyone. I did not initiate a change password request. This email just showed up in my mailbox. At any rate, I can't complain about Cakewalk fast response to this, both on the way hone and here in the forum. We shall see if the above changes solve the problem.
post edited by 1andyf88 - 2016/03/07 19:05:01

Intel i7, 12g tri channel ram, 1.5 T disk, too many softsynths and plug-ins
#16
John
Forum Host
  • Total Posts : 30467
  • Joined: 2003/11/06 11:53:17
  • Status: offline
Re: Account hacked? 2016/03/07 18:53:45 (permalink)
Ryan Munnis [Cakewalk]
There are only two ways an account password is reset and that email is triggered.
 
1) someone clicks the one-time link generated and sent to your email address. Example:
 
Hello Ryan Munnis [Cakewalk], 

A request to reset your Cakewalk Account password has been made. To reset your password, please click the following link: 
 
[Link]

If you did not request to reset your password please discard this message. 

Best Regards, 
Cakewalk Account Management
 
2) someone on Cakewalk Support Staff does it at the request of a user
 
With that being the case, my suspicion is either Cakewalk Support Staff (I'll follow up internally), or that someone has access to your email. I'd reset your passwords for both your Cakewalk Account and Email Account (as well as disable any Email Clients / portable devices, etc. that may have access to your email address).
 
BTW John, I believe we may have discussed before, but given how common "John" is for a name, my suspicion is many people attempt to reset their account password pre-emptively by entering "John". As mentioned above, however, they cannot reset your password, only create a request to reset.


It was me I think that brought it to your attention. I am totally happy now with your response. I don't use a log in manually. I have my browser set to automatically to log me in. Rarely do I log in myself. I'm going to watch this a little closer and try to figure out what conditions cause an email to be sent. What might be a problem is a delay in logging in and the email being sent. Though I can't be sure of this at the present time. It seems that these emails are sent at odd times. The funny thing is I have been on these forums very shortly after they were implemented. I was on the newsgroup and was reluctant to come here. That said, I can't recall ever seeing this happen before.  
 
I do hope you understand my concern about this as there is so much talk about all sorts of nasty things going on lately. I can say I am very pleased that you posted here and shed some light on this. I really thank you for that.    

Best
John
#17
stratman70
Max Output Level: -45 dBFS
  • Total Posts : 3044
  • Joined: 2006/09/12 20:34:12
  • Location: Earth
  • Status: offline
Re: Account hacked? 2016/03/07 21:28:31 (permalink)
EDIT: Whoops-didn't see your post John or the ops-I need to scroll all the way down next time-sorry guys
 
I don't think clicking on a link like that is a good idea. I would log in again and change the password again-that's if you logged in with the link you received and changed it. Just me-I'm old :-) 

 
 
#18
Paul P
Max Output Level: -48.5 dBFS
  • Total Posts : 2685
  • Joined: 2012/12/08 17:15:47
  • Location: Montreal
  • Status: offline
Re: Account hacked? 2016/03/07 21:43:49 (permalink)
stratman70
I don't think clicking on a link like that is a good idea. I would log in again and change the password again-that's if you logged in with the link you received and changed it. Just me-I'm old :-) 



Yes.  Reading the post above I checked the link, expecting to see something from Russia or Pakistan.  I was kind of surprised to see the correct Cakewalk address.

Sonar Platinum [2017.10], Win7U x64 sp1, Xeon E5-1620 3.6 GHz, Asus P9X79WS, 16 GB ECC, 128gb SSD, HD7950, Mackie Blackjack
#19
bvideo
Max Output Level: -58 dBFS
  • Total Posts : 1707
  • Joined: 2006/09/02 22:20:02
  • Status: offline
Re: Account hacked? 2016/03/07 23:39:01 (permalink) ☄ Helpfulby tlw 2016/03/09 09:17:13
1andyf88
This is what I received as an email. I have since changed the password twice. I never initiated a password change or reset.

Cakewalk Password Reset

Cakewalk Account Management
to me
18 minutes agoDetails
Hello AndyF,

Your Cakewalk password has been reset to the following: v:lE#v*5

Please sign in and change your password here: https://www.cakewalk.com/.-Account/Change-Password

If the above password is not accepted, please try typing it in manually instead of copying and pasting it.

Best Regards,
Cakewalk Account Management



This sounds exactly like someone clicked the "forgot password?" link for your userid and the forum software dutifully picked a scrambly password and sent it to you at your email registered with the forum. This could happen harmlessly without anyone successfully accessing your email or your forum account.

W10 pro, Sonar Platinum, Alesis Multimix 16 FW, MOTU Express 128, Gigabyte Z370 HD3P, i7 8700K, 16 Gigs, ssd + 2 X 2T disks, D50-MEX, JV80, A90EX, M1REX
#20
Ryan Munnis [Cakewalk]
Administrator
  • Total Posts : 1067
  • Joined: 2009/11/01 10:28:44
  • Status: offline
Re: Account hacked? 2016/03/08 10:32:23 (permalink)
1andyf88
Thanks Ryan. I did indeed, after receiving the email, change the account password and my user name,.I have also changed my email password. I however do not have an open email thread with anyone. I did not initiate a change password request. This email just showed up in my mailbox. At any rate, I can't complain about Cakewalk fast response to this, both on the way hone and here in the forum. We shall see if the above changes solve the problem.

 
Thanks. I've asked our rep to reach out to clear up the confusion. I can definitely confirm the password reset email was triggered by us though, so that's a relief. I'm sorry for any alarm as a result!

John
 
It was me I think that brought it to your attention. I am totally happy now with your response. I don't use a log in manually. I have my browser set to automatically to log me in. Rarely do I log in myself. I'm going to watch this a little closer and try to figure out what conditions cause an email to be sent. What might be a problem is a delay in logging in and the email being sent. Though I can't be sure of this at the present time. It seems that these emails are sent at odd times. The funny thing is I have been on these forums very shortly after they were implemented. I was on the newsgroup and was reluctant to come here. That said, I can't recall ever seeing this happen before.  
 
I do hope you understand my concern about this as there is so much talk about all sorts of nasty things going on lately. I can say I am very pleased that you posted here and shed some light on this. I really thank you for that.    



Yeah, the emails aren't initiated by the forum software but rather by our Cakewalk account management. When we switched the forum over to Cakewalk accounts is probably when these emails started getting triggered. Round 1 would automatically reset the password, which was obviously at the dismay of many users, so we updated the process to require action from the account owner's email address before preemptively resetting passwords.
 
bvideo
 
This sounds exactly like someone clicked the "forgot password?" link for your userid and the forum software dutifully picked a scrambly password and sent it to you at your email registered with the forum. This could happen harmlessly without anyone successfully accessing your email or your forum account.




That is incorrect. Please see my post here http://forum.cakewalk.com/FindPost/3382517

Ryan Munnis
Cakewalk
#21
John
Forum Host
  • Total Posts : 30467
  • Joined: 2003/11/06 11:53:17
  • Status: offline
Re: Account hacked? 2016/03/08 21:55:23 (permalink)
Thank you Ryan for the further explanation. 

Best
John
#22
Jump to:
© 2025 APG vNext Commercial Version 5.1