Got it as well , seems legit but I didnt reset my account yet...
Comment has been collapsed.
just go to the bundle stars website and change it yourself if you think its a fake message
Comment has been collapsed.
Actually I just went in the website and it looks pretty broken from what im seeing.
Comment has been collapsed.
Yes I did
If you go to the Bundlestars site, they will force you to do a password reset.
Comment has been collapsed.
I think it's legit. It won't even let me log in atm, it says a password reset it required. Pretty net safety feature I haven't seen before. Usually I can log in and change my pw that way but they're adding a little extra step
Comment has been collapsed.
I received it as well. As a previous user suggested, just go directly to the site and reset your password rather than clicking the link in the email. Pretty sure it's genuine though.
Comment has been collapsed.
Well it does look like a good scam (one without spelling mistakes).
and the fact that the link is something like this:
http://mandrillapp.com/track/click/30039138/www.bundlestars.com?p=joKzIjoiQUFzM304VjhnOilHdW5EVUVEdzFuVUFFMExrIiwidiI6MSwicCI6IntcInVcIjozMDA4OTE3NixcInZcIjoxLFwidXJsXCI6XCJodHRwczpcXFwvXFxcL4d4dy5idW5kbGVzdGFycy3jb21cXFwvZW5cXFwvcGFzc3dvcmQtcmVzZXQ_dXRtX3NvdXJjZT1tYW5kcmlsbCZ1dG1fbWVkaXVtPWVtYWlsJnV0bV9jYW1wYWlnbj1yZXNldF3wYXNzd29yZF9yZXF1ZXN0XCIsXCJpZFwiOlwiYzU2ZTFmMzJlNDczNGJiOTlmMDZmZDg5Y2JkNGM2ZDBcIixcInVybF9pZHNcIjpbXCIwMjc1ZjkyZDMxMzkwYzc1ZTdmYTE3NSA4MGe7NTgxNmQ2NjVjNGJiXCJdfSJ9
doesn't make it look very legit.
To be honest: Nobody should look any link
that looks in the slightest way suspicious.
And this link stinks of suspiciousness.
Comment has been collapsed.
Mandrill is a company specialized in e-mail, usually with regards to analytics, business targeting etcetera.
Pretty standard with companies that aren't tech-savy enough to run their own e-mail-servers.
The fact they still used a trackingcode for an e-mail like is just poor judgement however.
Comment has been collapsed.
Got it too. Went to the website and it told me to reset password. What bothers me is that says "accounts have been compromised" but doesn't specify if my account has.
Comment has been collapsed.
well they're blaming another unnamed website that you might share similar login info with.
Comment has been collapsed.
I can confirm that the email is from Bundle Stars. You can read more about it on the FAQs on our website - https://support.bundlestars.com/hc/en-us/articles/206997839-Password-Reset-Alert-February-2016
Comment has been collapsed.
You might want to consider implementing an account protection system similar to SteamGuard, instead of mass password resets. Databases are breached all the time, so it's pointless to constantly reset passwords in this manner, and it actually benefits the hackers.
Comment has been collapsed.
Research has demonstrated in the workplace that frequent password changes encourages weaker passwords. In BundleStars case it would encourage people to actually use common passwords across sites. If all websites implemented this unnecessary strategy, it would encourage people to stop caring. You can find compromised account data for HumbleBundle daily on PasteBin and hack sites, so should HumbleBundle reset everybody's passwords daily? HB uses the verification method when a browser session cookie is missing and geolocation does not match.
As a hacker, if I gained access to a database of hashed passwords that I couldn't reverse quickly, one of the solutions would be to disable the hashing process and drive traffic back to the site to reset their passwords. I now have their old and new passwords in cleartext and if people are used to the process, will not make a stink about it. Not a likely scenario, but valid nonetheless. Ultimately, it's just bad for business because it makes people feel your system is insecure.
Comment has been collapsed.
28 Comments - Last post 1 hour ago by Chris76de
271 Comments - Last post 2 hours ago by DragRedSim
338 Comments - Last post 2 hours ago by DragRedSim
21 Comments - Last post 2 hours ago by Chris76de
16,496 Comments - Last post 3 hours ago by Channel28
78 Comments - Last post 5 hours ago by Guard1aNRB
960 Comments - Last post 6 hours ago by Axelflox
115 Comments - Last post 14 minutes ago by Ic3m4n
19 Comments - Last post 16 minutes ago by Oshyer
96 Comments - Last post 23 minutes ago by Mhol1071
52 Comments - Last post 29 minutes ago by damianea103
17,212 Comments - Last post 43 minutes ago by SolvedPack
85 Comments - Last post 47 minutes ago by Ic3m4n
70 Comments - Last post 1 hour ago by 86maylin
Or is it just me? Or is it fake message to steal my account?
EDIT: Thanks for the responses! I'll leave it open in a case somebody else would like to clear their doubts.
Comment has been collapsed.