{"id":32210,"date":"2023-11-06T00:02:13","date_gmt":"2023-11-05T23:02:13","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=32210"},"modified":"2023-12-22T02:10:02","modified_gmt":"2023-12-22T01:10:02","slug":"lego-marketplace-bricklink-probably-hacked","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2023\/11\/06\/lego-marketplace-bricklink-probably-hacked\/","title":{"rendered":"Lego marketplace BrickLink probably hacked"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" width=\"200\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2023\/11\/05\/lego-marktplatz-bricklink-down-opfer-eines-hacks\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]The popular online marketplace for Lego<b>\u00ae<\/b> bricks, Bricklink, is suspected to have been the victim of a cyber attack. The marketplace has currently been taken offline and states \"Maintenance in progress\" on its homepage. Individual accounts are probably posting messages from the hackers. There is a clear warning on the marketplace page that \"Stormtrooper\" is not a maintenance guy.<\/p>\n<p><!--more--><\/p>\n<h2>Who or what is Bricklink?<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg05.met.vgwort.de\/na\/d8c6e70a60d449a3a7913606041de20c\" alt=\"\" width=\"1\" height=\"1\" \/>Bricklink\u00ae i is (according to its own statement) the world's largest online marketplace for buying and selling LEGO\u00ae parts, mini figures and sets, both new and used. If you are looking for Lego<b>\u00ae<\/b> bricks or want to sell them frequently, you are probably in good hands on the internationally active platform (the eBay of the little Lego<b>\u00ae<\/b> man).<\/p>\n<h2>Unusual activities, store offline<\/h2>\n<p>There seems to have been \"unusual activity\" in the BrickLink online store for a few days now. BrickLink's <a href=\"https:\/\/twitter.com\/BrickLink\" target=\"_blank\" rel=\"noopener\">X account<\/a> doesn't know anything about this yet, as I saw during a quick check &#8211; the last post was from Oct. 31, 2023.<\/p>\n<p><a href=\"https:\/\/twitter.com\/BrickLink\" target=\"_blank\" rel=\"nofollow noopener\"><img decoding=\"async\" title=\"BrickLink on Twitter\" src=\"https:\/\/i.postimg.cc\/GpyP0C5b\/image.png\" alt=\"BrickLink on Twitter\" \/><\/a><\/p>\n<p>However, the Bricklink website currently indicates maintenance work in the top right-hand corner (see graphic) and only displays a static graphic. There is a clear warning at the bottom of the page:<\/p>\n<blockquote>\n<h4 align=\"center\">Stormtrooper is not a maintenance man.<\/h4>\n<p>We're sorry Bricklink continues to be unavailable.<br \/>\n<i>Update November 4th. 3.55 pm EST<\/i> We continue to investigate the unusual activity. We aim to restore normal operations as swiftly as possible.<\/p><\/blockquote>\n<p>Also on November 4, 2023, it says that unusual activities are being monitored. Furthermore, since \"Stormtrooper\" is not a maintenance man. It looks like someone has been sending posts to registered users of the marketplace under this name.<\/p>\n<p><img decoding=\"async\" title=\"BrickLink Marketplace down\" src=\"https:\/\/i.postimg.cc\/Y0kTG8Wm\/image.png\" alt=\"BrickLink Marketplace down\" \/><\/p>\n<p>On November 3, 2023, there was already the following <a href=\"https:\/\/twitter.com\/ItsCrystalSue\/status\/1720546516123730166\" target=\"_blank\" rel=\"noopener\">post<\/a> on X, where someone refers to a possible hack of the marketplace. Reference is then made to a <a href=\"https:\/\/www.reddit.com\/r\/Bricklink\/comments\/17n2ltk\/re_ransom_demand_from_apparent_hackers_why\/\" target=\"_blank\" rel=\"noopener\">reddit.com post<\/a>.<\/p>\n<p><img decoding=\"async\" title=\"BrickLink hacked?\" src=\"https:\/\/i.postimg.cc\/QNw6Hh2Z\/image.png\" alt=\"BrickLink hacked?\" \/><\/p>\n<p>Within the <a href=\"https:\/\/www.reddit.com\/r\/Bricklink\/comments\/17n2ltk\/re_ransom_demand_from_apparent_hackers_why\/\" target=\"_blank\" rel=\"noopener\">reddit.com post<\/a> someone has published the following screenshot of a BrickLink account, which indicates a hack. The screenshot contains a message from the attacker.<\/p>\n<p><a href=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2023\/11\/as1lsukrm6yb1.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" title=\"BrickLink post der Hacker\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2023\/11\/as1lsukrm6yb1.png\" alt=\"BrickLink post der Hacker\" width=\"575\" height=\"426\" \/><\/a><\/p>\n<p>In the screenshot above, the hacker writes that he or she has or could have hacked all BrickLink accounts. The message should remain, they will start deleting entries from the store in 30 minutes and demand 50,000 euros in a BTC wallet (bitcoins) to be handed over. One user suspects that the operator has taken the platform offline because several user accounts have been hacked in the last week. This refers to <a href=\"https:\/\/www.reddit.com\/r\/Bricklink\/comments\/17n24zi\/has_bricklink_been_hacked\/\" target=\"_blank\" rel=\"noopener\">this reddit.com post<\/a>. I found the following screenshot of another account in an internal Facebook group.<\/p>\n<p><img decoding=\"async\" title=\"BrickLink post der Hacker\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2023\/11\/image-3.png\" alt=\"BrickLink post der Hacker\" \/><\/p>\n<p>One seller says: \"URGENT! Bricklink is unfortunately currently under attack. If you are a seller, PLEASE download your inventory and take precautions.\" A blog also has reported the incident <a href=\"https:\/\/jaysbrickblog.com\/news\/bricklink-is-currently-down-due-to-a-suspected-hacking-cybersecurity-incident\/\" target=\"_blank\" rel=\"noopener\">here<\/a>. There is no official statement from BrickLink (owned by <a href=\"https:\/\/www.lego.com\/de-de\" target=\"_blank\" rel=\"nofollow noopener\">Lego<\/a><b>\u00ae<\/b>) as far as I know.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]The popular online marketplace for Lego\u00ae bricks, Bricklink, is suspected to have been the victim of a cyber attack. The marketplace has currently been taken offline and states \"Maintenance in progress\" on its homepage. Individual accounts are probably posting messages &hellip; <a href=\"https:\/\/borncity.com\/win\/2023\/11\/06\/lego-marketplace-bricklink-probably-hacked\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69],"class_list":["post-32210","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/32210","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=32210"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/32210\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=32210"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=32210"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=32210"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}