Settings

Theme

Tell HN: Poshmark instantly leaked my email to scammers

9 points by hardenedmetapod 18 days ago · 8 comments · 1 min read


Browsing for an obscure piece of electronics, I ran across a Poshmark listing that had it for considerably cheaper than anywhere else.

I didn't have an account yet, so I signed up with Google SSO and was able to place the order.

About an hour later I got an email as if I was the seller telling me to click this link to verify my account for my funds to be deposited.

Obviously phishing. Upon closer inspection, I had two earlier that were properly filtered to spam that were about 30 minutes after the order.

So the question here is what part of their system is so fundamentally broken that scammers instantly get my email? Does the seller get that upon me making that purchase?

And if that's not the case, then that means somebody has completely compromised their system.

altairprime 18 days ago

Sounds exactly like a common website “significantly cheaper” scam, only on Poshmark slash Etsy slash Amazon, where the seller is provided your contact info in order to ship you things. Did they have a history of completed sales? Did you ask any questions and get a response (or not) before purchasing? Someone always ends up being the first rube at any online marketplaces from a scam seller who hasn’t been reported yet, at least when said marketplaces aren’t doing serious in-person identity verification first, and this time you’re the lucky one.

chrisjj 18 days ago

> So the question here is what part of their system is so fundamentally broken that scammers instantly get my email?

Perhaps none. Did the T&Cs permit this disclosure?

  • hardenedmetapodOP 18 days ago

    Not that I can see offhand. It mentions using your email for correspondence and copyright disputes.

    • chrisjj 18 days ago

      I'd say odds on Poshmark leaking your address to the seller.

      The fact you got spam so soon makes me wonder, did you get your goods?

myself248 18 days ago

Yikes. I wonder if there's a way to differentiate between the bad-seller and the poshmark-is-compromised case.

  • hardenedmetapodOP 18 days ago

    There's a third case that I never considered.

    Google SSO is the promoted way of signing in and it auto assigns your email to the username without any special characters so scammers could just be scraping new accounts and making a best guess at the email.

    Lame.

  • chrisjj 18 days ago

    Sure. Be a seller.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection