I got an email by somebody named Kirurusec.com / Salvatore Ansani.
Original mail at the end.
Trying to lay this out clearly because three separate things may or may not be connected.
The setup
I run a small print on demand business. I work with an assistant in the philippines who connects to an old windows 10 machine of mine over RDP. My own daily driver is windows 11.
2 different email addresses are involved
Email A: got the alert/mail from Salvatore. Used for lots of accounts but i almost never send mail from it. Not listed on haveibeenpwned.
Email B: leaked in a big 2020 breach, confirmed on haveibeenpwned.
Timeline
2020 – Email B gets leaked. Nothing i could have prevented.
Since then – once a year someone sends bad english emails to my old contacts. Stranger's address, but my name as the display name.
A few months ago – 2FA codes by SMS for tiktok and amazon on my phone (Email B & C not A!), daily for about a week, then it stopped. Nothing happened, no money gone.
Last week – the KiruruSec email lands on Email A.
The email itself
Guy calls himself an independent security researcher, KiruruSec / Salvatore Ansani. Says Email A shows up in an infostealer log, so malware on a device i use, not a normal website breach. He lists 10 domains where i supposedly have accounts.
5 domains matches: facebook, teepublic, freepik and a philippine job platform (I dont use). Oddly specific and all genuinely mine. Plus a german private LAN router address.
5 doesn't: a game launcher i have never used, and netflix, i was never signed up there with that address.
What i already did
Full scan on the windows 11 machine, clean. Haven't touched the old windows 10 box yet, and that's honestly where i'd expect something if anything.
What bugs me
He wants no money and sends no links, but i have to reply to get the full list. And where did he even get this mail address, it isn't on haveibeenpwned.
Questions
How should I react?
I know some of my data are out there and people try to log in. But I use a really save password manager, use super long passwords and every account a different one. I didnt had any problems yet except the display spoofing mails once a year.
Is this just a smarter flavour of phishing, or do people really do this?
How reliable are these domain lists from stealer logs, can entries from other machines get mixed in?
Where did he got this mail address?
Original email below.
Source: r/cybersecurity_help · by /u/WhatAmIdoingHere9839
