Tastytrade账号被莫名转出了50k wire

今天早上莫名看到账号被转出了一笔 wire 50k现金
只收到了邮件提醒
Thank you for reaching out. Full account restrictions have been placed on your account at this time. These restrictions can be removed at any time at your request.

It looks like the wire was sent to Truist Bank account number 1430006402575. Unfortunately, it is too late to reject the wire request on our end. We have requested that our clearing firm, Apex Clearing Corporation, submits a wire recall request.

From what we can tell, this account intrusion was not a result of deficiencies of tastytrade systems. It appears that the intruder was in possession of your login credentials and was able to login cleanly at first try. Further, it appears that you did not have two-factor authentication enabled for your account at the time of the unauthorized withdrawal. Unfortunately, this would have likely stopped the wire withdrawal from being requested as it is usually a very effective security measure.

I see that you have updated your tastytrade password and enabled two-factor authentication for sensitive actions within your account. Please be sure when updating passwords to use strong password practices. Ideally, a password should be at least 12 characters and include a mix of lower-case and capital letters, numbers, and special characters such as @, $ or *. It should be unrelated to any of your prior passwords and should be unique and not used within more than one website or app. If you are struggling to think of something, you can use a password generator (there are several free options available) or pick a short sentence or phrase to use as inspiration and replace certain letters with numbers or special characters. You may want to consider changing the password tied to your email address associated with your tastytrade account. I am not indicating that your email is compromised, but this is a common place where such leaks occur.

We strongly suggest that you enable two-factor authentication for sensitive actions AND at every login within your tastytrade account. You can do so by logging into your account at my.tastytrade.comand follow Manage>My Profile>Security. You will see the toggle to enable these features. If offered, you should do this for all important websites.

I would also suggest to never use the “stay logged in” feature for any website and be sure to clear your cookies/cache files routinely. It is a good practice to power cycle your internet router on a routine basis. Finally, frequent and routine virus scans on your devices are highly recommended.

I wanted to let you know that wire withdrawals are extremely difficult to call back as the account intruder will act quickly to try to move the funds further away from the receiving bank account. If we caught this early enough, the return of the funds can take quite a bit of time as the bank needs to complete an investigation on their end. Such investigations can take over 90 days.

I will keep you posted as more information becomes available to me. Please know that I am doing all I can to return these funds to you

已报警


邮箱也被黑了

2 个赞

昨天我也是被盗号!我突然收到短信验证码,觉得不对就立马改的密码。我的密码是苹果自动生成的这样也能被盗。这么看来应该是tastytrade数据库不知道为啥泄露了

我靠真吓人啊 之前$250K $10K 没赶上。真的是你图它利息它图你本金

4 个赞

现在不知道咋整了
今天早上九点wire转出的.

有没有重复用密码?tastyworks和邮箱

两个可能性:

  1. Password recycling
  2. Email got hacked

at any rate, To anyone reading this, please set up 2FA on all your financial, social, airline, and hotel accounts, PLEASE I BEG YOU

42 个赞

虾仁 我也薅了这个 赶紧加验证

他家app里好像没看到有加验证的地方?

这种能要回来吗

去网页版设置。

2 个赞

update:

家人们能不能管管俺啊
打电话给了truist
他们说这笔钱在pending 看到这笔钱了

怎么办啊

我的没有。苹果自动产生的

楼主看你截图fidelity也改了密码 这是hacker改的还是你自己操作的

打电话给tastytrade和背后的银行让他们试下能不能拦住这笔wire有用吗(我是小白)?

gotta learn to ask gemini man, it’s free




did you secure your email and clear any forwarding per suggestion 4?
number 1’s ic3.gov seems pretty legit?

here’s how the number 1 IC3 kill chain works:
https://www.justice.gov/elderjustice/media/1364056/dl?inline

5 个赞

tastytrade怎么说?如果一般的客服不给力赶快要求跟supervisor直接对话?

这家有前科啊?

1 个赞

让truist freeze啊

On April 4, my brother’s account, who had a unique password and 2FA enabled, was compromised. The hackers did not withdraw money or change info and trigger 2FA. Though I have repeatedly emailed multiple divisions and Tom, Scott and Tony at Tastytrade, no one is helping me understand what happened and how to resolve.

太吓人了

是不是没有密码也能发出来?