Solved Piriform CCleaner email about MoveIT data leak


Pretty much ALL "corporations" (companies with money), are targets for hackers. Money is the root of all evil... etc.

My suspicion is that these identity protection companies, have seen a possible market.
They give out free samples (like a drug dealer), then use some sort of scare tactics, that will hopefully generate new customers.
With all the companies being hacked these days... it's a ripe market.

Personally... I just try to keep the data I put on the internet... down to a minimum.
And I put nothing of a financial nature on the phone. Phones are a hacker's wet dream.

Unless you're a high roller, financially, or even a mid-roller... you probably don't have much to worry about.
That being said, try not to leave tracks on the internet.

Remember: It's not paranoia, if they ARE out to get you. :-)
 

My Computers

System One System Two

  • OS
    Win 11 Home ♦♦♦22631.3527 ♦♦♦♦♦♦♦23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 4702)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Internet Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Mouse
    Logitech Optical M-BT96a
    Keyboard
    Logitech Classic Keybooard 200
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 13 years?
And I put nothing of a financial nature on the phone. Phones are a hacker's wet dream.
Hear, hear! And I love the metaphor! :love:
 

My Computers

System One System Two

  • OS
    11 Pro 23H2 22631.3447
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo ThinkCentre M920S SFF
    CPU
    i7-9700 @ 3.00GHz
    Motherboard
    Lenovo 3132
    Memory
    32GBDDR4 @ 2666MHz
    Graphics Card(s)
    Intel HD 630 Graphics onboard
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    LG E2442
    Screen Resolution
    1920x1080
    Hard Drives
    1 x Samsung 970 EVO PLUS 500GB NVMe SSD, 1 x WD_BLACK SN770
    250GB NVMe SSD (OS and programs), 1 x WD_BLACK SN770
    500GB NVMe SSD (Data)
    Case
    Lenovo SFF
    Keyboard
    Cherry Stream TKL JK-8600US-2 Wired
    Mouse
    LogiTech M510 wireless
    Internet Speed
    Fast (for fixed wireless!)
    Browser
    Chrome, sometimes Firefox
    Antivirus
    Malwarebytes Premium & Defender (working together beautifully!)
  • Operating System
    11 Pro 23H2 22631.3527
    Computer type
    PC/Desktop
    Manufacturer/Model
    Lenovo ThinkCentre M920S SFF
    CPU
    i5-8400 @ 2.80GHz
    Motherboard
    Lenovo 3132
    Memory
    32GB DDR4 @ 2600MHz
    Graphics card(s)
    Intel HD 630 Graphics onboard
    Sound Card
    Realtek High Definition Audio onboard
    Monitor(s) Displays
    LG FULL HD (1920x1080@59Hz)
    Screen Resolution
    1920 x 1080
    Hard Drives
    1 x Samsung 970 EVO PLUS NVMe; 1 x Samsung 980 NVMe SSD
    Case
    Lenovo Think Centre SFF
    Mouse
    LogiTech M510 wireless
    Keyboard
    Cherry Stream TKL JK-8600US-2 Wired
    Internet Speed
    Fast (for fixed wireless!)
    Browser
    Chrome
    Antivirus
    Malwarebytes Premium and MS Defender, beautiful together
Personally... I just try to keep the data I put on the internet... down to a minimum.
I very much agree with that, and you would expect the regulars on this site to be extremely careful. Yet, on this very web site, one poster, ahem... , has invited people to post a picture of themselves, beginning with a self portrait; another has invited people to give details of their careers to date. Not mentioning any names, you understand. :-)

Anyway, with regard to the current issue at hand, I have decided to cancel my subscription to CCleaner (two data breaches for one company is a red flag, I think). That turned out to be more difficult than it should, because they have cancelled the original cancellation link (to protect the end user). However, the company which handles their subscription sent a new link which worked. Now I just have to work out how to simply manage my cookies using MS tools. Managing cookies was the main reason I stuck with CCleaner.
 

My Computers

System One System Two

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home built
    CPU
    Ryzen 3900x
    Motherboard
    Gigabyte Aorus Master x570 rel 1.0
    Memory
    32GB (2x16) @ 3600 MHz Corsair Vengeance LPX
    Graphics Card(s)
    Gigabyte Windforce RTX 2080
    Sound Card
    No separate sound card.
    Monitor(s) Displays
    Dell U2718Q
    Screen Resolution
    3840x2160
    Hard Drives
    1TB WD-Black SN850; 1TB Samsung Sata 850 Evo; 4 TB WD Blue Sata SA510 2.5''; 4TB Samsung Sata SSD 870 EVO 2.5".
    PSU
    Be Quiet Dark Power Pro 11 750W
    Case
    Lian Li PC-8FIB
    Cooling
    CPU: Noctua NH-U12A; Case: BeQuiet + Lian Li fans.
    Keyboard
    Steelseries Apex 7 brown keys.
    Mouse
    Logitech (wired) G403
    Internet Speed
    940 Mb/s down; 105 Mb/s up
    Browser
    Edge (Chromium)
    Antivirus
    Eset Internet Security
    Other Info
    Pioneer blu-ray optical drive.
  • Operating System
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    Dell Inspiron 7373 2-in-1
    CPU
    Intel Core i7 8th Generation
    Motherboard
    Dell 0HG1FH (U3E1)
    Memory
    8GB DDR4
    Graphics card(s)
    Intel UHD Graphics 620 (Dell)
    Sound Card
    Realtek Audio (on motherboard)
    Monitor(s) Displays
    Touch screen generic monitor
    Screen Resolution
    1920x1080
    Hard Drives
    256GB Micron SATA SSD.
    Browser
    Edge Chromium
    Antivirus
    Eset Internet Security
    Other Info
    Dell says this system is not Windows 11 capable, but Microsoft seems happy with it.
I very much agree with that, and you would expect the regulars on this site to be extremely careful. Yet, on this very web site, one poster, ahem... , has invited people to post a picture of themselves, beginning with a self portrait; another has invited people to give details of their careers to date. Not mentioning any names, you understand. :-)

Anyway, with regard to the current issue at hand, I have decided to cancel my subscription to CCleaner (two data breaches for one company is a red flag, I think). That turned out to be more difficult than it should, because they have cancelled the original cancellation link (to protect the end user). However, the company which handles their subscription sent a new link which worked. Now I just have to work out how to simply manage my cookies using MS tools. Managing cookies was the main reason I stuck with CCleaner.



I use an older free version (5.78), and I got no emails about this...

It scans clean locally, and has one false positive at Virustotal.


I also added these lines to the "HOSTS" file...

0.0.0.0 ncc.avast.com
0.0.0.0 ncc.avast.com.edgesuite.net
0.0.0.0 license.piriform.com
0.0.0.0 ipm-provider.ff.avast.com
0.0.0.0 shepherd.ff.avast.com
0.0.0.0 ip-info.ff.avast.com
0.0.0.0 analytics.ff.avast.com



In the CCleaner settings, I turned OFF all the call home thingies, AND blocked these entries in the Bitdefender firewall...

Image1.png
 

My Computers

System One System Two

  • OS
    Win 11 Home ♦♦♦22631.3527 ♦♦♦♦♦♦♦23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 4702)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Internet Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Mouse
    Logitech Optical M-BT96a
    Keyboard
    Logitech Classic Keybooard 200
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 13 years?
I just received this email:

Information about the MOVEit vulnerability




We’re reaching out as some of your personal information such as name and contact information has been exposed on the dark web. We take the safety of our customers extremely seriously, and we want to be sure you are aware of the potential impact and how to best protect yourself.

Earlier this year many companies were impacted by the MOVEit vulnerability. As a user of the software, we acted immediately to protect our systems and investigate the potential impact. We recently discovered that as a customer of CCleaner, some limited personal information of yours was exposed on the dark web. The information is primarily limited to name and/or contact information, as well as information on the product you purchased from us. No banking details, credit card numbers or high-risk data such as log-in information or account details were taken.

Naturally, we take any data exposure very seriously. As a valued customer, we would like to offer you BreachGuard for additional dark web monitoring, free of charge, for 6 months. BreachGuard helps monitor for data breaches, personal information on the dark web, and can give you access to privacy resources as applicable in your region. We will send details of how to install BreachGuard in the coming days, so please keep an eye out for those instructions, which we will send to this email address.

Please stay vigilant against potential phishing threats, as more commonly available personal information, like your name and contact information combined with purchase information, can be engineered to phish for high-risk data. You can learn more about how to best protect yourself here:


<Link “What is phishing and how you can remain safe” removed>​


Thank you for your continued support. Stay safe and keep an eye out for your instructions to install BreachGuard.

Your CCleaner Team

I find CCleaner very useful and would prefer not to stop using it, but I'm really doubtful about installing BreachGuard. I'd be interested in your thoughts on this matter, and what steps I should take to protect myself against identity theft.

John
I've been using CCleaner Pro for several years and have found it quite useful and reliable. I received the same message. Since it was from an address I hadn't seen before, I sent a query to support@ccleaner.com, an address I know is valid. Here's the reply:

Hello Arnold,

My name is Melvin, and I’m on the CCleaner Customer Care Team.

Thank you for reaching out to us regarding MOVEit breach, I’d be happy to [answer your question, and help you].

I see you’re having trouble with the email you receive and wanted to verify if that is legitimate from and let me answer your question.

First and foremost, thank you for being cautious and checking with us directly. We did send you a legitimate notification on 24 Oct 2023 to inform you that some of your personal information was involved in a recent cyber event. While the information is not considered high risk, we take this seriously and want to ensure you are prepared to be vigilant against any potential phishing threats using this information. As a valued customer, we are here to help. If you do not already have Dark Web Monitoring in place, we can help get you set up with complimentary Dark Web Monitoring services for 6 months. You will be receiving an email from us with instructions on how to redeem your product offering.

I hope that was helpful. Again, I’m sorry for the inconvenience. If you need anything else at all, feel free to message me at any time. I’d be happy to help.

Thank you.

Best regards,
Melvin | CCleaner Support - Manila, Philippines
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    Fujitsu Lifebook
    CPU
    2.60 gigahertz Intel Core i7-10750H
    Motherboard
    FUJITSU CLIENT COMPUTING LIMITED FJNBB69 813378-01R2100004
    Memory
    32500 Megabytes Usable Installed Memory
    Monitor(s) Displays
    Fujitsu 17WIDE LCD
Thanks @Arnold17 - that does rather draw a line under the whole thing. I'm a little surprised that they haven't put out such a statement on their web site (not that I can see, anyway - even the post from the moderator denying it has disappeared). It seems they are attempting damage limitation. It may be, of course, that the leak only impacts a small sub-set of their users.

Anyway, I will mark this thread as solved. Thanks to everyone who commented.
 

My Computers

System One System Two

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home built
    CPU
    Ryzen 3900x
    Motherboard
    Gigabyte Aorus Master x570 rel 1.0
    Memory
    32GB (2x16) @ 3600 MHz Corsair Vengeance LPX
    Graphics Card(s)
    Gigabyte Windforce RTX 2080
    Sound Card
    No separate sound card.
    Monitor(s) Displays
    Dell U2718Q
    Screen Resolution
    3840x2160
    Hard Drives
    1TB WD-Black SN850; 1TB Samsung Sata 850 Evo; 4 TB WD Blue Sata SA510 2.5''; 4TB Samsung Sata SSD 870 EVO 2.5".
    PSU
    Be Quiet Dark Power Pro 11 750W
    Case
    Lian Li PC-8FIB
    Cooling
    CPU: Noctua NH-U12A; Case: BeQuiet + Lian Li fans.
    Keyboard
    Steelseries Apex 7 brown keys.
    Mouse
    Logitech (wired) G403
    Internet Speed
    940 Mb/s down; 105 Mb/s up
    Browser
    Edge (Chromium)
    Antivirus
    Eset Internet Security
    Other Info
    Pioneer blu-ray optical drive.
  • Operating System
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    Dell Inspiron 7373 2-in-1
    CPU
    Intel Core i7 8th Generation
    Motherboard
    Dell 0HG1FH (U3E1)
    Memory
    8GB DDR4
    Graphics card(s)
    Intel UHD Graphics 620 (Dell)
    Sound Card
    Realtek Audio (on motherboard)
    Monitor(s) Displays
    Touch screen generic monitor
    Screen Resolution
    1920x1080
    Hard Drives
    256GB Micron SATA SSD.
    Browser
    Edge Chromium
    Antivirus
    Eset Internet Security
    Other Info
    Dell says this system is not Windows 11 capable, but Microsoft seems happy with it.
Back
Top Bottom