Skip to main content
Solved

OT: Important JAMF Nation Account Notification

  • March 18, 2014
  • 32 replies
  • 112 views

Forum|alt.badge.img+10

Hey all,

Did anyone else get an email from JAMF with the above Subject?

This was in the body:

On March 14, an unknown source maliciously gained access to your primary e-mail address on JAMF Nation through a previously unknown and unintentional information disclosure on the website. ....

I ask cause me and anther guy at work got the same email at the same time.
Just wondering if anyone else getting this and if it's legit.

Thanks,
-p

Best answer by zach

Hi everybody-

The email that you received is a legit email from us.

One point of clarification on the email: People have been asking us the question about exactly what the individual gained access to. They found the "Primary Email Address" field from JAMF Nation. They did not gain access to your email or to your password.

We're fielding questions as they come in. Feel free to continue to email our primary contact for privacy (privacy@jamfsoftware.com), Wudi (wudi@jamfsoftware.com), or me at zach@jamfsoftware.com.

Zach Halmstad

32 replies

Forum|alt.badge.img+19
  • Employee
  • March 18, 2014

Yes. I got it as well, seems legit.


Forum|alt.badge.img+3
  • New Contributor
  • March 18, 2014

I received the same notification from JAMF also.


Forum|alt.badge.img
  • New Contributor
  • March 18, 2014

Hey - I got the same too. The "mail" links aren't valid "mailto:" format and have a very strange URL linked. I scanned the URL in VirusTotal and got no hits but I really don't trust the email at the moment.


emily
Forum|alt.badge.img+26
  • Hall of Fame
  • March 18, 2014

I got it as well. I also got random spam yesterday that I immediately discarded. Now I understand why I got it.


Forum|alt.badge.img+9
  • New Contributor
  • March 18, 2014

I have been getting a lot of spam and when I looked at who all got sent it I was wondering why most if not all the emails had edu or school emails, now I know got this email today.


Forum|alt.badge.img+5
  • Contributor
  • March 18, 2014

Same here.


Forum|alt.badge.img+4
  • Contributor
  • March 18, 2014

Same here i received a email like this a few mins ago as well. I been getting bitcoin spam email to my company address for the past few days i wonder if its related.


Forum|alt.badge.img+13
  • Valued Contributor
  • March 18, 2014

Got one, as did my coworker. The URLs might point to Marketo, which could be a service JAMF is using for this kind of email blast (though I don't have many old emails from JAMF to check against, outside of service tickets).

Edit: Apparently I didn't delete the old 9.1/8.72 announcement; it has the same kind of links (mkto-p00...). MKTO is the stock symbol for Marketo.


Forum|alt.badge.img
  • New Contributor
  • March 18, 2014

WTF is JAMFNATION ? i just got that email too ?


Forum|alt.badge.img+3
  • New Contributor
  • March 18, 2014

I got this email twice today.


Forum|alt.badge.img+4
  • Contributor
  • March 18, 2014

i replied to the email and asked for a source address that they claim my account was hacked. I would like to share the information with my information security team just to make sure we aren't affected


Forum|alt.badge.img+4
  • Contributor
  • March 18, 2014

I got one just wondering if its legit.


Forum|alt.badge.img+4
  • Contributor
  • March 18, 2014

I got one just wondering if its legit.


Forum|alt.badge.img+3
  • New Contributor
  • March 18, 2014

Anyone know what actually happened?


Forum|alt.badge.img+4
  • Contributor
  • March 18, 2014

brokenimages seems to be a fake account LOL


Forum|alt.badge.img+1
  • New Contributor
  • March 18, 2014

If it's true, and it's coming from JAMF Nation via Marketo as the headers would seem to indicate, it'd be nice to know if passwords were also compromised, etc.

If not, more bits for the bit bucket.


Forum|alt.badge.img+6
  • Contributor
  • March 18, 2014

I got it too. Email comes from Jason Wudi. Doesn't look too official though. The links are all randomised addresses.

https://jamfnation.jamfsoftware.com/viewProfile.html?userID=7


Forum|alt.badge.img+1
  • New Contributor
  • March 18, 2014

I received it as well.


Forum|alt.badge.img+7
  • Employee
  • Answer
  • March 18, 2014

Hi everybody-

The email that you received is a legit email from us.

One point of clarification on the email: People have been asking us the question about exactly what the individual gained access to. They found the "Primary Email Address" field from JAMF Nation. They did not gain access to your email or to your password.

We're fielding questions as they come in. Feel free to continue to email our primary contact for privacy (privacy@jamfsoftware.com), Wudi (wudi@jamfsoftware.com), or me at zach@jamfsoftware.com.

Zach Halmstad


Forum|alt.badge.img+7
  • Contributor
  • March 18, 2014

I've gotten the email as well. I checked out the links with another email that I got from a release point update email. It seems that they use that service, so this looks legit. Would love to see an official response on here though just to make sure.

Edit: I see that an official response came out as I posted this. :)


Forum|alt.badge.img+10
  • Author
  • Contributor
  • March 18, 2014

Thanks for the quick answer Zach!!

-p


Forum|alt.badge.img+6
  • Contributor
  • March 18, 2014

Yes thanks Zach


Forum|alt.badge.img+8
  • Contributor
  • March 18, 2014

Thanks Zach et al.


cdenesha
Forum|alt.badge.img+14
  • Honored Contributor
  • March 18, 2014

best practice - change your password anyway.


donmontalvo
Forum|alt.badge.img+36
  • Hall of Fame
  • March 18, 2014

Gotta love 1Password...took 30 seconds to update my JAMF account with a long complex password across all my computers and devices. ;)

https://agilebits.com/onepassword