
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:23 AM
Hey all,
Did anyone else get an email from JAMF with the above Subject?
This was in the body:
On March 14, an unknown source maliciously gained access to your primary e-mail address on JAMF Nation through a previously unknown and unintentional information disclosure on the website. ....
I ask cause me and anther guy at work got the same email at the same time.
Just wondering if anyone else getting this and if it's legit.
Thanks,
-p
Solved! Go to Solution.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:40 AM
Hi everybody-
The email that you received is a legit email from us.
One point of clarification on the email: People have been asking us the question about exactly what the individual gained access to. They found the "Primary Email Address" field from JAMF Nation. They did not gain access to your email or to your password.
We're fielding questions as they come in. Feel free to continue to email our primary contact for privacy (privacy@jamfsoftware.com), Wudi (wudi@jamfsoftware.com), or me at zach@jamfsoftware.com.
Zach Halmstad

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:24 AM
Yes. I got it as well, seems legit.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:24 AM
I received the same notification from JAMF also.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:24 AM
Hey - I got the same too. The "mail" links aren't valid "mailto:" format and have a very strange URL linked. I scanned the URL in VirusTotal and got no hits but I really don't trust the email at the moment.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:25 AM
I got it as well. I also got random spam yesterday that I immediately discarded. Now I understand why I got it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:26 AM
I have been getting a lot of spam and when I looked at who all got sent it I was wondering why most if not all the emails had edu or school emails, now I know got this email today.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:26 AM
Same here.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:30 AM
Same here i received a email like this a few mins ago as well. I been getting bitcoin spam email to my company address for the past few days i wonder if its related.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:31 AM
Got one, as did my coworker. The URLs might point to Marketo, which could be a service JAMF is using for this kind of email blast (though I don't have many old emails from JAMF to check against, outside of service tickets).
Edit: Apparently I didn't delete the old 9.1/8.72 announcement; it has the same kind of links (mkto-p00...). MKTO is the stock symbol for Marketo.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:33 AM
WTF is JAMFNATION ? i just got that email too ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:33 AM
I got this email twice today.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:34 AM
i replied to the email and asked for a source address that they claim my account was hacked. I would like to share the information with my information security team just to make sure we aren't affected

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:34 AM
I got one just wondering if its legit.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:34 AM
I got one just wondering if its legit.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:35 AM
Anyone know what actually happened?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:35 AM
brokenimages seems to be a fake account LOL
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:36 AM
If it's true, and it's coming from JAMF Nation via Marketo as the headers would seem to indicate, it'd be nice to know if passwords were also compromised, etc.
If not, more bits for the bit bucket.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:37 AM
I got it too. Email comes from Jason Wudi. Doesn't look too official though. The links are all randomised addresses.
https://jamfnation.jamfsoftware.com/viewProfile.html?userID=7
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:39 AM
I received it as well.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:40 AM
Hi everybody-
The email that you received is a legit email from us.
One point of clarification on the email: People have been asking us the question about exactly what the individual gained access to. They found the "Primary Email Address" field from JAMF Nation. They did not gain access to your email or to your password.
We're fielding questions as they come in. Feel free to continue to email our primary contact for privacy (privacy@jamfsoftware.com), Wudi (wudi@jamfsoftware.com), or me at zach@jamfsoftware.com.
Zach Halmstad
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:40 AM
I've gotten the email as well. I checked out the links with another email that I got from a release point update email. It seems that they use that service, so this looks legit. Would love to see an official response on here though just to make sure.
Edit: I see that an official response came out as I posted this. :)

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:42 AM
Thanks for the quick answer Zach!!
-p

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:44 AM
Yes thanks Zach

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 08:52 AM
Thanks Zach et al.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 09:02 AM
best practice - change your password anyway.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 09:10 AM
Gotta love 1Password...took 30 seconds to update my JAMF account with a long complex password across all my computers and devices. ;)
https://agilebits.com/onepassword
https://donmontalvo.com

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 09:52 AM
1password is the best...
Anyway is there a way to actually remove a jamfnation account? I had a colleague just ask me.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 09:54 AM
I did as well.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 01:04 PM
Me and my colleagues too....

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 05:04 PM
I got one too. Doesn't sound like they got access to passwords, nor to our JAMFNation account per se, just the email addresses stored for our JN accounts, so while I may change my JN password for good measure, not sure there's much of a need to.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-18-2014 05:06 PM
I have received a very odd spam email. I keep getting emails supposedly from Apple regarding upcoming genius bar appointments. Has anyone else been getting these emails since our email addresses have been stolen?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-19-2014 10:19 AM
Spam and SYN attacks are like the background radiation of the Internet... They're always there. I've noticed no change in the volume of spam hitting our filters or my inbox.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Posted on 03-19-2014 11:19 AM
true. Although it would be too soon to be getting spam yet they would have to sell the data.
Yes, 1Password is awesome. :)
