Thursday, September 27, 2007

my macy's myspace effort continues...

ok, everyone, i'm on step two! i have presented my evidence to a macy's director as promised. i will spare you all the big ass document i sent and just share the letter:

Hi Elina,

I'm writing to follow up with you, as promised, about MySpace hacking that involves Macy's. You requested information on specific instances (and details about comments and messages where Macy's was included) so you could share the information with the legal department, and any other department at Macy's that needs to be made aware of this. I have attached a fourteen-page document that will give you a general idea of what is going on. This document is not a complete report on MySpace hacking that involves Macy's, not even close. What I have complied is just an overview of information from my own brief research and my network of friends.

While researching Macy's-related MySpace hacking I noticed a skate video from October 2006 titled, "I don't want a Macy's gift card" (included in document). I haven't been on MySpace very long so I can't personally attest to the time frame, but to me this suggests that Macy's-related MySpace hacking has been going on for over a year.

In this document you'll notice that various gift card images and text that predominately feature Macy's were posted as comments on various pages (my small sample includes over 60 such examples), and that these comments were posted in the same time frame (March 2007, May 2007, July 2007, and September 2007 – please note the pattern in this time-frame). The common theme is a 500 hundred dollar gift card from Macy's that can be received by linking to a Web site included in the comment, and the various images used (a variety of Macy's gift cards, Chanel purses, naked women, etc.). This same occurrence happens with MySpace bulletins as well (I included very recent examples of this at the end of the document).

The feedback I got from the people who have been hacked is that they have trouble logging on (or they can't log on at all that day) and the next thing they know a MySpace friend is telling them they've been hacked (meaning that friend received a Macy's-related comment or bulletin). Sadly, these people aren't hacked only once (it happens up to five times) and after the first time the hacking becomes more aggressive (their screen is redirected to a fake screen). After they have been hacked their 'Top Friends' are typically hacked right afterwards.

I noticed that various Web links are used in the hacking. Some of the sites I encountered included 'givezaway.com,' 'macys.ILoveFreeShit.com,' and, most recently, 'promotionalpalace.com.' I found the promotional palace link very interesting because it was brought to my attention by someone who was hacked just last week. When I clicked on the Macy's gift card it redirected me (VERY quickly) to one site and then immediately over to 'promotional palace'. The redirect site was difficult for me to pinpoint because of the speed and the only thing I was able to make out was 'miicinmedia.com.' What I found on the promotional palace site was contradictory. In one section it reads; "Since Promotional Palace's sponsors pay to be part of this program it allows us to give our participants incredible gifts," and yet at the bottom of the site it states; "PromotionalPalace.com is an independent rewards program for consumers and is not affiliated with, sponsored by or endorsed by any of the listed products or retailers…"

Is Macy's involved with Promotional Palace (or any of the Web sites mentioned above) at this time, or has the company being affiliated or involved with this 'company' at any time?

Everyone I was in contact with while researching this believes that Macy's is aware of (and/or involved in) this hacking. It would be great if I could let all of these people know that Macy's isn't involved and that the company is being proactive in putting an end to this.

As I mentioned before, Macy's brand has become a joke on MySpace, so I would hope your company takes this very seriously and takes action on the matter (as well as publicly addressing it in order to clear Macy's name).


I look forward to hearing from you, and I hope the information I have attached is helpful.

Best regards,
Holly

9 comments:

ms. p said...

the same thing happened to me. i'll be interested to see if you hear back from them.

Anonymous said...

Wow..it's happening to me too...how can they get away with this!? I feel like a fool now, but my good friend swore that it worked..that's not cool

Anonymous said...

I left a comment yesterday...I'm "anonymous." Instead of being idle about the whole thing, I also contacted Macy's via e-mail...they responded back with a cookie-cutter draft letter, saying that they are not responsible and to contact myspace. I sent a response, demanding follow-up with this fraud "promotional palace," more like promotional hell...now I'm bombarded with junk e-mails, and now I'm getting cell phone solicitations!!!! I bear some responsibility; I should have done research on this company, before signing away my right arm; however, this is insane!! We are in a hacker scamming world now, and we should all be cautious..Fantastic..The power of marketing

holly beal said...

woah, i'm sorry you are having to deal with all of this. did you send a general email to macy's or were you in contact with someone specific?

contacting myspace about this has always been in the back of my mind. now that i've discovered promotional HELL is the most recent offender i think they need to be contacted as well.

for whatever this is worth - i've heard it's best to change your password right after it happens and then keep changing your password regularly. 8 character passwords containing both numbers and letters are the safest.

Lynne said...

I don't know how they're getting into my account to spam other people's comments sections, but 15 minutes of digging produces this:

All these latest hack/spams are coming from domains registered within the past week-

macyshasfreecredit.com
doyoushopmacys.com
mymacyscredits.com
freecreditformacys.com, etc.

They all are being masked behind a company that calls itself whoisguard.com

WhoisGuard
+1.6613102107
Fax: +1.6613102107
8939 S. Sepulveda Blvd. #110 - 732
Westchester, CA 90045

DNS points back to this spammy looking company, but they probably just registered the names, or are hosting the servers.

eNom, Inc.

http://www.enom.com/ 72.5.232.18

The links themselves go to a page for promotionalpalace.com

And that looks like it is associated with these people

http://www.marketlabs.net/

who look mighty suspicious from their web page, if you ask me.

It's difficult for me to believe that Macy's would allow their name to be associated with this type of thing unless they were actually involved in it.

Hmm.

I'm not all that great at cyber sleuthing, so certainly someone who gets paid to do that could get to the bottom of this. What I want to know is how they used my account to spam people. I use pretty tight passwords.

Cheers,

~Katt

hexkaster said...

ok, they are ultimatly registered with godaddy.com
http://www.securepaynet.net/gdshop/spamreport/spamreport.asp?prog_id=domainsbyproxy
that's who owns the bullshit, so complaints directed there :)

Anonymous said...

Hi guys, it's "Anonymous" again. Actually, my name is Sophia. Yeah, it's a real bummer..I feel violated. I had to contact the BBB, because one of the offers I signed up for to get the bogus Macys gift card, "PosterPass.com" was also a scam. Their offer was to get four posters at $2 a piece. They charged $34.00 on my bankcard, then charged an additional, unauthorized $48.00! I called my bank, then they canceled my card. It's crazy..but again, I bear some responsibility for giving out my information nilly willy on the net..but damn, it still sucks! I definately learned my lesson...so, who should I contact to report "Promotional Palace?" Oops, I mean HELL? I bet I'm just S.O.L.

holly beal said...

oh chica, i'm so sorry you're having to deal with this crap. i've been trying to figure out where promotional palace is located but it's like a freakin' vapor. i think you took the right step by reporting this to the better business bureau, but what to do beyond that i'm not completely sure. but how about starting here:

internet crime complaint center:
http://www.ic3.gov/

national fraud info center:
http://www.fraud.org/info/repoform.htm

ftc consumer complaint:
https://rn.ftc.gov/pls/dod/wsolcq$.startup

you must be so pissed, because i am pissed that this happened to you. please let these agencies know what happened to you because a lot of people don't make their situation public which only allows these jerks to continue to operate under the radar (like they want to).

if anyone reading this has other ideas, please share them with sophia!

Anonymous said...

im so sick of macys giftcards

now i cant even erase those comments cause when i try it sends me to promotional palace,,

either myspace or macys has to stop this company