Hacker News new | ask | show | jobs
Ask HN: I'm getting emails about trial accounts on sites I don't recognise
5 points by amihacked 154 days ago
I’m seeing emails for a few services at my primary personal gmail account that I don’t know anything about, e.g. A shopify trial account in the Germany region (I do not live there and I've never signed up for a Shopify account) and an account on a ticket resale site that I didn't know existed.

I don’t understand how someone could have done this without being able to verify the account by receiving and clicking on an email, yet I recognise every device/access on Google’s list of devices. I also have 2FA enabled.

I've obviously changed my password and invoked Shopify's 30 day delete on my PII - the trial has expired so I cannot get past the "pay us money to do anything" wall and delete the shop myself.

What could I be missing? Could this be someone with remote access to one my devices and able to defeat 2FA?

2 comments

“ emails for a few services”

You mean these emails are more than just a first verification step to check that your email address exists and to confirm that you want to sign up as a new user?

The emails say things like "upgrade your trial account now" or "you might be interested in these other products". I have not seen any welcome or request to verify emails.
Unless you’ve got evidence to the contrary: this sounds most likely to be spam campaigns that’s being sent to millions of email addresses, from leaked lists or random generated.

One of the emails is yours

I have evidence to the contrary: there is a real German Shopify account that I never signed up for (I don't even speak German), and these are real emails from Shopify.
What's your email? lol
More specific:

@OP: If your email is john.smith@gmail.com there are probably a few idiots Jonh Smith out there that don't remember their email and fill your email instead. If your email is ju3hh4y3g79us99fahh0827@gmail.com probably your email is leaked and some idiot is sending fake email for grow hacking or just phishing.

I have a top level email address based on my first.lastname@gmail.com ... but it is an unusual name and LinkedIn / google does not find collisions.