frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: Poshmark instantly leaked my email to scammers

9•hardenedmetapod•2w ago
Browsing for an obscure piece of electronics, I ran across a Poshmark listing that had it for considerably cheaper than anywhere else.

I didn't have an account yet, so I signed up with Google SSO and was able to place the order.

About an hour later I got an email as if I was the seller telling me to click this link to verify my account for my funds to be deposited.

Obviously phishing. Upon closer inspection, I had two earlier that were properly filtered to spam that were about 30 minutes after the order.

So the question here is what part of their system is so fundamentally broken that scammers instantly get my email? Does the seller get that upon me making that purchase?

And if that's not the case, then that means somebody has completely compromised their system.

Comments

myself248•2w ago
Yikes. I wonder if there's a way to differentiate between the bad-seller and the poshmark-is-compromised case.
chrisjj•2w ago
Sure. Be a seller.
hardenedmetapod•2w ago
There's a third case that I never considered.

Google SSO is the promoted way of signing in and it auto assigns your email to the username without any special characters so scammers could just be scraping new accounts and making a best guess at the email.

Lame.

chrisjj•2w ago
I'd call that the first case and the second case. Lame indeed.
chrisjj•2w ago
> So the question here is what part of their system is so fundamentally broken that scammers instantly get my email?

Perhaps none. Did the T&Cs permit this disclosure?

hardenedmetapod•2w ago
Not that I can see offhand. It mentions using your email for correspondence and copyright disputes.
chrisjj•2w ago
I'd say odds on Poshmark leaking your address to the seller.

The fact you got spam so soon makes me wonder, did you get your goods?

altairprime•2w ago
Sounds exactly like a common website “significantly cheaper” scam, only on Poshmark slash Etsy slash Amazon, where the seller is provided your contact info in order to ship you things. Did they have a history of completed sales? Did you ask any questions and get a response (or not) before purchasing? Someone always ends up being the first rube at any online marketplaces from a scam seller who hasn’t been reported yet, at least when said marketplaces aren’t doing serious in-person identity verification first, and this time you’re the lucky one.

LLMs are powerful, but enterprises are deterministic by nature

3•prateekdalal•2h ago•2 comments

Ask HN: Anyone Using a Mac Studio for Local AI/LLM?

46•UmYeahNo•1d ago•28 comments

Ask HN: Ideas for small ways to make the world a better place

13•jlmcgraw•16h ago•19 comments

Ask HN: Non AI-obsessed tech forums

23•nanocat•13h ago•20 comments

Ask HN: 10 months since the Llama-4 release: what happened to Meta AI?

44•Invictus0•1d ago•11 comments

Ask HN: Who wants to be hired? (February 2026)

139•whoishiring•4d ago•514 comments

Ask HN: Non-profit, volunteers run org needs CRM. Is Odoo Community a good sol.?

2•netfortius•11h ago•1 comments

Ask HN: Who is hiring? (February 2026)

313•whoishiring•4d ago•512 comments

AI Regex Scientist: A self-improving regex solver

6•PranoyP•18h ago•1 comments

Tell HN: Another round of Zendesk email spam

104•Philpax•2d ago•54 comments

Ask HN: Is Connecting via SSH Risky?

19•atrevbot•2d ago•37 comments

Ask HN: Has your whole engineering team gone big into AI coding? How's it going?

17•jchung•2d ago•12 comments

Ask HN: Why LLM providers sell access instead of consulting services?

4•pera•1d ago•13 comments

Ask HN: What is the most complicated Algorithm you came up with yourself?

3•meffmadd•1d ago•7 comments

Ask HN: How does ChatGPT decide which websites to recommend?

5•nworley•1d ago•11 comments

Ask HN: Is it just me or are most businesses insane?

7•justenough•1d ago•7 comments

Ask HN: Mem0 stores memories, but doesn't learn user patterns

9•fliellerjulian•2d ago•6 comments

Ask HN: Is there anyone here who still uses slide rules?

123•blenderob•3d ago•122 comments

Ask HN: Any International Job Boards for International Workers?

2•15charslong•13h ago•2 comments

Kernighan on Programming

170•chrisjj•4d ago•61 comments

Ask HN: Anyone Seeing YT ads related to chats on ChatGPT?

2•guhsnamih•1d ago•4 comments

Ask HN: Does global decoupling from the USA signal comeback of the desktop app?

5•wewewedxfgdf•1d ago•3 comments

We built a serverless GPU inference platform with predictable latency

5•QubridAI•2d ago•1 comments

Ask HN: Does a good "read it later" app exist?

8•buchanae•3d ago•18 comments

Ask HN: How Did You Validate?

4•haute_cuisine•1d ago•6 comments

Ask HN: Have you been fired because of AI?

17•s-stude•4d ago•15 comments

Ask HN: Cheap laptop for Linux without GUI (for writing)

15•locusofself•3d ago•16 comments

Ask HN: Anyone have a "sovereign" solution for phone calls?

12•kldg•3d ago•1 comments

Ask HN: OpenClaw users, what is your token spend?

14•8cvor6j844qw_d6•4d ago•6 comments

Test management tools for automation heavy teams

2•Divyakurian•2d ago•2 comments