Anyone who got that message please reply to me directly - I would sure like to get to the source of this. It's identified by the From and XML contents - not by the subject. The only reference back to me is in the headers and yet I never saw the message with XML attachments. I keep folders of bogus messages and all messages in an archive or (that recent) junk or spam folders. AND if you goggle that email antwon.bechtelar -- it shows up in a PHP git class that generates fake names for testing. I removed the headers Mik posted - you can see the full email down the list. Lets keep more this off the list and I'll report how many saw it and if anything comes up. As for now, Mik and Stephen Michel saw it - with different bodies. This leads me to believe someone has just taken and hand hacked some of the HT archive -- date 2/5 on both. And thanks Mik for the full headers - that is what is needed to make any sense of this. Stay well - Rich On 2/18/2021 3:50 PM, Michael Muller via Hidden-discuss wrote: > > Did everyone get this email back on Feb 5 from "Stephen > <antwon.bechtelar at imperfecciones.inatural24.com>" > > It had an XLS file attached and the emailer asked me to sign it and > email it back. Yeah, right.. Looks like someone's account has been hacked. > > Full headers, below. Original email below that. > > Mik > > -- Rich Roth CEO TnR Global Bio and personal blog: http://rizbang.com Building the really big sites: http://www.tnrglobal.com Small/Soho business in the PV: http://www.hidden-tech.net Places to meet for business: http://www.meetmewhere.com And for Arts and relaxation: http://TarotMuertos.com - Artistic Tarot Deck http://www.welovemuseums.com http://www.artonmytv.com/ Helping move the world: http://www.earththrives.com -------------- next part -------------- An HTML attachment was scrubbed... URL: <http://lists.hidden-tech.net/pipermail/hidden-discuss/attachments/20210219/be13d338/attachment.html>