DailyStrength Members Community Support Group
Welcome! This community exists for DailyStrength members to have a place to share thoughts and feedback about the site with the folks that run DailyStrength. DailyStrength team members will regularly visit this community, sharing new product ideas, seeking feedback and beta testers, and most importantly, listening to you. Come join us!
Hello,
A few weeks ago, we began receiving reports that some member accounts were showing a link to graphic material in their status updates, and those same accounts were sending out random friend requests.
After a thorough investigation, we have concluded that this issue is NOT happening due to a technology issue with the DailyStrength.org site. It's been discovered that some members are using email addresses from outside organizations who have previously experienced data breaches. This information was not taken from DailyStrength's account database nor was DailyStrength's login system compromised.
What we're doing to address this issue:
· Here at DailyStrength, we are committed to ensuring the safety, privacy and the integrity of your accounts.
· To combat this issue we have blocked access to the DailyStrength.org site from regions across the globe where many of these spammers were originating.
· We are also deactivating any accounts we come across that look affected by this issue.
· Additionally, please know that we use best practices for safeguarding your information, and industry standard technologies to prevent unauthorized access to member accounts.
Our recommendations for you:
If at any time you are concerned that someone has unauthorized access to your DailyStrength account, you should:
· Change the password associated with the email address that you use to login to DailyStrength. You'll need to contact your email provider for instructions on how to do this.
· Change your DailyStrength account password by navigating to your own profile page and clicking on the orange "edit" button.
· Let us know by filling out this form
Please contact us via the submit a request form if you have any questions or concerns.
Best,
Team DailyStrength
-
Does anyone follow her? She's really got some good tips.
-
check out that smoke ring. It tasted really good. I smothered it with Maulls BBQ sauce which is Local to St. Louis and one of the best I ever had.....

accounts that you are deactivating because their accounts were affected or should they choose to log in, find their accounts are deactivated without any reason why?
< After a thorough investigation, we have concluded that this issue is NOT happening due to a technology issue with the DailyStrength.org site. It's been discovered that some members are using email addresses from outside organizations who have previously experienced data breaches. This information was not taken from DailyStrength's account database nor was DailyStrength's login system compromised.>
Outside organisations like gmail or yahoo? That must mean multiple email accounts were hacked, then hackers found their way to DS. And logged on to multiple DS accounts? But where on our email accounts do we store our DS password?
Maybe I misunderstood. Please expand.
And it would be good if you could answer Sambod’s question.
Ty from a cynical member.
https://healthitsecurity.com/news/blue-shield-altamed-patient-data-breached-in-business-associate-hack
"After a thorough investigation, we have concluded that this issue is NOT happening due to a technology issue with the DailyStrength.org site. It's been discovered that some members are using email addresses from outside organizations who have previously experienced data breaches. This information was not taken from DailyStrength's account database nor was DailyStrength's login system compromised"
I'm struggling to understand how that works. Emails have been hacked but somehow the hackers found a way of sort of sending their spam through the email so that it appears in the status line on DS? And it also makes the account send out lots of friend requests? And they did this while just doing a general hack, not knowing which emails would be attached to DS?
How can a hack of an email have that effect?
And for so many people to be affected it must be a popular email domain - so google, aol, yahoo etc.
Somebody sends us an email with a link attached. The email address might have someone's name on it whom we know. We might click on that link out of curiosity to see where it takes us and in comes the virus doing all kinds of damage, unbeknownst to us.
So someone may have joined the site and posted an email address containing a virus. Somebody else may have clicked on it out of curiosity and all hell broke loose under our noses. I hope DS tells the person before shutting him off so that if he was unaware of it happening, he can get his puter fixed.
It's nobody's fault except the one who posted the email address who may have or have not known it contained a virus.
That's my take on it but I could be wrong. Just thought I'd throw that out there.
I've never heard of anything like the explanation given here.
How would a general virus that infected a PC then compromise the platforms it is attached to in such a specific way? How would any platform like Facebook, Instagram, Twitter etc work if it had any members whose computers were virused or hacked if those viruses could then get onto those platforms and wreak havoc?
Those sites work because they have basic security protocols in place.
Also it would have to either be a very targetted or clever virus to go "Am I attached to DS? - if so place spam in status line - send out friend requests".
Very very odd explanation. I worked in high tech, including being around cyber security people and I've never heard of anything like this.
These accounts were targeted, not "accidentally infected" by someone opening an infected email.
Someone or some group knows to go after accounts that aren't active and haven't been used in a very long time. Those accounts are then hacked and the "illicit material heading" inserted and random friend requests to people sent out.
I get several of these, and I go back and look at who's been friend requested and the date. Because I have a Computer Science Degree, I'm curious. Its pretty easy to see how they go after "friends" they choose people who are recently active on Boards and the main Daily Strength News Feed. Its not Rocket Science.
None of this is "accidental" or "fed in through an infected email addy" someone/group is doing this.
Also to claim that an email domain like @gmail or @yahoo, etc. was at fault because they were targeted as a group and had a security breach is insane. There aren't enough of these for that to have happened. If something like that would have happened a huge percentage of DS clients would have been affected, it wouldn't have been just certain accounts of users who'd not been active.
Really Lame Explanation.....
You will see which friend requests were Accepted....and those would be people who are currently active on the boards.
The accounts that are being affected aren't actively being used by people.
And your question to me makes no sense, yes I can see which idiots accepted a friend request on what date from a person without checking them out....which is exactly what I said. Yes they sent out more, but some people actually look at a persons profile and their activity level before they just accept a "friend request" we all don't just accept everyone for the heck of it.
But hey I'll defer to your computer knowledge.
Even if the problem had originated via some e-mail virus (which I do not believe for an instant), the fact that DS has not stopped it speaks volumes on the lack of care, security, and oversight the website has been given.
I am appalled that this is the response we have received. Especially those of us who have been volunteering here for YEARS - 8 years as a CL for me - to be handed this nonsensical explanation after a MONTH of begging for help is unfathomable and unconscionable.
Of course i’m speculating. I don’t suppose DS will divulge WHICH outside organisations they were referring to.
As for accounts...probably 99.9% of the accounts on here are inactive. From the very beginning, I've been often logged on here at night....ie when spammers are most apparent. People/scammers or whatever who posted ads to journal after journal after journal....and that's from back when DS first added the journal feature. One was always home improvement, I don't remember what all else. I never bothered reporting them because they never bothered anyone.
Just doing the numbers (my ex has worked with statistics/BlackBelt, etc for 20 years...boy getting old). Spammers hitting random accounts...most are going to be inactive.
There'd be dozens of spam posted to TeamDS daily inspirational stuff, and the stuff that articles that the Experts used to post (I forget what they're called.) For years, I would take 10-15 minutes nearly daily to fill out report after report after report to the "public" posts from DS.
This (excessive amounts of spam) isn't a new issue. This was here on the old site. This was here when Doug was still on here. Due to declining active members, it's just a whole lot more noticeable.
It is different that accounts got hacked. But I doubt that there were more than a couple hundred of them, and with most affecting boards that aren't even active anymore. (Because I know that I am the only active member on the Hyperhidrosis board, and probably the only one that routinely checks out the Hidradenitis Supurativa board because an old friend used to be on there.)
Lets go with a hypothetical situation that it was Facebook that was hacked and due to the Facebook based sign in that DS introduced that's how "it" got in. I think that certainly could be the way in - also it explains DS's rather odd phrasing about "outside organisations"
My question would be, surely there should be some security protocols on DS that would stop the hacking/ hijacking getting a hold here? Many forums / sites offer linking of accounts with Facebook accounts - what do they do?