Suddenly receiving New Post notifications
-
Yesterday I found a new post notification in my email from one of my websites, mineolaamerican.com. I clicked “manage subscriptions” and it said I began to follow that site the day before (July 6). I never chose to follow this site.
Today, I have the same kind of new post notification in my email from one of my other sites, thewestburytimes.com. Same thing – I clicked “manage subscriptions” and it says I began to follow the site on July 7. I absolutely did not.
Is Jetpack sending these notifications? Why all of a sudden? Was it enabled remotely across the board? Are my readers getting these emails without ever having signed up?
I know I can simply unfollow these sites, but I am more interested in finding out why this feature was turned on without my permission. If it is not Jetpack doing it, what else might be at fault? Thank you.
-
Jetpack doesn’t remotely subscribe you or anyone to a site. For you to start receiving notifications, you have to add the site your WordPress.com subscriptions manually.
I see that was done for 3 different sites over the past 5 days for your account. If you didn’t subscribe yourself, I’d recommend that you change your WordPress.com account password immediately, and set a new, strong, password, to make sure no one else has access to your account:
https://en.support.wordpress.com/passwords/#change-your-passwordI hope this helps.
Thank you. I will do that right away. I’d like to attach a screencap of what the email looks like though so someone can tell me if the formatting looks like what a Jetpack notification would look like, or something else.
Here is a link since I can’t attach the image: http://glencoverecordpilot.com/glencovenewpostemail/
Also, may I ask where you can see the 3 sites with notifications enabled for my account? I can’t find anywhere that lists all three together. When I click manage subscriptions in the emails, it only shows me that one site. Thanks.
That’s indeed a Jetpack notification email, although the comment button seems a bit misaligned. I’m guessing that’s linked to your email client.
may I ask where you can see the 3 sites with notifications enabled for my account? I can’t find anywhere that lists all three together.
You can see your subscriptions here:
https://wordpress.com/following/editThanks!
Hi I’m opening this question back up to add new information. I have 18 websites. Until today, only 3 of them had started sending me notifications of new posts without prompting. Today I started getting notifications from 2 others.
My account has been compromised in other ways. I’ve definitely been hacked and the hackerbot has added hundreds of new users to my sites, some as Admins.
I’ve changed my passwords and deleted the accounts and will keep an eye on it, but I don’t know the source of it. Since I use Jetpack through the same account for all 18 sites, does it make sense that the hacker got through my Jetpack account and not my individual WordPress accounts? Is having Jetpack what made me vulnerable to this attack?
Only one other person is an admin on all 18 sites – our web developer – and I’m sure his passwords are secure. I’d like to get to the bottom of this to prevent it from happening again. Thanks for any insight you can provide.
I have 18 websites. Until today, only 3 of them had started sending me notifications of new posts without prompting. Today I started getting notifications from 2 others.
To subscribe your email address to any Jetpack site, one would need access to one of these 2 things:
- Your WordPress.com account, where they’ll have access to your subscription list, and will be able to subscribe to more sites via the link I posted in my last post.
- Your email account. Once one has access to your emails, they can subscribe to any site that offers a subscription form by entering your email address, and they can then click on the link in the confirmation emails that are sent to your email address.
The person who subscribed to those additional 2 sites consequently had access to one of the 2 items above, or to both.
It’s worth noting that once someone can access your inbox, they can also access your WordPress.com account if you don’t use 2 factor authentication. They can indeed ask for a password reset, and receive the password rest link at your email address that they now control.
I’ve changed my passwords and deleted the accounts and will keep an eye on it,
Changing your local WordPress account password won’t help here, as it’s not needed to subscribe to a Jetpack site.
I would strongly suggest that you change your WordPress.com account password, following the instructions at the link I posted above. I would also recommend enabling 2 step authentication for your WordPress.com account, following the link I posted above in this message. It’s one more step required for anyone wanting to log in to your account.Once you’ve done so, change your email account password as well, and enable 2 step authentication there as well if that option is available. If you use a popular email provider like Gmail, Hotmail, or Yahoo, you’ll have the option.
Once you’ve done that, you’ll need to figure out what information the person who had access to your accounts could access:
- Do you store important information among your emails? You’ll need to change that info.
- Is your email account linked to other services? If it’s a Gmail account for example, anyone with access to the account could access and edit information for your YouTube account, Google+ account, Google Maps, and much more.
- If the person had access to your WordPress.com account, they were able to access and edit all sites currently linked to your WordPress.com account, and listed here:
https://wordpress.com/sites/ You’ll need to review all these sites for modified settings, posts, pages, or new users.
the hackerbot has added hundreds of new users to my sites, some as Admins.
Anyone with access to your WordPress.com account would be able to add new users to each one of the 18 sites linked to your account, via this page:
https://wordpress.com/people/teamYou’ll consequently need to review each and every one of your sites.
Is having Jetpack what made me vulnerable to this attack?
That depends how the hackers got in, but if they got it through your WordPress.com account, then yes, they were able to use the WordPress.com interface to edit all your sites linked via Jetpack. The interface was built to allow you to manage multiple sites from a central location. In the wrong hands, that means that multiple sites can be edited from that central location.
For that reason, it’s important that you use a strong password and 2 factor authentication on any service or app that can be used to access multiple other services at once. Your email is definitely an obvious target for hackers, but you should also protect any site management interface you use today.
I hope this clarifies things a bit. Let me know if it helps.
Thank you for the thorough response!
First, there’s no evidence that my email was hacked and IT assures me it is secure. I don’t use Gmail, I use Outlook at work.
Second, I have reset my wordpress.com password and would like to set up two step authentication, but I don’t have a mobile phone for work. Can I set this up with my landline work phone?
Third, I never set up the aspect of Jetpack that allows me to manage multiple sites from the same interface. So far I’ve only set up Publicize.
Thanks again for your help. I hope this puts an end to the whole thing.
First, there’s no evidence that my email was hacked and IT assures me it is secure. I don’t use Gmail, I use Outlook at work.
Good news!
I would still recommend that you change your password and set up 2 factor authentication if possible. That won’t hurt, and can only make things better!
would like to set up two step authentication, but I don’t have a mobile phone for work. Can I set this up with my landline work phone?
I’m afraid that won’t work. To use 2 step authentication, you’d need a device where you can install an authenticator app (like a smartphone or a tablet), or a phone that can receive text messages (SMS).
I never set up the aspect of Jetpack that allows me to manage multiple sites from the same interface.
That interface is available as soon as you connect Jetpack to your WordPress.com account, so you wouldn’t need to set up anything.
The topic ‘Suddenly receiving New Post notifications’ is closed to new replies.