Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Spammer Keep invite me and other to this project and this site doesn't have tool to help

Deleted user August 26, 2023

I have person information on this account I can't make private so they can get my name and email address

I have already had an attempt against my microsoft login

I can block these groups of people

 

It seem that if I want to have a bitbucket account or a trello account I am stuck with this piece of shit spammer accessible atlassian shit

I delete all their shit spam tickets whenever I sign on, and I have disable email notif, but I was really hoping for a better way to protect against this shit

2 answers

0 votes
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 27, 2023

Eh?

There's no personal private information available here, and nothing is accessible to other people.

Spammers here can abuse free Atlassian systems to send mail to any email address they can find in public, or from harvested lists, or even make them up (it would not be hard to guess what my email address is at Adaptavist for example - you would get it right within the first few obvious guesses at the bit before @adaptavist.com).  The spammers have no access to your personal information on your Atlassian account, they are just sending spam to a range of email addresses that they think might be valid.

If you're seeing exposed personal information, then it's you who has published it, not Atlassian.  Atlassian systems all have security and access controls, and it's up to your organisation to configure these correctly (the defaults are generally "only let people in that have been added by an admin")

There is no security or privacy issue on the Atlassian side here.  The problem is that malicious people can easily abuse free Atlassian systems.

0 votes
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 26, 2023

Welcome to the Community!

I am sorry that you are getting spam from Atlassian hosted systems, and I'm sure that Atlassian are too.

Atlassian want to hear about all malicious systems, as they currently have a monitoring system looking for potential abuse that needs to learn more!  They're looking to improve their detection so that they can shut down or even prevent the creation of malicious sites.

Please forward the emails you are getting to the abuse email.  You do not need to explain or add anything to it, just forward the whole thing - it gets processed into a task for an Atlassian to look at the site that sent it to see if it is malicious

There is no need to send more than one per site.  Over the last month, I've had about 40 spam mails from 3 different sites, so I've sent on 3 emails.

You may not get a human response, but I know that the team investigates all the reports.

The long explanation (which I don't know if you are interested in, but in case other people land here and do want to understand the problem), is;

Atlassian want people to use their software, so they make it easy to create an Atlassian account, and that lets you create new Atlassian Cloud systems (Jira, Bitbucket, or Confluence). 

The idea is "set up a free system, use it a bit, then expand up into a paid system when we grow".  It's not a bad business model, but it is open to abuse.

People (and 'bots) can create a free Jira system really easily, and then automate spam from it almost as easily.  So they do.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events