83
PSA: Possible data breach at Nicotine River/River Supply
submitted over 5 years ago by talinutarionchim

First, emphasis on the word "Possible." I am making this post to both warn people and determine if it is widespread. So if you have ordered from them recently please check your email/spam and comment if you have received a similar email.

Backround:

I use an email forwarding service that generates a unique email address for each website/online account I use and forwards all messages to my regular inbox. I have exposed this address only once, a single order at Nicotine River about 6 months ago. I am relatively confident that Nicotine River is the source of the breach, as I have witnessed this several times with the email system I use.

Today I received a classic scam email to that address:

  • Stolen personal information in the subject line (such as name, password, or address) to get your attention
  • Threat that they had obtained a video from my webcam to blackmail me with ("hand to gland combat" haha).
  • Demanding payment in crypto currency to prevent spreading the video to family and friends  

It is unclear what information was extracted. The email subject was my real "firstname lastname ID########." I'm unsure what the 8 digit ID number is. Possibly a customer ID from a CRM database?

​

Edit:

To be clear, I'm not necessarily trying to put blame on River Supply. I just found myself in the unique position of using an email address 1 time and receiving pretty compelling evidence that my personal information was compromised. Figured this was the best place to find people that may have had the same experience and could help investigate.

I have seen nothing to suggest credit card info has been stolen. Regardless, I recommend everybody check if there credit card offers virtual cards. If not check out a service like privacy.com. I used a privacy.com burner card on this transaction so worst case they got a fake email address, a useless credit card number, and my address. And a sweet video of me jackin' the bean stalk according to the spam email.

Comments
Sort
55 points
 
by NicotineRiverover 5 years ago

Hey everyone, we're aware of the situation. This is not confirmed and we are currently working closely with Shopify as all of our store data goes 100% through their platform. In order for any data to be stolen from our site, it would have to be stolen from Shopify which is home to over a thousand e-commerce stores.

As of now, do not respond to the email. It is purely spam and is intended to scare you by threatening your privacy, it's a commonly used method explained here: https://www.merchantfraudjournal.com/sextortion-email-scam/

Thank you, when I have further details I will convey them here.

2 points
 
by mkweiseover 5 years agoMissing One Flavor

I think what everyone's anxious to find out is whether our payment card information may have been compromised. Hopefully you'll be back with good news on that front soon...

2 points
 
by vapingrayneover 5 years agoOne of "The Damned"

A few things

  1. Alarms and Worries me this silence
  2. I see you have not offered us anything for having our data stolen and blackmailed.
  3. By law are you not supposed to notify us?
  4. Will you say what action you have taken to stop this from happening again?

I know that I was just about to make another order a small one at 120ish hadn't finished it. Had the money, still do. Just recommended your company, really want to make a new order but. I would like to feel secure in doing so. I have been waiting on a word back from you before placing a new order. Been 19 day's or so

A %off discount and free shipping for 100mg+ would be nice, after all how many people would call to place order for the discount or is there a different way

Ty about to place an order somewhere

1 points
 
by prollynottrollinover 5 years ago

Cheap fuck

2 points
 
by vapingrayneover 5 years agoOne of "The Damned"

I'm cheap? I had a blackmailing email emailed to me. Heard nothing back about it. Still no reply. Has nothing to do with being cheap. If you bothered to read the rest of thread about 20 days ago this was and my father was involved. I just might go see a lawyer Monday about this. Still nothing from them telling me my sensitive personal secret information was stolen from them.

And by the way a simple here have this as a apology is a time honored tradition businesses

Btw isn't your reply disallowed

-42 points
 
by Youreawasteofspaceover 5 years ago

As someone who uses Shopify for their own business, don't pass blame. You guys gotta approve all the apps that access your customer data. Shopify doesn't send emails, so either someone was sloppy with their password or you guys let someone steal this data through negligence.

27 points
 
by NicotineRiverover 5 years ago

Hey youreawasteofspace, regarding our apps Shopify already has a team doing an investigation on all apps associated with our website for anything related to these scam/blackmail emails. Although Shopify houses 100% of our data if this is related to an app that is improperly accessing our customers email addresses, it will be deleted immediately from our store.

For those who are skeptical regarding their payment information. Payment information submitted to a Shopify store is kept in a securely encrypted, entirely separate location and cannot be accessed. We do not keep any payment information on file and never will due to these reasons.

I will respond here when I discover further information regarding this matter. As of this moment, this is still under investigation.

Thank you

5 points
 
by NicotineRiverover 5 years ago

Hey everyone, just an update. We're currently awaiting Shopify's confirmation regarding the situation, but ours and Shopify's educated guess seems to be that an app that has access to our,

Customer Names

Customer Emails

was somehow linked to a breach that also included that data from our store. This is still not confirmed, but is expected to be soon. For those still curious, all of our customers payment information is kept in an entirely separate encrypted location and is safe. We appreciate your understanding and hope to check back soon. We'll have confirmed source of these spam emails once and for all!

Referred to us by SessionDrummer on ELR. If you'd like to check out your emails status regarding data breaches go here,

https://haveibeenpwned.com/

Thank you everyone for your patience!

-46 points
 
by Youreawasteofspaceover 5 years ago

Thanks for down voting me for calling you out.

24 points
 
by mkweiseover 5 years agoMissing One Flavor

Thanks so much for the heads up, from now on I will remember not to play with myself while shopping at River Supply Co...hard as it is to contain the excitement caused by the anticipation of trying new flavors.

19 points
 
by talinutarionchimover 5 years ago

If you stop doing what you love, then the scammers win. I'm simply suggesting you keep an eye out for fraud on your cc statement.

23 points
 
by TeslaDelMarover 5 years agoI Survived Grack

Yep, I have the same email in my spam, it has my full name (middle initial) in the subject. Thanks for the heads-up, time to call my bank...

9 points
 
by rapemybonesover 5 years agoFrugivore

Same here, also got the same exact email. Jokes on them though, I have no webcam and I'm broke as fuck anyway lol.

2 points
 
by calmerpoleeceover 5 years ago

Hahhaa right? What do they think we are boomers? It would be more compelling if they said they hacked your phone and used the front facing camera....

8 points
 
by Barbarakeover 5 years ago

Add another one to the list. Got the email this morning. Don't have a webcam. Also, I'm female, LOL.

1 points
 
by CloudKickersover 5 years ago

I'm also female with no webcam lol They were asking for DashCoins

7 points
 
by BitRedactionover 5 years ago

Just replying to add one to the pile.

Wouldn’t rush to the conclusion that it’s necessarily usernames and passwords though, I’ve only ever used guest checkout with them. Not that that’s any better.

6 points
 
by mixsomniaover 5 years ago

https://haveibeenpwned.com/

A member on ELR showed me this site,

it can show you if your email account name has been acquired by known data breaches

NOTE: if pwnd it does NOT mean your email is hacked just listed.

I just checked and I actually have been pwnd by an adobe breach, my email and bank is safe

but considering I used my name as my email like an idiot years ago,

I'm not taking any chances time for a new one

1 points
 
by cremestickover 5 years ago

all you need is a new password

3 points
 
by mixsomniaover 5 years ago

once your email has been pulled, it is now pretty much a known and shared target forever.

​

my EA and ubisoft account is already being used all over the world (Like I really care) and bliZZard account password was reset recently, steam is still safe.

hackers and bots start cross referencing for other usernames you have used build a profile, brute forcing passwords etc

plus like I said i used my name for my email long time ago when cyber warfare wasn't just a hot deal, these days that can be a pretty serious issue with identity theft.

So it's also a privacy thing and it's easy enough to make a new one

1 points
 
by St1llFrankover 5 years agoThis flavor... This is not my kind of flavor

> Yep, I have the same email

Same here. It freaked me out at first. Not the masturbation part lol. My full name and email adress sent from russia with love by some dude named Nikolai. I was wondering how they got that information..

1 points
 
by zucciniknifeover 5 years ago

Probs just wants to go bowling.

16 points
 
by Slippery_Molassesover 5 years ago

I got a similar email yesterday. I have only used this email at nicotineriver and big sites like amazon/walmart. Here is the email text:

"A large number of lovers of tickling their schlong on adult sites after a while receive this text!
Terrible video of you tickling your wiener was shot using your web camera. I believe that your family will be surprised by it!
My spyware stole all ur enquiries, accesses to ur social networking sites and more data.
My english literacy leaves much to be desired since I am a foreign citizen (don’t try to consult with legal bodies they won’t be able to catch me).
You destinate 10.5 Lite coin to the address ltc(removed by me) and I will eliminate all of your staggering videos.
I give u 24 hours to perform payment for my silence (my system will notify me that you have opened the text)!
If you neglect these demands I will destroy your public image in front of your relatives, within forty-eight hours all ur compromising data will be directed to ur contacts and ur social networking sites.
This electronic-mail is short life, soon the access to it will be denied, don’t write to it."

10 points
 
by xGRANITExover 5 years agoSilky

I got this exact same one. hmm.

any precautions i should take with my bank and such? i just reported it as spam.

7 points
 
by Slippery_Molassesover 5 years ago

I have no idea but I used my credit card at nicotineriver so I am assuming they got that info. I have my credit card set to send me an email for any charge at any amount so I can catch fraudulent charges right away. I would suggest you do the same.

3 points
 
by shadow_mooseover 5 years ago

CVC's should never be stored on the site itself. You should have to enter that every time you make a purchase, which will probably end up saving everyone the trouble of dealing with getting a new CC #. I find it unlikely that they have enough of your credit card info to make a purchase. If they did, they'd be running a much more silent credit card scam instead of this. I'm sure Nicotine River has poor security, but to fuck up so bad that people get the entirety of their credit card info stolen such that the thief will be able to commit fraud with it, that's almost impossible to do.

7 points
 
by falls_asleep_readingover 5 years agoProud Sidebar Reader!

I got one of those emails, too, but I found it hilarious since I have neither a dick nor a webcam.

1 points
 
by ottorobotto76over 5 years ago

I got the same email, almost word for word. Wife and I had a good laugh over it and I deleted it. Thanks for the heads up!

12 points
 
by Slippery_Molassesover 5 years ago

/u/nicotineriver any comment on this?

9 points
 
by -fryguy-over 5 years ago

Well since we all got one and this is probably the only thing we have in common except for pleasuring ourselves in front of the computer, it is safe to say it was nic river..

Which really sucks because I have been getting spammed so bad in my email now..

6 points
 
by sadistic_tendenciesover 5 years ago

Too bad for them since everyone in my contact list has already seen my rock hard boner.

Wisdom of the day: Don't send your old lady dick pics while blackout drunk!

6 points
 
by -fryguy-over 5 years ago

So if I respond to the email with my goto dic$ pic would that go to nic rivers customer support... sorry Tyler didnt mean to send it to you.. but in my defense it was january and I just got out of the ocean /u/nicotineriver Can I get that discount code now out of pitty

6 points
 
by TechUnoover 5 years ago

River Supply Co. uses Shopify as their e-commerce platform and Shopify is the platform where your data was held. Shopify has had various data breaches and or vulnerabilities exposed in the last year including this one: https://www.zdnet.com/article/shopify-api-flaw-offered-access-to-revenue-traffic-data-of-thousands-of-stores/

3 points
 
by talinutarionchimover 5 years ago

True. Could be any number of issues. I was previously involved in a small eCommerce site. The number of platforms that customer information can be shuffled through is staggering. Shopping cart, payment processor, email marketing, analytics software, CRM, etc

5 points
 
by SacraficeMyGoatover 5 years ago

I recieve emails from them (never once ordered from them.)

I recieved a similar spam message a couple of days ago. Can't say for sure if it was them or not. The only information they obtained was my full name and an ID #, which I have no idea what the ID number is for.

5 points
 
by Ristol68over 5 years ago

Got one of these this morning. Lol

1 points
 
by iloovemeover 5 years ago

Same. O_o

5 points
 
by doctor_yapover 5 years ago

Yep, just checked and I have a similar email.

5 points
 
by _Passafire_over 5 years ago

I received this same email

2 points
 
by i_wank_dogsover 5 years ago

Moi aussi.

5 points
 
by Duffmcmcmcwhalenover 5 years ago

Damn, I feel left out now. I didn't get one of these lovely emails

1 points
 
by notworthteheffortover 5 years ago

Hey

Send me some money man. You promised you would. Alright. Do the right thing. Ok

Thanks from your friend that you owe money to.

3 points
 
by righteous__userover 5 years ago

I wonder if Anthony Weiner got this email?

3 points
 
by TimInElmiraover 5 years ago

Thank you. I've had my credit card breached twice by what I believe are vape shops. I am extremely pissed that these companies won't disclose this. I have avoided some shops out of fear of cc breaches: so potentially good shops lose and bad shops profit from my misfortune.

5 points
 
by YueAsalover 5 years ago

I know right. There is one I will never do business with again because of this. Now I only create a virtual card number, make my order than delete that number straight away.

3 points
 
by -fryguy-over 5 years ago

I got one also and know it was from one of 2 places. Nic river being one of them

3 points
 
by cjinctover 5 years ago

I got one of those, I recognize the subject line but I didn't open it. It went straight into my junk folder and I delete everything in that once a day

3 points
 
by gravyleg77over 5 years ago

Add another one had a message about jerking my dick on some website. I always use a Pre Paid credit card from Walmart and never use my other cards for online purchases.

3 points
 
by Assault_and_Vinegarover 5 years ago

I got one. Asking for 2.4 btc, that’s 21810.1 usd as of right now.

I just tried logging onto NicRivers site and my account doesn’t exist now.

4 points
 
by TheFez531over 5 years ago

My account is still active

4 points
 
by doctor_yapover 5 years ago

Bruh mine asked for 8 lmfao

Edit: I couldn’t log on to mine, but idk if the password was changed or I couldn’t remember, so I reset it anyway.

2 points
 
by Assault_and_Vinegarover 5 years ago

Probably a good video. Or you did something raunchy.

3 points
 
by jacls0608over 5 years ago

I'm just terrified. They somehow broke into my apartment, installed a hidden webcam on my PC, caught me doing the dirty, and then took the webcam back..

​

they left all my stuff though..

1 points
 
by iloovemeover 5 years ago

Mine said 20 lite coin.

Edit: apparently that’s only $1,218.60.. guess they’re getting desperate haha

2 points
 
by Kerbal634over 5 years ago

I only got blackmailed for .08 bitcoin:(

3 points
 
by Sociofuneticover 5 years ago

Just checked. Got it. Hand to gland. Lol. Nope.

3 points
 
by TheNewJediMasterYodaover 5 years ago

Got 1 lastnight at 9pm. Saying So you like to masturbate had my real name and a id number idk of. Wanted 8 lite coins or theyl send photos or video of me masturbating. I used NicotineRiver before Black Friday and rite before Christmas. I just deleted and changed passwords it was a email I use for junk and ordering stuff anyway. Found the email kept giving me an error messege after changing password when I try to check other mail so I shut it down and made a new junk email.

3 points
 
by kuri_sanTouover 5 years agoDiketones, Schmiketones

I ordered mid December. I got an email yesterday calling me a masturbator

3 points
 
by Ktmktmktmover 5 years ago

I got one too. By petalbeat429cambridge_llc.group@aol.com. i dont even have a webcam.

3 points
 
by Mac_Sn0wd3nover 5 years ago

I ordered some flavors from them that haven’t even come in yet and I got one of those emails today.

2 points
 
by kuri_sanTouover 5 years agoDiketones, Schmiketones

Happy Cake Day

1 points
 
by Mac_Sn0wd3nover 5 years ago

Hey! Thank you. I didn’t even notice. 😬

2 points
 
by TheFez531over 5 years ago

I have the same email too. While I'd hesitate to point the finger at anyone without conclusive proof, it does seem like it may be from Nic River, cause that's what we all have in common here. Unless it's from LB or BCF....

2 points
 
by mjag1over 5 years ago

I checked my email and spam folder and no email like this and I have ordered from them probably 25 times, last time was probably a month ago or less.

Was it sent this morning? I checked for time stamps for today and a few back for yesterday as well.

4 points
 
by mjag1over 5 years ago

Oh wait, I did get an email in my spam folder from Sarah that says "FUCK- me don't stop never...." so I have of course setup a date for later this evening....it is real, I swear :-)

2 points
 
by TheFez531over 5 years ago

I've had 2 orders this past month, has everyone else who got the email ordered recently as well?

3 points
 
by Slippery_Molassesover 5 years ago

I ordered during the black Friday sale

2 points
 
by Barbarakeover 5 years ago

I last ordered December 20th, before that was October 28th.

2 points
 
by doctor_yapover 5 years ago

Mine was October 23~

2 points
 
by babepandaover 5 years ago

I have exactly the same here ! Waiting for words from NicRiv !

2 points
 
by drock7050over 5 years ago

I got the same message. Bought from them multiple times as well.

2 points
 
by Jtwasluckover 5 years ago

Woah I got the same email. Do you guys recommend changing passwords too? How severe is this data breach. Is it just access to our email address and name or is it a lot worse?

1 points
 
by talinutarionchimover 5 years ago

No evidence of anything besides name and email. Not even conclusive evidence nicotine river was the source or had anything to do with it. Probably no need to panic.

But if you use the same password on multiple sites, then yes change them. Not because of this thread, but because that's dumb. Get a password manager.

1 points
 
by iloovemeover 5 years ago

Or a 2FA token app. I use authy on all possible places.

1 points
 
by Jtwasluckover 5 years ago

I use authy but some of my 'less important' accounts do use the same password.

2 points
 
by c82mcleanover 5 years ago

I recieved one last night. Thought it might of been because of the Zynga data breach last year. But this makes sense. Glad you used the generator. Helps to know.

2 points
 
by jo-jo70over 5 years ago

Same here. Received it yesterday. Exact same format you described

2 points
 
by MackRenover 5 years ago

I got this email recently as well. Just a heads up, the account name and credit card holder name were different on my last order. The scam email used the card holder's name and not the name on the Nic river account

2 points
 
by kuri_sanTouover 5 years agoDiketones, Schmiketones

Same here. My NicRiv email, my friend's name (card holder)

2 points
 
by Mad_Goukiover 5 years ago

I haven't received one. Just wanted to propose another possibility. It could also be the age checker service, since they need name and other details to verify.

edit: actually I did receive the email. They only want 0.06 BTC from me tho :(

1 points
 
by EdibleMalfunctionover 5 years agoI found my thrill on Blueberry Hill

So. Is there video?

7 points
 
by talinutarionchimover 5 years ago

I'll reply and ask for a sample

9 points
 
by EdibleMalfunctionover 5 years agoI found my thrill on Blueberry Hill

I too have received the email. I went ahead and paid them.

8 points
 
by ID10-Tover 5 years agoWinner: Best Recipe of 2019 - Counter Punch

I sent back a list of people I wanted them to send their video of me "tickling my knob" to. Save me the trouble of sending it to them myself.

1 points
 
by bloflyover 5 years ago

This sounds an awful lot like an email/phishing scam that has been going around for a while.

Two things: I would be careful pointing the finger at any source, until you have absolute incontrovertible evidence of that being the source. I would also not respond to the email, as you will be pegged as an "active account" for any scammers keeping track.

These sentences contradict each other: >First >I use an email forwarding service that generates a unique email address for each website/online account I use and forwards all messages to my regular inbox. I have exposed this address only once, a single order at Nicotine River about 6 months ago.

If you are using what I think you're using, your real email address shouldn't be exposed. Or are you saying you used your real email address for the NR order?

9 points
 
by talinutarionchimover 5 years ago

My real personal address wasn't exposed. It was the address unique to that single NR order that the spam message was sent to. My real name was in the subject line, suggesting that they accessed shipping/billing info.

I have a received 3 messages to that email. NR order confirmation, NR shipment confirmation, and spam message today.

3 points
 
by bloflyover 5 years ago

Got it. I thought you meant your "real" address was exposed. Since others are reporting the same email from the same source, it certainly lends credibility to your theory.

7 points
 
by TimInElmiraover 5 years ago

He's saying he used a virtual email address once, on a single order at Nicotine River. Hence, with a data breach, the scammers would get his real name address, credit card information and the virtual email address. Irrefutable evidence that NR has been breached.

3 points
 
by bloflyover 5 years ago

Not necessarily. His email system, service, or even PC could be compromised, giving the scammers all sorts of info regarding his various accounts.

I'm in IT, I deal with this stuff daily.

1 points
 
by stabloggerover 5 years ago

Yep, it's a classic, like the nigerian prince who wants to transfer money, the heritage by an uncle you never knew or the lottery win in a lottery you never heard about before.

1 points
 
by SeiferLeonheartover 5 years ago

Regarding the ID, some antispams behavior analysis can cause e-mails with the same title or content to be blocked, so spammers use a random number generator to bypass the filter. Although the already generated customer ID could serve the same purpose, lol.

1 points
 
by RichardMcCartyover 5 years ago

Received this today too. Ugh.

1 points
 
by sas2470over 5 years ago

I recieved the same email,the email wasnt used at nic river.

1 points
 
by sas2470over 5 years ago

The only companies used on that email were underground vapes and element vapes. I also recieved a version of the email at my main address,which was used at nic riv

1 points
 
by ApeCloudzover 5 years ago

Happened to me too yesterday...

1 points
 
by BrickHardcheeseover 5 years ago

Can confirm, for the same email in spam folder.

1 points
 
by V6A6P6Eover 5 years ago

I got one too! I was asking for donations to pay it off at work. Haha

1 points
 
by Thenobody42092over 5 years ago

I already sent the DashCoins, you're saying the email was a fraud? I also made a NR order a few weeks back during the NYD sale

1 points
 
by PacificBlisterover 5 years ago

thats not good :/ i havent received an email like that but glad you made the PSA

1 points
 
by [deleted]over 5 years ago

Yep, got one here too.

1 points
 
by Schuywardover 5 years ago

Damn, just saw this and checked my spam folder I have the same email as well! No doubt they leaked some info.. theres no way we all have this in common by chance

1 points
 
by Friedsteak7over 5 years ago

I have the email as well

1 points
 
by deja_blue-flover 5 years ago

Found one waiting for me in my spam folder. I wonder how they managed to take the tape off my webcam and give me a shwang to tickle without me noticing!

1 points
 
by Kerbal634over 5 years ago

I'm gonna have to agree, I just got a similar email. I told them that I've got a big dick so do it lmao

1 points
 
by Angelam2418over 5 years ago

Yep, I received that same spam/blackmail email 2 days ago and I just placed an order with Nicotine River 12 days ago.

I haven't seen any suspicious bank activity, but keeping an eye out and definitely checking out privacy.com for next time.

1 points
 
by WK3iSmEover 5 years ago

In my email too. Wasn’t the slightest bit worried, albeit curious about how my email address had fallen into asshole hands, but I have ordered from a shopify run site recently. Thanks for info

1 points
 
by samm4over 5 years ago

Received this email a couple days ago, they asked for 7 dashcoin which looks to be about $.15. LOL

1 points
 
by Tehsid67over 5 years ago

I recently made an RiverSupply order, after not having made one for around 6 months. I too got a "sextortion" email. My order date was 1/24 and i received the sextortion email on 1/27.

1 points
 
by jadeblackhawkover 5 years ago

I got one of those the other day, laughed, and deleted it.

1 points
 
by LuvsMetalSatanWaffleover 5 years ago

I got the email about exposing me for wacking off if I didn’t pay up. Lil do they know I keep my webcam covered. ;) lol

I also use throw away email accounts, random generated passwords and privacy dot com cards.

Ain’t gonna get me that easy. Lol

Thanks for the psa though I haven’t pinpointed which site or platform got hit as of yet.

1 points
 
by vapingrayneover 5 years agoOne of "The Damned"

Was checking my gmail and I have it with my father's name who we ordered under since he paid upfront for me because I didn't want to wait.

Wasn't to happy with river supply co but was about to give them a second chance now not to certain.

I've got to wonder if my information is safe

1 points
 
by talinutarionchimover 5 years ago

This could be a useful data point. Have you associated your father's name with your email address in the past? Or just for river supply order?

1 points
 
by vapingrayneover 5 years agoOne of "The Damned"

To be honest a couple of sites. But I got it around the same time as everyone. Had to come from site though

1 points
 
by vettemn86over 5 years ago

Got one of these as well on 1/25, ordered from Nicotine River on black Friday. Credit card looks untouched though so it might just be email addresses

Site copyright © 2025 DIY Compendium. Data courtesy of Reddit.