Sumit Kumar Profile picture
Jan 8, 2019 β€’ 12 tweets β€’ 3 min read
😱😱 WOW... get this:
A friend went to his HR department today asking why he did not receive salary since two months. HR had to check and apparently, they got hit by fraudsters in the most insane way. You should read this as a warning πŸ‘‡
It all started with a friend searching for an apartment on german website @Immobilienscout. To verify his identity and income he had to upload his ID and the last two income reports from his employer - standard practice in german apartment hunting.
Thinking this data is only shared with serious apartment offers or not at all was something that he (and I until now) considered obvious. But *someone* now had his ID, bank account data, salary, employer name, employee number and signature. So...
That sneaky bastard sent a FAX(!!!) to the companies HR department to send the salary to a new account from now on. Happened 3 months ago. HR did it because it had his sig, employee #, etc. A fax is a valid official document even if the sender is not identified (opposed to email)
Neither HR nor the bank got suspicious that the new bank account had a different holder name but that name is also not bound. You can write whatever you want as long as your IBAN is correct.
There was no additional notification to the employee (two-factor-auth anyone?).
Not sure why the fraudsters even tried though. Bank will refund everything but it's still a big blow to the privacy & data protection of the company and of course ImmoScout.
So please, black out all data that is not needed on this documents, like your employee number, bank account, etc. I blindly trusted those services and I'm definitely only lucky that it did not hit me yet. Uploading this data to @Immobilienscout seems like a huge mistake.
Seems to be exactly the reason why there are so many fake listings. Nice observation πŸ‘
Small update: bank did not refund yet and it’s still up in the air. They obviously see the fault on HR side. So all parties are blaming each other right now.
I talked so much about this today with my colleagues as it is such an interesting attack, exploiting different weaknesses in different established systems. From german housing, to tech, to money transfer, auth, etc... πŸ€“. Interesting and scary.
Let me make this perfectly clear: I wanted to share this to show the problem with german apt hunting. I have no idea about @Immobilienscoutβ€˜s data topics. I never wanted to imply a leak or anything. It’s normal to give salary verification and ID to landlords in Germany like this.

β€’ β€’ β€’

Missing some Tweet in this thread? You can try to force a refresh
γ€€

Keep Current with Sumit Kumar

Sumit Kumar Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @TweetsOfSumit

Jan 13
In 2018 I wanted to invest more. I cut down costs until it hurt. At that point, cutting 100€/mo is more difficult than earning 300€ more. So I started to very deliberately work on my salary.

It grew 4x since.

Here's what had the most impact πŸ§΅πŸ‘‡

Image
🀝 learn to negotiate. Seriously, it's like a few books and articles + some practice and it makes you 20% to 50% more. Best ROI of all.

🏁 learn the goals of your manager (personal and org) and help them reach them.

If your (only) goal is more salary, you need to get promoted, have more impact, and have people rooting for you. If you help them succeed, they want you to stick around and take more responsibility
Read 11 tweets
Jan 7
I'm running a company on the side while being employed at @stripe full time.
These are my top learnings balancing a side project and a full-time job 🧡
@stripe πŸ’ž Get your partner on board. Especially if you have kids - you absolutely need support from your partner and a shared goal of what you're working towards. Side-projects are fine when you can just ignore them if time is scarce. But you can't ignore a business with employees, etc
@stripe Your partner will be a huge help, motivator, harbor, shoulder, fan, hugger... they have to be on your side. If you're juggling full-time job AND a business, you can't do more juggling at home. Even if they might not directly work on your business, they are in this with you.
Read 24 tweets
Oct 22, 2021
I get asked a lot about my legal setup. I'm no legal advisor of course but here's what I do. I own a holding company, which owns my operational projects like Parqet. One of the operational co's is like an incubator where I start new projects. Once a project reaches ~10k MRR I...
spin it out into a new company owned by the holding. The holding could also invest in other startups or even stocks - however, all my current stocks are bought privately. But with this setup, I'm prepared for the future re starting companies, investing in and/or selling them
Will talk a lot more about this stuff in my big ass video series about bootstrapping a company from 0€ to 200k€ ARR in 18 months. If you don't want to miss it, add yourself to my @revue πŸ‘‡

getrevue.co/profile/noteso…
Read 4 tweets
Mar 29, 2021
Many people around me considered my move from Head of Engineering (Manager) at SN to an individual contributor (IC) role at Stripe a "step down". I don't think it's a step down at all.

THREADπŸ‘‡
First of all: I know I will learn A TON at Stripe - no matter which role. This is by far my biggest deciding factor when changing positions / companies
Next, IC vs Manager are just roles. It doesn't matter to me as long as I can have meaningful impact on fun, challenging, interesting work.
If a manager is needed and I'm a fit: happy to step in. If there's a great manager already, I will be the best teammate I can be.
Read 11 tweets
Jan 28, 2021
After 4 years, tomorrow is my last day at @sharenowTech - here are the learnings of that time that stay with me for years to come.

Thread πŸ‘‡
Don’t just complain about the situation, do something about it. I’m much happier when I feel I’m in control.
When something sucks, I ask what I can do to fix it. Not blame people.
Climb the latter if you want bigger organizational impact. Don’t climb for money. Especially going into management is not a step up but to the side. Make sure to know why, because losing a good IC for a bad manager is the worst for everyone.
Read 23 tweets
Jan 21, 2021
I just finished Zero to Sold by @arvidkahl - here's what I got out of it for me personally, to apply on my efforts to build tresor.one πŸ‘‡
πŸ‘‰ Product to Business
I'm somewhere between Survival and Stability stage. I should (and do) focus on building a business around the product. Pumping out features alone will not make T1 sustainable. There is much more around it and I feel the pain of not focusing on it earlier.
πŸ‘‰ 2020 went well
I think I did an OK job last year to build, validate and grow the project. It was validated when the first customer entered their credit card details, and it continued from there.
From 42€ payout, to >8000€ in 9 months.
Read 12 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(