Unfortnatly this is nothing new. Spambots are using existing leaked password lists from users that use the same password on every site.
Best thing you can do is to security lock inactive accounts.
And, worse, with no need of stealing such account.
The fact is that since a week ago or so I am getting some spam messages posted by users with little or no activity, but registered years ago. All IP's are located next, and the message is tipically a link to a Telegram channel related to crypto.
It is not a flood, and actually doesn't pose a problem by now. The thing that seems scary is that it seems to avoid the pwd system. At least, the spammer doesn't leave track of having reset such pwd in the log...
I've noticed an increase in spam from old accounts over the past few days. These are accounts that haven't posted on the forum for many years. All the spam is advertising "Top-notch Casual Dating".
After analyzing other forums, I've noticed the same thing happening there too. But the most interesting part is that these forums operate on different platforms.
XenForo - https://pika-network.net/threads/top-notch-sasual-dating-verified-maidens.390411/
Vbulletin - https://www.nissan-club.org/board/showthread.php?t=53559
Invision Community -...
Recently I upgraded our forum from 2.2.8 to latest version and I noticed that many old users are becoming SPAM everyday (5 to 10 old memberships are stolen everyday and posting spam threads). I can't see any relation between the upgrade and the issue, however, this is what happened. Is it a coincidence? Is this a new method of SPAM attacking to steal the users accounts instead of new registration? I mean I am moderating this forum since 2006, moved to Xenforo since 2015 and I didn't face something similar.
Currently I am trying to control the SPAM posts by banning many valuable...