At 2103 Central Standard Time (CST), WPEngine sent out an email to their customers asking them to change their passwords. While normally not a concern to the vast majority of National Association of Mortgage Field Services (NAMFS) Members involved in fraud, it may be of concern for folks like Joel McCall, of McCall Field Services, whom we reported upon last year. It is simply a repeat of the failed Sunrise Property Pros LLC endeavor that he and Yanira drove into the ground like a tent stake as best I can tell.
After Foreclosurepedia released a scathing article in May, 2014, Joel and his henchmen went into damage control in an attempt to pull the wool back over the eyes of both the Portfolio Holders and Labor alike. To his credit, most of the issues are solved; however, I would presume at the expense of Labor.
Apparently, the user portal, sFTP, your WordPress database password, your original wp-admin WordPress account and any password protected installs and transferable installs were all compromised as WP Engine requested that they all be changed. In Full Disclosure, Foreclosurepedia does NOT use WP Engine. In fact, Foreclosurepedia does not use WordFence either. On 06 September 2014, Mark Maunder, CEO and Founder of WordFence reached out to me directly to handle an issue and ultimately to refund my money — Ticket #3562 if you are curious.
Wordfence Founder and CEO Mark Maunder, contacted WP Engine and received this response from Eric Jones:
As we indicated in our notification to customers at WP Engine, the security of our members’ personal information is a top priority. In response to an exposure involving some of our customers’ credentials, we are taking proactive steps to mitigate the issue. While we have no evidence that the information was used inappropriately, out of an abundance of caution, we have initiated an investigation and notified customers that we are invalidating five passwords associated with their WP Engine account. Customers were provided with specific instructions on how to reset each of them.
Again, we are committed to the protection of our customers’ personal information. As we learn more from our ongoing investigation, we will provide updates to our customers if we learn of information that affects them.
What should be of potential concern is the fact that Wordfence, with over 10 million downloads, was apparently hosted on WP Engine. Above and beyond the bad blood between Maunder, Wordfence CEO and myself, the fact of the matter is that no one knows, for sure, what the ultimate score is going to be with respect to the penetration. I applaud both WP Engine and Wordfence for publicly releasing that which they have; however, out of an abundance of caution, Foreclosurepedia has issued an Emergency Alert — this is only the third time in our existence that we have issued one — to review Security Protocols and to ensure that each Client has a Disaster Recovery Plan (DRP) in play.
Many of you are aware of the fact that the National Association of Mortgage Field Services (NAMFS) has been using email servers incapable of sending encrypted email as they does not support Transport Layer Security (TLS). Coming on the heels of the NAMFS Website being hacked multiple times and even reported by Google in its Search Results, one would have thought that NAMFS, as a Trade Association, would want to protect its Membership. In light of the fact that Eric Miller, NAMFS Executive Director, is annually paid OVER ONE HUNDRED AND TWENTY THOUSAND DOLLARS CONSUMING OVER SEVENTY PERCENT OF ALL MEMBER DUES, it boggles the mind why they cannot afford the Five Dollars per month to run Google Business Apps. The exodus of over ONE HUNDRED AND FIFTY NAMFS MEMBERS since 2011, is a testament to the fact that the Miller Regime is both out of touch and perhaps being compensated to allow for these types of inactions.
Foreclosurepedia has led the charge in IT Security within the Mortgage Field Services Industry since our inception. In fact, Foreclosurepedia was the only Media Outlet to report upon the NAMFS Website being hacked three times in nearly as many months recently; the only Media Outlet to report upon Brunswick Companies along with M&M Mortgage having been left responsible to viruses being sent out to thousands of Industry Contractors, and later today, we will be THE ONLY Media outlet to report upon, later this week, TaskEasy‘s Rebekah Smith, Account Executive at TaskEasy, having her email address used to forward a virus, the same type of payload delivery virus we reported upon in South Carolina. It is yet another sign that the Industry’s inattention to cyber security is now spilling out on all shores.
Did I forget to mention the ForeRunner hack, which was a Joe Badalamenti production whom is the owner and founder of Five Brothels as I like to think of them as.




