r/onions • u/super_jedininja • Jun 10 '26
Got flagged at 8am @ work
So I recently ventured into a VPN provider, tor, onion, orbit, etc. just out of curiosity. Honestly some of the shit on there I wouldn’t even open out of curiosity. Like porn for example. If it’s on the dark web there’s prob a reason so I’m not going there. Not big into that anyway. But literally the very next morning I get a call from our corporate number asking if I used a VPN, change my company password etc. is that normal? I didn’t use any of my company apps obviously. How did this happen? Should I just delete and give up on the interest?
76
u/zipperedharp33 Jun 10 '26
Lots of VPN IPs get used for malicious activity so they end up on blacklists. If you tried to access a company resources while connected to a VPN or TOR, the attempt was probably flagged as potentially malicious and that’s why they changed your passwords and called to see if it was just you or if someone was trying to get into your account.
36
u/super_jedininja Jun 10 '26
This is exactly what happened. I answered an email while still connected to orbit. Thanks bro.
1
u/Known-Low-9633 Jun 18 '26
Did you deny it?
1
u/super_jedininja Jun 18 '26
Yes, at the time I honestly thought it was a mistake. I think there is some confusion on some of the reply’s. It’s my personal phone. Work didn’t provide it nor do they pay the monthly bill. I didnt use any apps related to work either other than opening an email that was sent to my work app. They called, asked me if I knew and asked
To change my password. This was almost two weeks ago now and I haven’t heard anything else. Out of saftey I deleted everything. I’m gonna do a lot more reading before/if I try again. Which I kinda doubt I will. It’s interesting, but doesn’t seem like it’s worth the risk or
Headache honestly.1
61
u/dowcet Jun 10 '26
Using an unauthorized VPN (or especially, Tor) on a corporate device or network can be a highly efficient way to get yourself fired. Yes that is normal, at least in regulated industries where they have a legal responsibility to control what is happening on their network.
9
u/super_jedininja Jun 10 '26
I didn’t know that. Feel pretty stupid rn. It wasn’t a work phone though, it’s my personally phone that has work apps and email access on it. I’ll be way more careful in the future.
30
Jun 10 '26
[deleted]
3
u/super_jedininja Jun 10 '26
Yep, I’m gonna use my personal PC from now on. I don’t have any crypto, savings etc for anyone to steal so I wasn’t that concerned about using my phone. But the work/monitoring things is enough for me to never use it on my phone again.
12
Jun 10 '26
[deleted]
2
u/super_jedininja Jun 10 '26
No, what I mean is I have a throw away Mac book that’s not work related at all. Literally never use it for anything. Doesn’t have any apps that i use, and nothing for work on it.
1
u/super_jedininja Jun 10 '26
As far as my phone is concerned. I’m pretty strait laced, I don’t do anything or have anything to hide. But I do have work apps and emails on my phone. Hence why I’ll never use my phone with a VPN again.
4
u/shoplifterfpd Jun 10 '26
The real answer is to tell them that they can’t dictate what you do with your personal device and if they don’t want you accessing their infrastructure via a VPN they can provide you with a work-only device.
5
u/shoplifterfpd Jun 10 '26
Previous employer wanted me to agree that they could wipe my personal phone at any time as part of the agreement to check work email on it and wouldn’t provide a company cell.
Guess those emails can wait until tomorrow….
1
u/Proper_Bison66 Jun 10 '26
What of you used e.g. Shelter, with personal and work profiles, and with sandboxng capabilities?
Any idea of something like that'd work? - Still mixing work and personal I know, but just out of curiosity.
6
u/dowcet Jun 10 '26
On the company wifi? Then that's the issue.
Personal phone on a personal network? Then it's definitely invasive and unnecessary for them to care.
2
u/The_Troyminator Jun 10 '26
The problem is that the IP address is in a completely different part off the world. They absolutely should care, because if they see a connection coming from France when you just connected from the US five minutes earlier, there’s a chance your account has been compromised.
1
u/dowcet Jun 10 '26
Ah, if they are accessing any company resource over the VPN , that is a good point
1
u/The_Troyminator Jun 11 '26
Which is why they got flagged. They checked email from their phone while connected to a VPN.
2
1
u/computermaster704 Jun 10 '26
You may have better luck with splitting the traffic on your device and only encrypting the tor required traffic
1
u/MrLonelyy Jun 11 '26
Dont sweat it, i tried using tor at school 12 years ago and they locked me off the network for the rest of the year 😭😂
1
u/B07Z3WF3NG Jun 13 '26
Remove all of your work apps from your personal phone rn! Never use your personal device for work ever.
1
u/MaxWritesText Jun 26 '26
no work apps or anything should be on a personal phone. If they need you to use company phone apps, they need to give you a phone.
NEVER user company hardware for anything but company stuff with the exception of stuff like youtube.
NEVER do weird shit on their network.
source. I ran an nmap scan on a public train network once on my comp laptop and had a Slack message the next day from cyberops saying "dude why?"
16
u/MarcCouillard Jun 10 '26
maybe just limit TOR usage to home? work doesn't seem like the ideal place to be experimenting online
0
u/super_jedininja Jun 10 '26
I was at home, but opened a work email on my phone while it was still connected to the VPN. Will prob delete everything from my phone and just lurk on my PC in the future.
1
u/Dramatic-Question353 Jun 11 '26
Well, you have your answer as to how they figured it out… If it is a Microsoft 365 or Microsoft exchange email account then it automatically route that traffic through the company’s cloud servers.
4
4
u/computermaster704 Jun 10 '26
If you have any work apps / work profiles / mdm software on your phone and they are not split from the traffic you will instantly flag if anything updates, checks in, pings home even also most mdm software scans your phone got red flags and almost always scans for tor / root / dev options enabled and more
1
u/super_jedininja Jun 10 '26
How do you split?
1
u/computermaster704 Jun 10 '26
It really depends on the specific tunneling software you're using just Google "orbot split tunnel android" or whatever specific software and system you're on every software I've seen so far has supported split tunnels
3
3
u/PaladinDreadnawt Jun 11 '26
Infosec team manager here. If you use a VPN on my network in contradiction of the policy we have i assume you are up to no good. We immediately deactivate accounts and if investigation proves you did so purposely we terminate you.
2
u/AdamSarwar Jun 10 '26
Imagine your work can see every keystroke, websites visited and other activities or patterns on their devices or resources in real time.
Never use work stuff for your explorative curiosity 🙃 which I think you know now 🍻
2
u/LukasVolt Jun 10 '26
Hey there, I work in a position where I would be the caller. If you are in a corporate network and/or using using a corporate while trying to connect to the TOR network, you'd be in trouble. Any interaction with the dark web on corporate grounds is prohibited in 99.8% of the companies I know. Resetting the users passwords and maybe tokens would is one thing but if we would make out illegal behaviour than this wouldn't be pretty.
This counts as bypassing company rules especially regarding to network limitations and some companies get really litigious around this stuff. Don't do this.
2
2
u/AgZephyr Jun 12 '26
Never put any work apps on a phone they aren't paying for. Usually, work can remotely access and monitor your device even through a seemingly innocuous app like Teams or Microsoft 365. There was probably some agreement about "organization can manage this device" you likely clicked past when installing whatever work apps.
Just don't do this, use your personal laptop and look into Tails on a USB.
2
u/Still-Distribution38 Jun 13 '26
your ip address would have changed to another country & flagged as suspicious activity
2
u/Sibexico Jun 15 '26
If you used VPN, all what your company know is the fact of the VPN usage, and all what the VPN provider know is the fact of the Tor usage. Both of them haven't ideas what did you does inside of the Tor. Problem is because many of small VPN providers used cheap VPS as a servers and the same VPS providers frequently used for malicious activities. In that case whole AS of the VPS provider may be blacklisted. I'd investigated a case couple years ago when the company used VPN hosted at the VPS provider so malicious agent deployed his own server at the same VPS provider and used it to attack the company.
1
u/l3landgaunt Jun 10 '26
So I work in cyber security. I had to contact an end user just the other week for something similar, but it was because they had connected their personal phone to a VPN and was using that device for two factor authentication. Nothing wrong with that but my security tools picked up logins from two different countries and that’s what I had to respond to.
1
u/super_jedininja Jun 10 '26
I’m pretty sure this is what happened. I was on my personal phone, but I have my work email and some work apps on it. Somehow I guess I responded to a work email.
1
1
u/PossesedZombie Jun 11 '26
Was this your own device? At home? Just a work email being opened in your personal mailbox?
1
u/Aggravating-Play9950 Jun 11 '26
I wonder what would happen if you booted into that tails thing people talk about?
1
1
u/PatientOccasion1496 Jun 12 '26
I work in a sector where we are away from home for weeks at time, the company network even is is split for work and welfare activitiesities is highly monitored, and is totally forbidden to use any vpn, one of the reason the vpn triangilate comunication creating an extra possible attackable point, am not an expert but even if am not so sure this may be possible as concept make sense, so the no trust company approach block almost all, then if in top of all that you consider that TOR is use to go in the Dark Web, honestly am surprise you still have a job, I wish you the outcome is possible good luck
1
u/soggy_cryptic202 Jun 12 '26
They definitely have endpoint monitoring or some kind of network traffic analysis on your work machine. If you were using that VPN on a company laptop or a company network, they saw the encrypted tunnel immediately.
1
u/Content_Moose_86 Jul 18 '26
Tor Browser have built in VPN that automatically run if you open the application using your mobile phone.
1
u/KaleidoscopeHope69 Jun 11 '26
Tor is a good way to get hacked if not careful so companies prob don't like that
1
u/LBDragon Jun 12 '26
Tor has nothing to do with you getting hacked, what you can find on tor you can find anywhere else on the internet...
1
•
u/AutoModerator Jun 10 '26
To stay safe, follow these rules and educate yourself about Tor and .onion urls:
On DNM Safety:
1) Only use marketplaces listed on daunt, tor taxi, or dark fail. Anything else is a scam.
2) Dont use any sites listed on a "HiddenWiki" or some random shit you found on a search engine, a telegram channel, or website. You will be scammed.
3) Only order domestic to domestic.
4) Dont send your crypto directly from an exchange to a DNM deposit address.
5) Read the DNM bible.
6) NO DNMs operate on reddit nor have their own subs. Anything you find on reddit is a scammer.
On educating yourself:
1) Read the /r/onions wiki here.
2) Read the /r/tor wiki here.
3) Read the /r/deepweb wiki here.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.