I had a secondary Gmail account with a really nice short nickname (from the early invite/alpha days), forwarded to another of my mailboxes. It had a weak password, leaked as part of one of the many database leaks.

Eventually I noticed some dude in Brazil started using my Gmail, and he changed the password — but I still got a copy of everything he did through the forwarding rule. I caught him bragging to a friend on how he cracked hashes and stole and sold email accounts and user details in bulk.

He used my account as his main email account. Over the years I saw more and more personal details getting through. Eventually I received a mail with a plaintext password... which he also used for a PayPal account, coupled to a Mastercard.

I used a local website to send him a giant expensive bouquet of flowers with a box of chocolates, using his own PayPal and the default shipping address.

I included a card:

"Congratulations on acquiring my Gmail account, even if I'm 7 years late. Thanks for letting me be such an integral part of your life, for letting me know who you are, what you buy, how much you earn, who your family and friends are and where you live. I've surprised your mother with a cruise ticket as you mentioned on Facebook how sorry you were that you forgot her birthday and couldn't buy her a nice present. She seems like a lovely woman. I've also made a $1000 donation in your name to the EFF, to celebrate our distant friendship"

    Did you really do all the mentioned in the end!?
    @Nawap Yes. The kid made thousands a month through various dubious channels. I won't judge, but I thought I'd help him spend it better than on parts for his tuned car.

    He quickly changed his PayPal password, and I stopped receiving the forwards. His mom posted a picture drinking a cocktail in the bar of the luxury cruise ship on Facebook mentioning she loved her son. Such a great lady. 😄
    Omg. If this is real this was the best thing ever.

    Stealing a stealer. Not aware of possible legal actions tho.
    @ivoecpereira I don't enjoy ruining lives, and it was not my intention to gain anything from it either. I just thought it was a dick move that he kept messaging his mom "desculpe eu nao tenho dinero", begging for funds, while buying luxury goods for himself.
    @ivoecpereira My alignment is chaotic good, sometimes chaotic neutral, depending on whether I've had my coffee.
    I like how you reacted to this, because if you emptied his paypal or responded negatively for this, lets say no one comes a winner of it, but with what you did and him finding out about forward rule, I'm sure he wont be doing anything wrong due to all the proof you have about what he is doing.
    @inpothet Google is pretty smart in locking out attackers and keeping you in, using questions, verified phone numbers, ip addresses, etc. Problem is, eventually all those things start favoring the one who took over.
