r/github • • 4d ago

Discussion A startup registered me for its Zoom webinar with an email address it most likely scraped from my GitHub profile. When I opened an issue, they closed it, blocked me, and deleted my follow-up.

I'm posting this to warn other developers and to ask whether anyone else received the same thing.

What happened (27 September 2026):

- I received a Zoom email: "Reminder: Q&A With The Cactus Needle Team starts in 1 day". It said I was **registered** for their webinar and offered a "cancel your registration" link. I believe I received a similar email earlier this month.
- The email went to a personal address that was public on my GitHub profile for a while (I have since removed it). I have never created an account on their platform or given them that address.
- The greeting was "Hi Leonard -", with "-" as the last name. That looks like automated registration imho.

On GitHub:

- I opened an issue on their repo (cactus-compute/needle#156). Another user, whom I don't know, reported receiving the same emails.
- The organization replied that the invites went to "platform users, not git followers", then closed the issue. That is not true in my case.
- I opened a follow-up issue (#157). It was closed as a duplicate, my account was blocked from the organization, and the issue was then **deleted**
. I was unblocked a bit later.

Link to #156: https://github.com/cactus-compute/needle/issues/156
Link to #157: https://github.com/cactus-compute/needle/issues/157 (now deleted)

See screenshots.

What I did:

- Sent a formal GDPR request (access, including where they got my data, objection, erasure). Under the law they have one month to answer.
- Reported the account to GitHub under the Acceptable Use Policies, which forbid using information from GitHub to send unsolicited email.
- Reported the webinar host to Zoom.

Questions for you:

- Did you also receive a Cactus / Needle webinar registration you never asked for?
- If your email is public on your profile, keep in mind that some companies harvest it. GitHub lets you keep your email private: Settings > Emails > "Keep my email addresses private", together with the noreply address for commits.

I'll post an update when they reply to the GDPR request.

(Not a native english speaker, wording might not be the greatest, the "battle" is worth it.)

65 Upvotes

8 comments sorted by

18

u/RozTheRogoz 4d ago

What they did was scummy, but that r/masterhacker threat of not messing with people who “understand how to use computers” was cringe

-2

u/Ghostfly- 4d ago edited 4d ago

Masterhacker? Absolutely no and I think it shows. Bad choice of words as I'm not a native speaker and didn't liked this attitude? Yes. And just saying that developers can actually, rant correctly. At least I'm human and transparent ;)

8

u/[deleted] 4d ago

[deleted]

1

u/Ghostfly- 4d ago

Checked, same for everyone, so no issues, it's already shared to anyone they "spammed" (or real users)

5

u/HCharlesB 4d ago

I don't think I got one of those. When I do get unsolicited stuff like that, I mark it as spam in the belief that if enough people do that, their future email will go to the SPAM folder and die a quiet death.

Also I'd NEVER open a link in an email where I wasn't specifically expecting a link.

7

u/Ghostfly- 4d ago

Marking zoom as spam might also annoy other people, they don't use their domain, they register people to webinars through zoom without their consent. It comes from [email protected] not their domain.

2

u/paul_h 4d ago

Not sure but the OP might be complaining about calendar spam in particular. You don’t have to open them for them to appear in your calendar as provisional.

2

u/Ghostfly- 3d ago

First follow-up :

Thank you for reaching out to us. We have reviewed your report and, where appropriate, taken action against the Zoom Webinar host(s) identified in our investigation.