October 10, 2009 1:54 PM PDT

Hacked Web mail accounts used to send spam

by Carly Newman
  • Font size
  • Print
  • 4 comments

There has been a marked increase in the amount of spam e-mails being sent from Yahoo, Gmail, and Hotmail accounts, according to analysts at Websense Security Labs.

Websense said on Thursday that personalized spam e-mails had been sent from the compromised accounts to all of each user's contacts. The e-mails contain links to fake shopping sites, intended to capture sensitive information from the reader.

Earlier this week, Microsoft acknowledged that 30,000 Hotmail accounts had breached, and suggested the passwords for the accounts had been obtained in a phishing scam.

However, some security experts believe that the password breach cannot be attributed to phishing. Amichai Shulman, chief technology officer for security firm Imperva, told ZDNet UK on Friday that the information was likely to have been obtained through key logging.

"The quantity of people hit makes me think that it was key logging--the success rate for phishing is only about one in 1,000," said Shulman. "Secondly, when I went through the list of email account credentials...

Read more of "Hacked Web mail accounts used to send spam" on ZDNet UK.

Recent posts from Security
RockYou sued over data breach
Hacker Gonzalez pleads guilty in Heartland breach
Microsoft rebuts IIS vulnerability claims
More attacks expected on Facebook, Twitter in 2010
GSM crypto code cracked, engineer says
Web-based Lookout protects mobile devices, data
Hackers claim to crack Kindle copyright armor
Using Facebook and Twitter safely
Add a Comment (Log in or register) (4 Comments)
  • prev
  • 1
  • next
by redmarine October 10, 2009 3:16 PM PDT
This could probably explain why I got so much spam comments in my YouTube videos.
Reply to this comment
by janikajala October 10, 2009 8:17 PM PDT
It could be also that the accounts were created originally just for sending spam. Lots of people are selling and buying accounts in big quantities.
Reply to this comment
by gerbercon October 11, 2009 12:44 PM PDT
After reading this article I'm going to click on the ad that offers to scan my PC...not.
Reply to this comment
by as-df October 16, 2009 9:32 AM PDT
My apologies if this has already been addressed, but I haven?t seen the answer.

How do I tell if a specific account was on the list? Overall, this situation calls for a general reminder to all our people about appropriate security. However, if one (or more) of us was hacked I need to approach that / those individuals somewhat differently.
Reply to this comment
(4 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right