Email phishing attack

PANDA

TCG Elite Member
TCG Premium
Event Coordinator
May 24, 2007
38,034
8,572
Wisconsin Northwoods
Just FYI, watch where you type in passwords.

Microsoft
confirmed yesterday evening that the popular web email service, Hotmail, had been targeted by malicious fraudsters in what is commonly referred to as a phishing scam, tricking users into revealing their credentials at fake websites.


Neowin can today reveal that more lists are circulating with genuine account information and that over 20,000 accounts have now been compromised. Non-Hotmail passport accounts have been affected too. A new list contains email accounts for Gmail, Yahoo, Comcast, Earthlink and other third party popular web mail services. It's not clear if this is login information for the service itself or the Microsoft Passport passwords.

Microsoft confirmed Neowin's exclusive report yesterday evening and issued a statement on a company blog:

"Over the weekend Microsoft learned that several thousand Windows Live Hotmail customer's credentials were exposed on a third-party site due to a likely phishing scheme. Upon learning of the issue, we immediately requested that the credentials be removed and launched an investigation to determine the impact to customers. As part of that investigation, we determined that this was not a breach of internal Microsoft data and initiated our standard process of working to help customers regain control of their accounts."

It's clear the lists are the result of a phishing scam and some commenters at Neowin suggest it could be the result of unwitting users sending their credentials to sites that name who has blocked you on popular instant messaging software Windows Live Messenger.

Neowin has once again reported the new lists to Microsoft's Security Response Center and can confirm that the lists originated from pastebin.com, a site commonly used by developers to share code snippets. Pastebin owner Paul Dixon confirmed that the site was down for maintenance due to "an unprecedented amount of traffic" after our initial reports. Dixon stated "Pastebin.com is just a fun side project for me, and today it's not fun. It will remain offline all day while I make some further modifications."

Update: The phishing attack has spread to Google Mail and Yahoo mail amongst others, we're currently awaiting full confirmation on the number of accounts at each service.

http://www.neowin.net/news/main/09/10/06/hotmail-phishing-attack-confirmed-20000-accounts-in-total
 

RebelGTP

Coyote Bus Lines
Jul 16, 2008
8,123
483
Rockford
phishlogo1cg.gif
 
Old Thread: Hello . There have been no replies in this thread for 90 days.
Content in this thread may no longer be relevant. Consider starting a new thread to get fresh replies.

Thread Info