Plan Finder Complete Guide Articles and Reviews Downloads About Us
Email Service Guide

Industry-wide Phishing Scheme

3 Comments »
October 6th, 2009
Viktor Petersson
A rather lame phishing attempt.

A rather lame phishing attempt.

Yesterday we reported that Microsoft Live/Hotmail was exposed to an extensive phishing scheme. Apparently the attack was more extensive than this. BBC News reports that a second list with 20,000 accounts was published. Contrary to the first list, the second list included accounts from AOL, Comcast, Earthlink, Gmail and Hotmail. With that information, we can conclude that this is an industry-wide attack, rather than an attack on a particular provider.

Phishing attacks by themselves are nothing new, but this is probably one of the biggest attacks that I have ever heard of.

What makes it even worse is that the people who oftentimes fall for these kind of attacks are the same users who are likely use the same password for everything. Hence, this problem is greater than just having a few private emails exposed. Equipped with a list of valid e-mail addresses and passwords combinations, an attacker can easily write a script that tries the credentials on a number of commonly used sites (and run it through a bot-network to be able to scale it). All of a sudden, the attacker now has a list of credentials to a number of sites, perhaps even including banks and other financial services.

For us techies, it’s easy to sport a phishing email. However, for the average user, this can be a challenging task. There are a number of technologies that can help prevent phishing (eg. DKIM). Unfortunately, due to the lack of industry-wide adoption, we cannot rely on these technologies entirely today.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Mixx
  • Google Bookmarks
  • LinkedIn
  • Posterous
  • Reddit
  • Slashdot
  • StumbleUpon
  • Suggest to Techmeme via Twitter
  • Technorati
  • Twitter
Tags: AOL, Gmail, Hotmail, phishing, security, Windows Live Posted in News 3 Comments »

3 Responses to “Industry-wide Phishing Scheme”

  1. Email Service Guide – FBI Director Nearly Falls for Phishing Attack says:
    October 9, 2009 at 11:13 AM

    [...] has been on a spectacular rise recently with over 20,000 email accounts being exposed by one such attack. To avoid becoming a victim, never reply to an email with your [...]

  2. Email Service Guide – How secure is your hosted email? says:
    October 11, 2009 at 12:26 PM

    [...] and Yahoo e-mail account passwords had been phished and posted online (which we covered here and here). This is neither the first nor the last time security has been or will be compromised by malicious [...]

  3. Email Service Guide – Avoid The Hook: Protect Yourself Against Phishing says:
    November 1, 2009 at 4:04 PM

    [...] technology news headlines have lately been buzzing with news of recent widespread phishing attacks. One report from earlier this month states that a phishing scheme aimed at email users took in more than 20,000 email addresses and [...]

  • RSS Feed
  • Facebook Fan
  • Twitter Feed
Old school? Join our mailinglist.

Latest Articles

  • 03/05 - reMail goes Open Source! What does it mean?
  • 02/15 - Email Marketing Part 4: 25 Tips To Optimize Your Campaign
  • 02/03 - Email Marketing Pt. 3: MadMimi, Aweber, Benchmark, iContact, CampaignMonitor Reviews
  • 01/28 - Atmail 6.1.3 is out. Now supports LDAP and Active Directory
  • 01/28 - Email Marketing Pt 2: MailChimp, ConstantContact, EmailBrain, LetterPop Reviews
  • 01/26 - Making Facebook’s messaging system IMAP compatible
  • 01/26 - Pegasus Mail 4.52 is out
  • 01/20 - Email Marketing Part 1: An Introduction
  • 01/14 - Major new deal for LotusLive
  • 01/13 - Gmail is now more secure.

Resources

  • Downloads
  • Browse our download-section that includes a number of email-related virtual appliances.
  • Email Troubleshooting Guide
  • A complete guide for troubleshooting IMAP, POP3 and SMTP.

Sponsored Link: YippieMove

Need to transfer email between accounts? The YippieMove email migration tool lets you do that easily online.


Tags

    ActiveSync Android AOL apocalypse Atmail chat client collaboration Exchange Facebook FastMail.FM Gmail Gmail Labs Google Google Apps Google Wave Hotmail IBM IMAP iNotes iPhone LotusLive Microsoft mobile Mozilla Open-Xchange Outlook phishing POP3 reMail review SaaS security social network spam T-Mobile threadsy Thunderbird Tips Twitter VMware Windows Live Yahoo Zenbe Zimbra


Archives

  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009

Connect with us!

  • Suggest an article
Got feedback, questions? Contact us. Advisory information only. Data may not be current or correct, prices and terms are based on our best interpretation of relevant user agreements. Database includes both affiliated and non affiliated providers. © 2009 WireLoad, LLC