Publishers blame spam on stolen lists

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
Email management company Lyris Technologies on Wednesday said it is investigating spam complaints that may involve hundreds of thousands of compromised customer email addresses. At least three current and former Lyris customers this week complained that recipients of their email newsletters have been receiving spam. MarketingSherpa.com, a publisher of online marketing newsletters, suspects that all eight of its mailing lists have been compromised, said Anne Holland, the company's founder. More than 20 other publishers, who combined have more than 2 million email addresses on their lists, have also contacted Holland saying their Lyris-hosted lists have been compromised. "We contacted Lyris immediately," Holland said. "Anytime you get a spam complaint from readers, you have to take it very seriously. It could kill your entire company." About five of the 1,000 customers who have their distribution lists hosted by Lyris have contacted the company with spam concerns, said Steven Brown, the company's chief of operations. The company has hired Word to the Wise, an outside consulting firm, to investigate the matter, Brown said. So far the company has no evidence that the lists on its servers have been compromised. "We're trying to be as responsive as we can," Brown said. "We try to take this stuff pretty seriously." Word to the Wise is sorting through the data it has, including the spam messages that have been forwarded by Lyris customers, said Laura Atkins, the company's chief executive officer. So far, the company doesn't know whether the spam was the result of a compromise of Lyris' servers, Atkins said. Atkins said she expected to have some initial conclusions by early next week. "There's no clear picture as to what it is. It's hard to tell," Atkins said. "We are head-down investigating as fast as we can." Security vulnerabilities on the Web are not a new thing. A hack at Amazon.com-owned Bibliofind last year compromised nearly 100,000 customer records, including credit card numbers. A security breach at Egghead temporarily exposed the records of 3.7 million of its customer records in late 2000. But hackers targeting servers just for their mailing lists is a novelty, said Jason Catlett, president of Junkbusters. Spammers can buy millions of email addresses on a CD, although many of them are stale or wrong, he said. Additionally, much spam is sent through attacks where spammers send email to a number of similarly spelled addresses at a particular domain, hoping their message will reach a good address, Catlett said. But mailing lists with good addresses of a targeted audience are a valuable item. "In the envelope world of marketing, lists are routinely stolen by employees that are moving to another company," Catlett said. "I don't have any evidence that that happened in this case, but it's happened in the offline world, and it wouldn't be implausible if it happened online." Lyris is investigating whether a disgruntled employee stole its lists, Brown said. Lyris bought rival SparkList.com last month and hired only three of SparkList's 20 to 25 employees, he said. "That's always a touchy issue," Brown said. "The fact of the matter is that one business bought another, and some people were brought along and some people weren't." The customers who talked with CNET News.com said their lists formerly had been hosted by SparkList. Canning spam
Spam, or unsolicited email, has been overwhelming the servers and in-boxes of many Net users, forcing some companies and organisations to take drastic measures to block it. Last month, Yahoo! found its stores site blacklisted by Mail Abuse Prevention System, an organisation whose lists of suspected spammers are used by other companies to block Web or email access. Holland and Andy Sernovitz, a former customer of SparkList and chief executive officer of email marketing firm GasPedal ventures, said they became aware that their lists had been compromised in early August. Both received email from people on their mailing lists saying that they had received spam. Both said they had not sold their mailing lists. Both Holland and Sernovitz, whose mailing list has some 10,000 subscribers, said they were frustrated by how Lyris responded to their reports of the compromise. The company didn't start trying to address the issue until the last several days, Holland said. "I do understand they've been extremely busy with the merger," she said. "But did they take this as seriously as they should have? No." Lyris first started receiving reports of spam being sent to recipients of its hosted mailing list in early August, Brown said. The company hired Word to the Wise "a couple days ago", he said. Still, Brown said that it was unclear from the messages sent by the company's clients that there really was a problem, especially considering how few of its customers had reported spam. "The information we've been given is pretty spotty," he said. Still, Lyris should have come forward immediately and acknowledged the problem, Sernovitz said. "Every time a high-tech company tries to hide, they always get busted," he said. "The longer they hide it, the worse it gets. People understand if you get hacked. The question is how do you respond." Ralph Wilson publishes four e-business newsletters. He suspects the two mailing lists that are hosted by Lyris were compromised. He warned his subscribers to that effect in an email message earlier this month. Wilson declined to talk about his conversations with Lyris about the compromise. But he said that his subscribers thus far had received few spam messages as a result. "I'm not saying that I'm not concerned about it," Wilson said. "I'm very concerned about it. But at this point, I don't think people are receiving huge amounts of spam as a result. That makes me feel good so far."
Who's watching you? Get the latest on spy networks such as Echelon and Carnivore, as well as privacy issues for companies and individuals alike, at ZDNet UK's Privacy News Section. Have your say instantly, and see what others have said. Go to the ZDNet news forum. Let the editors know what you think in the Mailroom.

Talkback

someone used my email adress to claim to be
anybrand@anybrandname.com
now I have hundreds replying to me to remove from thier lists
I don't even have any lists

via Facebook 12 April, 2004 15:52
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

5 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

8 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

8 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

9 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

10 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

11 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

11 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

11 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

12 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

12 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

12 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

12 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

13 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

16 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

17 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

17 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

18 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

19 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

21 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule
apexwm

Bill Goodrich : Just as al_langevin pointed out, with Windows Server 2008 there is no Services for Macintosh anymore. It's gone, not available....

1 day ago by apexwm on Windows Server 2008 drops the ball for Mac compatibility