The need for email archiving
Without an effective system for archiving emails, organisations can find themselves unable to recover vital business records, leaving them open..
There has been a marked increase in the amount of spam emails being sent from Yahoo, Gmail and Hotmail accounts, according to analysts at Websense Security Labs.
Websense said on Thursday that personalised spam emails had been sent from the compromised accounts to all of each user's contacts. The emails contain links to fake shopping sites, intended to capture sensitive information from the reader.
Earlier this week, Microsoft acknowledged that 30,000 Hotmail accounts had breached, and suggested the passwords for the accounts had been obtained in a phishing scam.
However, some security experts believe that the password breach cannot be attributed to phishing. Amichai Shulman, chief technology officer for security firm Imperva, told ZDNet UK on Friday that the information was likely to have been obtained through key logging.
"The quantity of people hit makes me think that it was key logging — the success rate for phishing is only about one in 1,000," said Shulman. "Secondly, when I went through the list of email account credentials, there were entries with the same username, but a slightly different password, which suggests that they're typos.
"I don't think people would keep falling for a phishing scam and entering their details, it looks more like people are making mistakes and the key-logging software is recording them," he said.
Mary Landesman, senior security consultant at ScanSafe, said in a blog post on Wednesday that a data-theft Trojan is likely to have been used. Many of the victims appeared to be taking reasonable precautions with the length and complexity of their passwords, she said.
Read this
As web malware proliferates, it seems the cybercriminals are always one step ahead, says Mary Landesman
In addition, there were errors throughout the list that appeared to be the result of improper extraction of data, Landesman suggested.
Patrick Runald, security research manager at Websense, said that as yet, there is no proof to suggest it was either a phishing or key-logging scam, although he suspected it could be both. He added that considering the number of compromised accounts, the attack is likely to date back months.
"We've been looking through our systems to try and locate an email that is credible enough to fool so many people, and so far we haven't found one," said Runald. "Generally phishing is declining and being replaced by key logging, and considering the number of compromised accounts, it could be a combination of both."
Runald urged users to change the passwords to their email accounts, and any other accounts that the same password might be used for, on a six-monthly basis. Websense also encouraged people to check that websites are properly encrypted and start with the secure version of hypertext transfer protocol, 'https'.
Carole Theriault, senior security consultant at Sophos, said Sophos customers had experienced no significant increase in spam over the past four days. However, she said forum phishing attacks had taken place.
"Some of the most popular passwords that were posted were words like 'neopets', 'tigger' and 'princess' — words that children would use. So not only should parents change their account passwords, they should make sure their kids do, too," she said.
In order to post a comment you need to be registered and logged in
Log in or create your ZDNet UK account below
By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ
Oracle signs Solaris deals with HP and Dell: Find the answers in the Community FAQ free shipping wholesale product... http://bit.ly/cDUyaj
39 minutes ago on Twitter by KC616free shipping wholesale products: Read more »h handbags,NIKE shoes, jewelry, watches, and jacket and so on. We gua... http://bit.ly/cWcW1e
39 minutes ago on Twitter by KC616Cyberwar defence plan is essential, says former CIA head: Michael Hayden, former head of the CIA and the National ... http://bit.ly/beLpKQ
1 hour ago on Twitter by SpyScrollSAP leads businesses into augmented reality http://bit.ly/9eMWYp | #Droid #Android
1 hour ago on Twitter by Droid_Newsfree shipping wholesale products: We mainly supply top mirror quality brand name products, such as wholesale handb... http://bit.ly/cWcW1e
1 hour ago on Twitter by wholesalegurruCyberwar defence plan is essential, says former CIA head: Michael Hayden, former head of the CIA and the N... http://bit.ly/9sn6ax #pdln4nx
1 hour ago on Twitter by CNSInstructorOracle signs Solaris deals with HP and Dell http://bit.ly/9KVeqD
2 hours ago on Twitter by AllAboutFashionSAP leads businesses into augmented reality http://bit.ly/9eMWYp | #Droid #Android
2 hours ago on Twitter by Droid_PhoneTalkTalk to sell mobile services via Vodafone deal http://bit.ly/bLVfxI | #Droid #Android
2 hours ago on Twitter by Droid_PhoneOracle signs Solaris deals with HP and Dell: Find the answers in the Community FAQ free shipping wholesale product... http://bit.ly/cDUyaj
2 hours ago on Twitter by wholesalegurrufree shipping wholesale products: Read more »h handbags,NIKE shoes, jewelry, watches, and jacket and so on. We gua... http://bit.ly/cWcW1e
2 hours ago on Twitter by wholesalegurruDoJ joins whistleblower in Oracle fraud suit http://bit.ly/bMT3SJ
2 hours ago on Twitter by felixsprisciUpdate: free shipping wholesale products - ZDNet UK (... http://www.actahandbags.com/trends/free-shipping-wholesale-products-zdnet-uk-blog/
2 hours ago on Twitter by actatrudyfree shipping wholesale products: Read more »h handbags,NIKE shoes, jewelry, watches, and jacket and so on. We gua... http://bit.ly/bRvFgG
2 hours ago on Twitter by lisabarnes001free shipping wholesale products: Read more »h handbags,NIKE shoes, jewelry, watches, and jacket and so on. We gua... http://bit.ly/9CXYG9
2 hours ago on Twitter by mensapparel2010free shipping wholesale products: Read more »h handbags,NIKE shoes, jewelry, watches, and jacket and so on. We gua... http://bit.ly/alnVOR
2 hours ago on Twitter by womensapparel20free shipping wholesale products: Read more »h handbags,NIKE shoes, jewelry, watches, and jacket and so on. We gua... http://bit.ly/cWcW1e
2 hours ago on Twitter by SharonFashionSecurity guru demonstrates ATM machine hack http://bit.ly/augzs1
2 hours ago on Twitter by ProtegoSSUK deems Google Wi-Fi data snatch safe: (Sign In or register below) Google moves to show YouTube has 'a very credi... http://bit.ly/9vHweP
2 hours ago on Twitter by kompasstechWithout an effective system for archiving emails, organisations can find themselves unable to recover vital business records, leaving them open..
This study was conducted in the United States amoung IT decision makers with involvement in data centre purchases at companies..
'Infrastructure as a Service' gives enterprises the flexibility to subscribe to the compute power and storage they require today with 'pay..