ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Publishers blame spam on stolen lists

Troy Wolverton CNet

Published: 12 Sep 2002 07:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Email management company Lyris Technologies on Wednesday said it is investigating spam complaints that may involve hundreds of thousands of compromised customer email addresses.

At least three current and former Lyris customers this week complained that recipients of their email newsletters have been receiving spam. MarketingSherpa.com, a publisher of online marketing newsletters, suspects that all eight of its mailing lists have been compromised, said Anne Holland, the company's founder. More than 20 other publishers, who combined have more than 2 million email addresses on their lists, have also contacted Holland saying their Lyris-hosted lists have been compromised.

"We contacted Lyris immediately," Holland said. "Anytime you get a spam complaint from readers, you have to take it very seriously. It could kill your entire company."

About five of the 1,000 customers who have their distribution lists hosted by Lyris have contacted the company with spam concerns, said Steven Brown, the company's chief of operations. The company has hired Word to the Wise, an outside consulting firm, to investigate the matter, Brown said. So far the company has no evidence that the lists on its servers have been compromised.

"We're trying to be as responsive as we can," Brown said. "We try to take this stuff pretty seriously."

Word to the Wise is sorting through the data it has, including the spam messages that have been forwarded by Lyris customers, said Laura Atkins, the company's chief executive officer. So far, the company doesn't know whether the spam was the result of a compromise of Lyris' servers, Atkins said. Atkins said she expected to have some initial conclusions by early next week.

"There's no clear picture as to what it is. It's hard to tell," Atkins said. "We are head-down investigating as fast as we can."

Security vulnerabilities on the Web are not a new thing. A hack at Amazon.com-owned Bibliofind last year compromised nearly 100,000 customer records, including credit card numbers. A security breach at Egghead temporarily exposed the records of 3.7 million of its customer records in late 2000.

But hackers targeting servers just for their mailing lists is a novelty, said Jason Catlett, president of Junkbusters. Spammers can buy millions of email addresses on a CD, although many of them are stale or wrong, he said. Additionally, much spam is sent through attacks where spammers send email to a number of similarly spelled addresses at a particular domain, hoping their message will reach a good address, Catlett said.

But mailing lists with good addresses of a targeted audience are a valuable item.

"In the envelope world of marketing, lists are routinely stolen by employees that are moving to another company," Catlett said. "I don't have any evidence that that happened in this case, but it's happened in the offline world, and it wouldn't be implausible if it happened online."

Lyris is investigating whether a disgruntled employee stole its lists, Brown said. Lyris bought rival SparkList.com last month and hired only three of SparkList's 20 to 25 employees, he said.

"That's always a touchy issue," Brown said. "The fact of the matter is that one business bought another, and some people were brought along and some people weren't."

The customers who talked with CNET News.com said their lists formerly had been hosted by SparkList.

Canning spam
Spam, or unsolicited email, has been overwhelming the servers and in-boxes of many Net users, forcing some companies and organisations to take drastic measures to block it. Last month, Yahoo! found its stores site blacklisted by Mail Abuse Prevention System, an organisation whose lists of suspected spammers are used by other companies to block Web or email access.

Holland and Andy Sernovitz, a former customer of SparkList and chief executive officer of email marketing firm GasPedal ventures, said they became aware that their lists had been compromised in early August. Both received email from people on their mailing lists saying that they had received spam. Both said they had not sold their mailing lists.

Both Holland and Sernovitz, whose mailing list has some 10,000 subscribers, said they were frustrated by how Lyris responded to their reports of the compromise. The company didn't start trying to address the issue until the last several days, Holland said.

"I do understand they've been extremely busy with the merger," she said. "But did they take this as seriously as they should have? No."

Lyris first started receiving reports of spam being sent to recipients of its hosted mailing list in early August, Brown said. The company hired Word to the Wise "a couple days ago", he said.

Still, Brown said that it was unclear from the messages sent by the company's clients that there really was a problem, especially considering how few of its customers had reported spam. "The information we've been given is pretty spotty," he said.

Still, Lyris should have come forward immediately and acknowledged the problem, Sernovitz said.

"Every time a high-tech company tries to hide, they always get busted," he said. "The longer they hide it, the worse it gets. People understand if you get hacked. The question is how do you respond."

Ralph Wilson publishes four e-business newsletters. He suspects the two mailing lists that are hosted by Lyris were compromised. He warned his subscribers to that effect in an email message earlier this month.

Wilson declined to talk about his conversations with Lyris about the compromise. But he said that his subscribers thus far had received few spam messages as a result.

"I'm not saying that I'm not concerned about it," Wilson said. "I'm very concerned about it. But at this point, I don't think people are receiving huge amounts of spam as a result. That makes me feel good so far."


Who's watching you? Get the latest on spy networks such as Echelon and Carnivore, as well as privacy issues for companies and individuals alike, at ZDNet UK's Privacy News Section.

Have your say instantly, and see what others have said. Go to the ZDNet news forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
48 out of 81 people found this useful


Full Talkback thread

1 comment

  1. someone used my email adress to claim to be anybr... Anonymous

Company/Topic Alerts

Create a new alert from the list below:





Sentry Posts Blog

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I知 a PC. I知 a Handheld.

Hello, I知 a PC. I知 a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I値l say it again, mobile devices are simply replacing computers.... More

Post a comment

Please educate your clients!

This extremely short post appeared following a meeting with a decision maker of a potential client. During the conversation I realized that this highly respected and well paid top manager... More

2 comments

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains