Advertisement
Promo

Security threats Toolkit

Pfizer PCs used to relay Viagra spam

Peter Judge ZDNet.co.uk

Published: 07 Sep 2007 17:51 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Spammers have hijacked computers at drug manufacturer Pfizer, causing them to send junk emails advertising the company's product Viagra.

At least 138 of Pfizer's IP addresses are being used to send the spam after being loaded with Trojan software, it emerged this week. Aside from Viagra, the spam advertises penis-enlargement drugs, fake Rolexes and shares, according to botnet-tracking company Support Intelligence, which said that those IP addresses have now been blacklisted by anti-spam companies.

Support Intelligence has saved 600 sample spam emails over the past six months, and contacted Pfizer about the problem. But Pfizer has not cleared the problem up, Support Intelligence's chief executive Paul Wesson told Wired.com on Wednesday.

Although the spam emails were sent by Pfizer computers, recipients would not have realised this, as the spammers used forged web-based email addresses.

The incident adds to the company's embarrassment after three major security breaches, each of which involved the theft of Pfizer employees' personal data. In one of these breaches, revealed on 24 August, details of 34,000 Pfizer employees were stolen by a former employee. Pfizer said in a letter to its employees that "there is no indication" the information is being misused.

That announcement followed two other major data losses at the drugs company. Pfizer warned in June that peer-to-peer software on one of its machines may have leaked the details of 17,000 employees, and in July the company lost two laptops containing staff details.

No connection has been made between these breaches and the spam attacks.

Pfizer said it was "actively investigating the allegations" and that it wanted to make clear "our respect for privacy and commitment to adherence to applicable laws".

It did not say specifically whether it was taking steps to shut down the affected machines. But the company said in a statement that it will "pursue any and all remedies available to the full extent of the law".

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
18 out of 18 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment

Watchdog reveals illegal sale of phone...

The Information Commissioner's Office is preparing a prosecution file against a mobile operator's employees who allegedly sold on thousands of customers' details to a competitor. The... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters