Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Pfizer PCs used to relay Viagra spam

Peter Judge ZDNet.co.uk

Published: 07 Sep 2007 17:51 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Spammers have hijacked computers at drug manufacturer Pfizer, causing them to send junk emails advertising the company's product Viagra.

At least 138 of Pfizer's IP addresses are being used to send the spam after being loaded with Trojan software, it emerged this week. Aside from Viagra, the spam advertises penis-enlargement drugs, fake Rolexes and shares, according to botnet-tracking company Support Intelligence, which said that those IP addresses have now been blacklisted by anti-spam companies.

Support Intelligence has saved 600 sample spam emails over the past six months, and contacted Pfizer about the problem. But Pfizer has not cleared the problem up, Support Intelligence's chief executive Paul Wesson told Wired.com on Wednesday.

Although the spam emails were sent by Pfizer computers, recipients would not have realised this, as the spammers used forged web-based email addresses.

The incident adds to the company's embarrassment after three major security breaches, each of which involved the theft of Pfizer employees' personal data. In one of these breaches, revealed on 24 August, details of 34,000 Pfizer employees were stolen by a former employee. Pfizer said in a letter to its employees that "there is no indication" the information is being misused.

That announcement followed two other major data losses at the drugs company. Pfizer warned in June that peer-to-peer software on one of its machines may have leaked the details of 17,000 employees, and in July the company lost two laptops containing staff details.

No connection has been made between these breaches and the spam attacks.

Pfizer said it was "actively investigating the allegations" and that it wanted to make clear "our respect for privacy and commitment to adherence to applicable laws".

It did not say specifically whether it was taking steps to shut down the affected machines. But the company said in a statement that it will "pursue any and all remedies available to the full extent of the law".

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
18 out of 18 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment

Nokia Siemens denies Iran web snoop

Nokia Siemens has denied providing deep packet inspection capabilities to the Iranian authorities, following an article in the Wall Street Journal on Monday. The WSJ published the... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters