Advertisement
Promo

Security threats Toolkit

Phishing attack hits thousands of Hotmail accounts

Matthew Broersma ZDNet UK

Published: 06 Oct 2009 13:09 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has confirmed that the login credentials for several thousand Hotmail email accounts have been posted on a public website as a result of a phishing scam, and said it is taking steps to protect Hotmail users.

"Over the weekend, Microsoft learned that several thousand Windows Live Hotmail customers' credentials were exposed on a third-party site due to a likely phishing scheme," Microsoft said in a statement published on a company blog on Monday. "Upon learning of the issue, we immediately requested that the credentials be removed and launched an investigation to determine the impact to customers."

The software maker said its investigation found that there had been no breach of internal company data.

As a result of the attack, Microsoft said it has blocked access to all of the accounts exposed. Users can fill out a form on the Windows Live email support site to regain access to their accounts.

A list of about 10,000 email account credentials were initially posted on Pastebin.com. The website is ordinarily used by programmers for exchanging code, including accounts using hotmail.com, live.com and msn.com email addresses.

Paul Dixon, who runs Pastebin.com, confirmed the list had been posted on the site, which has been taken offline temporarily as a result of the breach.

"Pastebin.com was intended as a tool to aid software developers, not for distributing this sort of material," Dixon said in a statement on the site. "Filters have been put in place to prevent reoccurrence, but the current traffic level is unsustainable. Pastebin.com is just a fun side project for me, and today it's not fun. It will remain offline all day while I make some further modifications."

A further list of about 20,000 email accounts was also posted on Pastebin.com, containing login credentials for Gmail, Yahoo Mail, AOL, Comcast and Earthlink accounts, according to reports. The second list was seen by the BBC as well as by Neowin.com, the IT community website that initially reported the possible phishing breach.

Microsoft said customers should exercise caution in opening unsolicited attachments and links from both known and unknown sources, and advised the use of antivirus software.

"Phishing is an industry-wide problem, and Microsoft is committed to helping consumers have a safe, secure and positive online experience," the company stated.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
77 out of 84 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:











Video icon

Video

Sentry Posts Blog

Malicious Mobile Apps a Growing Concer...

Malicious Mobile Apps a Growing Concern Author: Eric Everson, MBA, MSIT-SE The phrase “mobile security” does not usually mean much to anyone, until of course they encounter their... More

Post a comment

Malicious Mobile Code: What You Need t...

Malicious Mobile Code: What You Need to Know. Author: Eric Everson, MBA, MSIT-SE The thought of someone hacking into your mobile phone to steal your personal data added to the growing... More

1 comment

Bletchley Park calls for operators for...

The home of World War II codebreaking has called for engineers to operate an electro-mechanical machine developed by mathematician Alan Turing. The Turing Bombe was a brute-force... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters