Jump to content

hotmail account hijacked


shokan
 Share

Recommended Posts

A few months ago, I began getting undeliverable email notifications from various servers around the world. The emails were ostensibly sent by me from my Hotmail account. I never sent these, of course. Individuals that I have had recent correspondence with have gotten the emails from "me", and I believe my Contact list has been used, also. They are all sports shoe emails from a company in China, asking the recipient to check out their low prices, etc..

If there is no way to stop this and yet still keep the account, how do I close out this Hotmail account permanently so that it can no longer be used this way?

Thanks.

Link to comment
Share on other sites

I'm afraid that once an account has become hijacked it's almost impossible to get it back again. First you should start some new accounts (I'll explain why I say "some" in a moment). Then you should write to all your important contacts cancelling the old account and giving them the address of the new one. Then just stop using the old account. There are files on your computer containg copies of all your old hotmail files, so later, if you wish, you can copy all that into your new account.

You also need to investigate how your account was hijacked so you don't make the same mistake again.

Lastly it's advisable to have perhaps 2-3 accounts but reserve one of them only for you important personal contacts and use the others for subscribing to public groups, fora, social networks etc.

Link to comment
Share on other sites

I'm afraid that once an account has become hijacked it's almost impossible to get it back again. First you should start some new accounts (I'll explain why I say "some" in a moment). Then you should write to all your important contacts cancelling the old account and giving them the address of the new one. Then just stop using the old account. There are files on your computer containg copies of all your old hotmail files, so later, if you wish, you can copy all that into your new account.

You also need to investigate how your account was hijacked so you don't make the same mistake again.

Lastly it's advisable to have perhaps 2-3 accounts but reserve one of them only for you important personal contacts and use the others for subscribing to public groups, fora, social networks etc.

Yes, I've done these things...except finding out how it happened. I will look around on the internet for some answers. Thanks for the advice.

Link to comment
Share on other sites

I'm afraid that once an account has become hijacked it's almost impossible to get it back again. First you should start some new accounts (I'll explain why I say "some" in a moment). Then you should write to all your important contacts cancelling the old account and giving them the address of the new one. Then just stop using the old account. There are files on your computer containg copies of all your old hotmail files, so later, if you wish, you can copy all that into your new account.

You also need to investigate how your account was hijacked so you don't make the same mistake again.

Lastly it's advisable to have perhaps 2-3 accounts but reserve one of them only for you important personal contacts and use the others for subscribing to public groups, fora, social networks etc.

Yes, I've done these things...except finding out how it happened. I will look around on the internet for some answers. Thanks for the advice.

Did you use an unsecured WiFi (Starbucks, Mickey Dees) to access the account? Another user with the Firefox add-on Firesheep could captured your session cookie.

I would recommend using latest version of Firefox with the HTTPS Everywhere add-on installed.


/>https://www.eff.org/https-everywhere

Link to comment
Share on other sites

Having your contacts list hacked and your hotmail address used for spamming could easily be two different events. You don't have to have your computer compromised for a badguy to "spoof" your address for the return address of his mail. They can plug any address in there. This is why you should avoid posting your email address on public sites as badguys routinely troll sites, forums, and chat rooms for valid addresses. Also, avoid sending and forwarding jokes and other mass mailings and tell your friends and family to stop sending them to you. Too many people simply forward these without using blind CC and instead, leave the many addresses in the CC: box. A badguy can intercept one and pick up dozens of valid addresses.

As for your contacts being compromised, you need to ensure your system is free of malware by running a complete scan for malware.

I would recommend using latest version of Firefox with the HTTPS Everywhere add-on installed.

:( You don't have to switch to an alternative browser. This is unfounded advice, and I hope is not given as simple bashing. The latest version of Internet Explorer (IE8) is just fine (the BEST by some studies!! - though IE9Beta is proving to be even more secure) otherwise there would be 100s of millions of compromised systems out there, and there isn't. In fact, of the nearly 1 Billion Windows computers out there, MOST use IE and Windows Firewall with Windows Update set to automatic, and many use MSE for anti-malware - and the vast majority have no problems. Note that as alternative browsers become popular, they become targeted.

I am not bashing Firefox, just ensuring IE is not being bashed and prejudiced without justification. Security is NOT a reason to switch browsers. Period.

The point is, the user is the weak link, not the browser of choice. The user MUST keep their systems patched, updated, scanned, and blocked. That is, keep Windows patched and updated, use the latest version of your browser and security program of choice, use a real-time updated anti-malware scanner, and block with an active firewall and spamblocker. Also, highly recommended is a NAT router, even on a network of one computer.

Link to comment
Share on other sites

  • 2 weeks later...

Original poster here:

For what it's worth, here is a sample spam from the Chinese company using my account. The email subject text changes from email to email.

I have a question first: if it is the case of someone using the address of my Hotmail account found somehow on the Web, how can they send it from a server so that it is actually originating from my account?

Here's the spam sample. The asterixes are mine. Thanks.

From: "Peter R. *** ****" <e****[email protected]>

To: <a*******@hotmail.com>

Date: Tue, 23 Nov 2010 12:13:50 +0000

Subject: Hey / Cr

{ZhuFu-6} 3wSr NS uV6x Kly OV qHb9 sjN Ui aN3d cY2 Ps 46OY dEM

Fq yCAk

Our company is the largest electronics sector in Asia, the new

product goes on sale. 7 days arrival, 14 days package returned.

Welcome to our website have a fun shopping, we are ready to serve you!

You can buy everything that you want . 3Mkn ml ZFd8 rI4 FM JeuS 3

Welcome to our website: http://myturl.com/0pBTw

3jUL kk qsIY 100 Q2 rsf8 lod V3 IM85 0v4 Ft t2Qt 6dq Oq M0sV uxj M8 mYm8 3

Link to comment
Share on other sites

Once they've got your log-in ID & password they can use any computer to send out emails from "you", just as you can send out emails from an internet cafe. Usually they will actually hijack another computer(s) and use it as part of a botnet to send out these fraudulant emails or spam without the owner even being aware of it.

Link to comment
Share on other sites

Once they've got your log-in ID & password they can use any computer to send out emails from "you", just as you can send out emails from an internet cafe. Usually they will actually hijack another computer(s) and use it as part of a botnet to send out these fraudulant emails or spam without the owner even being aware of it.

Ah, yes. OK.

Would changing my password help anything at this point?

An update to this problem. I sent a "briskly" worded email to the offender's business site contact and, lo and behold, I have not rec'd any Undeliverable Mail notices for a few days. Fingers crossed. Ahem, now that I've gone to the considerable trouble of notifying everyone of my new email account, this would be a kick in the pants.

Thanks.

Link to comment
Share on other sites

Once they've got your log-in ID & password they can use any computer to send out emails from "you", just as you can send out emails from an internet cafe. Usually they will actually hijack another computer(s) and use it as part of a botnet to send out these fraudulant emails or spam without the owner even being aware of it.

Ah, yes. OK.

Would changing my password help anything at this point?

An update to this problem. I sent a "briskly" worded email to the offender's business site contact and, lo and behold, I have not rec'd any Undeliverable Mail notices for a few days. Fingers crossed. Ahem, now that I've gone to the considerable trouble of notifying everyone of my new email account, this would be a kick in the pants.

Thanks.

Never mind the above. It's all still happening. I am abandoning the Hotmail account for good. Too bad.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy