Help, Spammers Hijacked my Email Account!
A desperate reader asks: 'Can you please help me, somehow my email account got hijacked, and now all my friends are getting spam, FROM ME! I am always careful with my password. How could this have happened, and what should I do?' Read on for the answer...
Did Spammers Really Hijack Your Email?
The first thing to do is relax. It's quite likely that your account wasn't actually compromised. Spammers can use (or abuse) your email address without actually hacking into your email account. It is relatively easy to "spoof" an email address so that it appears a message is coming from one address when it was really sent from another.
Spammers don't like to poke their pointy little heads out from under the rocks where they live, so they try to divert attention from themselves by making it look like someone else sent the message. They use high-volume mail merge software that picks an address at random from their database of addresses, and inserts it into the FROM line of outgoing emails.
If a virus scan shows nothing unusual, if you can still login to your email account with your password, and you see nothing amiss in your Sent folder, then you can safely assume no breach has occurred. In such a case, you can explain to your angry friends that it was the work of an Evil Spammer who forged your address. If they give you flack, tell them to examine the "Received" lines in the email headers (most email programs let you view the headers if you poke around in the options) and they (or their Internet provider) can confirm that the email was not actually sent by you.
So there's no breach of your inbox, and your friends are satisfied that you've not joined the dark side. You can breathe a sigh of relief. But just to be safe, I recommend that you change your password, update the security question (if your account still uses it), and turn on two-factor authentication. In the worst case, hackers can gain full access to your email account and major trouble ensues.
It is possible for a hacker to change your email password so that you cannot log in to your own account. Then they can raid your contact list to harvest valid email addresses to add to his spam list. Also, the hacker now has access to all of your saved email, which may include sensitive personal and financial information. But it's more likely that a hacker will NOT change the password, to avoid the obvious red flag that would send. If you've been locked out of your own email account, contact your ISP, or use the "can't access my account" link that appears on the login screen to recover.
An email account can be hijacked in a number of ways. Phishing attacks in which a hacker subtly persuades a user into revealing login passwords are a common hijacking technique. A message, purportedly from your bank or other trusted partner, may tell you that a "security check" requires you to respond with your password. Such claims are always bogus; legitimate organizations never ask you to reveal your password via email, phone, or other means. See Spear Phishing and Internet Security for more on that.
Some forms of malware (viruses, spyware, etc.) attack for the purpose of gaining access to your computer, in order to enslave it in a botnet, and use it as a spam spewing device. This can happen without you even knowing, until people from all over the world start accusing YOU of being a spammer! Keylogger spyware installed on your computer can record every keystroke you type and send the results to a remote operator who can then read your password from the log file. There are several ways to detect and defeat keyloggers.
Password Safety Tips
Using the same password on multiple online accounts leaves all of them open to hijacking if just one account is penetrated. Be sure to use unique passwords on email, Facebook, eBay, online banking and other accounts. Storing passwords to other accounts in one place leaves you vulnerable in a similar way. If one account is hacked, a search through data stored there can yield several other passwords.
Failing to log out of an account when you've finished a session makes it easy for anyone who has access to the computer you used to hijack your account. Always log out of accounts accessed from shared computers, such as those in libraries, schools, Internet cafes, etc. A browser's auto-fill forms feature may reveal your password to someone who uses the same computer you use.
Password guessing is a brute-force hacking method that employs software to try random passwords until one works. Many email accounts go into "lock down" mode after a few failed password attempts, but if yours does not it's possible to get hijacked in this way. If you have a very weak or predictable password, it makes the hackers job that much easier. See my article Is Your Password Strong Enough? for tips on choosing a strong, secure password.
And then there are data breaches. Attacks against high-profile websites go after the password database, attempting to crack its security and harvest thousands or millions of email addresses and passwords in one swoop. In some cases, this information is left completely unprotected by incompetent IT personnel. There's not much you can do to prevent this type of attack except to host your email account with a reputable service provider who pays attention to security, and use a secure password.
Network packet monitoring software can sniff out passwords sent over unsecured wireless connections. You should be aware of this type of attack if you use free wifi in a coffee shop, airport, hotel, etc. Use encrypted (https) connections when logging in or emailing over unsecured public wireless networks. My related article [DANGER] Free Wifi Hotspots Can Be Risky has some helpful tips on how to stay safe while surfing in Starbucks.
As I mentioned above, the very best thing you can do to improve the security of any online account is to use two-factor authentication. See my article IMPORTANT: An Extra Layer of Security to understand two-factor authentication, and how it can protect you even if someone has (or guesses) your password.
So to recap, if your friends are asking why you sent those nasty emails, it's almost certain that you didn't. Check your email account for any signs of tampering, run a malware scan, and tighten up your inbox security. Tell your friends to use the DELETE button, and the problem will resolve itself soon enough.
Has your email account ever been hacked? Post your comment or question below...
This article was posted by Bob Rankin on 2 Apr 2019
|For Fun: Buy Bob a Snickers.|
The Best Upgrades for Old Computers?
The Top Twenty
Geekly Update - 03 April 2019
Post your Comments, Questions or Suggestions
Free Tech Support -- Ask Bob Rankin
Subscribe to AskBobRankin Updates: Free Newsletter
Copyright © 2005 - Bob Rankin - All Rights Reserved
Article information: AskBobRankin -- Help, Spammers Hijacked my Email Account! (Posted: 2 Apr 2019)
Copyright © 2005 - Bob Rankin - All Rights Reserved