ive been attacked by hackers

GrillMouster

Member
Joined
Nov 23, 2009
Messages
288
Reaction score
0
I'm sorry that someone maliciously took control of the OP's email account, but there's nothing linking that incident with Android. That's not to say that it couldn't be the case, but there's no evidence. This has been happening to a lot of hotmail users.

My wife had the exact same problem that the OP described several months ago. My wife's hotmail account was hacked and the hackers used her account to send spam email to everyone in her hotmail addressbook, anyone she has received or sent email to from that account, including me. We promptly changed the password and sent an apology email to everyone. I did research on the issue and found that it was happening to a bunch of other people. It had no connection to Android phones. It was happening before the Droids came out. Most of the hacks were automated; in other words it wasn't a person, but a computer that was trying "brute force" attacks to gain access to random email addresses. If your password contains any word found in the dictionary, it's particularly vulnerable to this type of attack. Once the hacking program gets into your email account it sends spam to everyone in your online addressbook and/or email folders. Some hacking programs go so far as to automatically delete the messages from your "sent" folder, so that, unless someone alerts you, you may not even know that your email account is being used to send out spam. Some hacking programs also go into the account settings and enter/change the alternate/backup email address and security questions so that if you change the password, they're still able to log back in to your account unless you also change those settings when you change your password.

A while back there was a virus that was hidden in banner ads found on legitimate websites that hacked your gmail account if you logged into gmail in another window or tab while you were on that infected web page. That virus would do everything mentioned above, AND it would created an email filter/rule in your gmail preferences to search your inbox for any email containing the word "password" in it, and forward all of those emails to another email address (the hacker's email), then it would delete those forwards from your "sent" folder, so you wouldn't even know what was happening. So, any time you sign up for a web site/service, or any time you reset a password on a web site (like when you forget the password and ask them to reset it) and that site emails you your password, it would go to the hacker, too. The hackers were able to get access to people's bank accounts, credit card accounts, and merchants (amazon) where people had their credit card info saved.

So, when your email gets hacked it's not enough to just change the password. Check all the settings/preferences in your account to make sure emails aren't being forwarded to another address, change your security questions and alternate email address.

Also, your password could have been stolen through a computer virus/keylogger on any computer. Have you checked your email on your home, work, school, public, or friend's computer?

So, with all that said, the fact that this has been going on for a long time now and most of the people affected don't have droids, I don't think it's connected to your android phone. It's most likely just a coincidence that it happened after you started using a smartphone.
 
Last edited:

ilikemoneygreen

Silver Member
Joined
Apr 7, 2010
Messages
2,579
Reaction score
18
Location
US
I'm sorry that someone maliciously took control of the OP's email account, but there's nothing linking that incident with Android. That's not to say that it couldn't be the case, but there's no evidence. This has been happening to a lot of hotmail users.

My wife had the exact same problem that the OP described several months ago. My wife's hotmail account was hacked and the hackers used her account to send spam email to everyone in her hotmail addressbook, anyone she has received or sent email to from that account, including me. We promptly changed the password and sent an apology email to everyone. I did research on the issue and found that it was happening to a bunch of other people. It had no connection to Android phones. It was happening before the Droids came out. Most of the hacks were automated; in other words it wasn't a person, but a computer that was trying "brute force" attacks to gain access to random email addresses. If your password contains any word found in the dictionary, it's particularly vulnerable to this type of attack. Once the hacking program gets into your email account it sends spam to everyone in your online addressbook and/or email folders. Some hacking programs go so far as to automatically delete the messages from your "sent" folder, so that, unless someone alerts you, you may not even know that your email account is being used to send out spam. Some hacking programs also go into the account settings and enter/change the alternate/backup email address and security questions so that if you change the email address, they're still able to log back in to your account unless you also change those settings when you change your password.

A while back there was a virus that was hidden in banner ads found on legitimate websites that hacked your gmail account if you logged into gmail in another window or tab while you were on that infected web page. That virus would do everything mentioned above, AND it would created an email filter/rule in your gmail preferences to search your inbox for any email containing the word "password" in it, and forward all of those emails to another email address (the hacker's email), then it would delete those forwards from your "sent" folder, so you wouldn't even know what was happening. So, any time you sign up for a web site/service, or any time you reset a password on a web site (like when you forget the password and ask them to reset it) and that site emails you your password, it would go to the hacker, too. The hackers were able to get access to people's bank accounts, credit card accounts, and merchants (amazon) where people had their credit card info saved.

So, when your email gets hacked it's not enough to just change the password. Check all the settings/preferences in your account to make sure emails aren't being forwarded to another address, change your security questions and alternate email address.

Also, your password could have been stolen through a computer virus/keylogger on any computer. Have you checked your email on your home, work, school, public, or friend's computer?

So, with all that said, the fact that this has been going on for a long time now and most of the people affected don't have droids, I don't think it's connected to your android phone. It's most likely just a coincidence that it happened after you started using a smartphone.
Interesting writeup. I hope none of this has happened to me... i am pretty tight on security though.
 

GrillMouster

Member
Joined
Nov 23, 2009
Messages
288
Reaction score
0
Oh, and another thing...regarding the "suspicious" apps that the OP referenced (the ones Google pulled from the marketplace). It turns out that reports on what the apps were sending to servers in China were grossly overblown. It was reported that text messages and voicemail passwords were being sent, but those reports were false. The app did send your phone number, but for a reason. Google did an investigation and found that the developer, just a normal dude in China, just wanted users of his apps to be able to recover their preferences (like favorite wallpapers, etc) if they ever switched phones, installed new ROM, or did a factory reset. Google said that there are better ways to impliment what this particular developer was intending to do, but it was innocent. Google issued a statement and and posted a list of best practices for all developers. I think Google was allowing those apps that were removed to go back onto the market.
 

aminaked

Silver Member
Joined
Jan 10, 2010
Messages
2,179
Reaction score
0
Location
California, USA
Sorry Boss.

I'm not sure he meant you. I totally agree with your comment:

The Original Poster said it was his Hotmail account that got hacked. That has happened to more than one person I know who still uses Hotmail. And of those people I know, none of them have Android phones. In fact, they don't have smart phones at all.

And now, they have all dumped Hotmail for something else (which I did years ago when I got my first Gmail invite).

I run a large email list including over 3,000 hotmail users. The account that sends out email receives quite a few spam messages...usually just a weird link all by itself...from hacked accounts. Hotmail has always been at the top of the list. Yahoo is 2nd. (As mentioned, the cure seems to be just to change your password.)

The bright side is that experiences like this teach
- select a complex password
- keep your software up to date
- don't use hotmail or yahoo (because they suck)
- if you visit strange sites, be careful and make sure your browser is closed after using them
 
Top