E-Mail Crooks Target Webmail Accounts

Imagine having to explain an e-mail message that asks your friends for money--a message sent from your Webmail account. (Webmail refers to any e-mail service you use via a Web browser rather than through an e-mail client.) That's exactly what's happening: Scammers are breaking into such ac­­counts and, from those addresses, sending e-mail messages to the victims' entire contact list. The messages often tout a Web site (such as an e-commerce site), or even ask for money directly.

By Erik Larkin
Tue, June 23, 2009

PC World — Imagine having to explain an e-mail message that asks your friends for money--a message sent from your Webmail account. (Webmail refers to any e-mail service you use via a Web browser rather than through an e-mail client.) That's exactly what's happening: Scammers are breaking into such ac­­counts and, from those addresses, sending e-mail messages to the victims' entire contact list. The messages often tout a Web site (such as an e-commerce site), or even ask for money directly.

It's a new, dastardly twist on an old scam. Crooks have long used harvested addresses in the 'From:' field on junk e-mail to make messages look realistic. But because anti­spam measures have been getting better at blocking such spoofed spam, the bad guys are now breaking in and sending e-mail from actual accounts.

Maureen Arnold, a former CPA in Apache Junction, Arizona, was hit by such an attack. When she checked her MSN mail one day, she found several warnings about undeliverable messages sent from her account that she hadn't written, along with messages in her Sent box. The scam e-mail--touting a site selling electronic products--went out to her family and friends. Similar attacks have asked recipients to wire money to a particular account; some have even deleted an account's contact list afterward.

The attacks underscore an oft-ignored fact: Webmail accounts are a major target because they have value. A recent report by the Anti-Phishing Working Group says the most common types of log-ins stolen by keylogger malware are for financial Web sites, e-commerce sites, and Webmail. In addition to hijacking an e-mail account to send out messages, crooks can often glean information that helps them break into a victim's financial accounts.

So how do you keep your valuable Webmail account safe? The first step, of course, is to keep your PC clean of malware. But that isn't a complete solution: Maureen Arnold checked her PC with mul­­tiple security scanners after she discovered the break-in, and found nothing.

Another important step is to as­­sume that any public or borrowed computer that you've used to check your Webmail account was infected with a keylogger, and that your account log-in was stolen. Change your password as soon as you can on a trusted, secure computer.

Web security expert Jeremiah Grossman of WhiteHat Security identifies another point of entry: Crooks often lift Webmail account details after breaking into other sites. Many sites require your e-mail address for logging in, and many people use the same password, as well, for their log-ins to different sites.

To address this problem, take two steps: First, use a unique password for your Webmail account. Free browser tools such as Password Hash can consolidate passwords. Second, when signing up for new accounts, use a "disposable" e-mail address--something AddressGuard, a feature in the premium Yahoo Mail Plus service ($20 per year), offers. Anonymizer's Nyms service works with any e-mail account; it's also $20 per year.

As you know, everything is mobile, connected, interactive, and immediate. This is exactly why organizations need a highly agile IT infrastructure in order to keep pace with extreme fluctuations in business demand. This book will help you understand why infrastructure convergence has been widely accepted as the optimal approach for simplifying and accelerating your IT to deliver services at the speed of business while also shifting significantly more IT resources from operations to innovation.
For this white paper, IDC performed an in-depth analysis of the business value of VMware View, defined as the expected ROI associated with the use of the solution as a platform for the targeted deployment of a virtual desktop infrastructure.
This paper explains virtualization, its benefits for mid-sized business and how IBM's virtualization strategy can help these companies reduce costs, improve services and simplify management.
Forrester Research makes recommendations on best practices to optimize branch virtualization and consolidation initiatives. See how a "thin" branch architecture, with key servers, services and applications in the data center that relies on a high-performing WAN connection, can offer the greatest efficiencies.
When trying to achieve continuous compliance with internal policies and external regulations, organizations need to replace traditional processes with a new best practice approach and new innovative technology, such as that provided by IBM Tivoli Endpoint Manager.
IBM Tivoli Endpoint Manager helps organizations automatically manage patches for multiple operating systems and applications across hundreds of thousands of endpoints regardless of location, connection type or status.  
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as support considerations
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
Applications are changing - they're increasingly web-oriented, global in nature and run from multiple device types. Additionally, the volume of data is growing exponentially every year. How do you ensure your applications have fast, accurate, up-to-date information in this new world? Modern applications are data-intensive; delivering data the old way using monolithic databases isn't working. What's needed is a modern approach to data. One that scales-out as needed and delivers predictable high performance, but without sacrificing data consistency or integrity.
VMware View™ 5 simplifies IT management while increasing end user freedom by delivering desktop services from your cloud. Building upon VMware's leadership in desktop virtualization, VMware View 5 delivers a high-performance user experience while giving IT greater policy control.

View this webcast and find out how VMware View 5 can help you:
- Deliver the highest fidelity experience of desktop services across any device and any network
- Simplify and automate IT management, security and control of desktop services
- Reduce the costs associated with your desktop environment
IT professionals are being asked to deliver faster "time-to-value" than ever before. An IDG Research survey found that CIOs are eager to invest in technologies that will enable them to get new applications and services up quickly, achieving faster time-to-value.
Learn how to reduce IT management overhead, ease revision control, guarantee data security, scale systems more quickly and reduce server and software costs.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center