On GameSpot: Vote for the 2009 Game of the Year!
BNET Business Network:
BNET
TechRepublic
ZDNet

October 5th, 2009

Hotmail hacked: Thousands of account details published online

Posted by Zack Whittaker @ 9:47 am

Categories: Breaking news, Microsoft, Productivity, Security, Windows Live

Tags: MSN Hotmail, Microsoft Windows Live, Phishing, Cyberthreats, Spam, E-mail Providers, Viruses And Worms, Security, Spam And Phishing, Internet

Update (19:55 GMT): added statement from Microsoft at the end.

Thousands, perhaps tens of thousands of Hotmail accounts have been hacked through phishing sites and published online, according to the BBC.

The news is still breaking but according to Neowin, who first reported the story, Microsoft have enacted a rapid-response protocol to limit the damage.

According to Neowin:

“It appears only accounts used to access Microsoft’s Windows Live Hotmail have been posted, this includes @hotmail.com, @msn.com and @live.com accounts.

However, considering the Windows Live ID is a single sign-on solution for all Microsoft and Windows Live services, the implications could be a lot greater than first considered.

While phishing is relatively new in the grand scheme of online malware and threats, it seems the tens of thousands of users have mistaken a genuine login page for a fake one, and are now suffering the consequences.

This poses a question I have considered for some time now. There will no doubt be a number of students who have been a victim in this phishing campaign who have been sending and receiving important emails through the service, instead of their own university dedicated system.

Phishing often relies on the service targeted having a massive user base. In comparison to colleges and universities, Hotmail has a greater number of users worldwide, therefore the benefits reaped would be greater.

As a result, it is not clear whether users of Live@edu were targeted, considering the Windows Live ID sign-in process is identical to that of Hotmail. The potential, however, is very much there,

It is unclear at this time whether this is a “proof of concept” come protest-like attack, as the potential to take advantage of these accounts on a personal scale could be endless. But considering the details were published to the wider web, it seems to me it could be a way of alerting people to the consequences of phishing and/or the security of Hotmail.

With the simplicity of the Windows Live ID sign-in screen, to attempt to create a phishing site from this is surprisingly easy. However with the most recent browsers, a clear green bar or similar will indicate that in fact the sign-in screen is secure.

Nevertheless, it is an interesting story which may well see Microsoft bump up their security to Yahoo! anti-phishing standards.

Microsoft’s statement:

“Over the weekend Microsoft learned that several thousand Windows Live Hotmail customers’ credentials were exposed on a third-party site due to a phishing scheme. As always, upon learning of the issue, we immediately requested that the credentials be removed and launched an investigation to determine the impact to customers.

As part of that investigation, we determined that this was not a breach of internal Microsoft data and initiated our standard process of working to help customers regain control of their accounts.”

Zack Whittaker, the youngest in the ZDNet network, is a British student at the University of Kent, Canterbury, where he studies BA (Hons) Criminology and Social Policy. His insight into the next-generation is unique and first-hand, sharing his knowledge of the here and now but more so what's next and how to get there.

You can read his public biography and his work disclosures of his current and past industry affiliations.

Fire off an email if you feel like sharing a story or insight, or leave a voicemail. You can also follow him on Twitter to keep up to date with his ramblings.

Subscribe to iGeneration via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 77 Talkback(s)
Hotmail Phishing Scam
A friend of mine fell victim to this scam. A few weeks ago a number of servers in China were set up to "pose" as hotmail, live, etc. servers. The ones I am aware of were posing to provide informatio... (Read the rest)
Posted by: HT Slider Posted on: 10/28/09  (Edited: 10/28/09 @ 01:09) You are currently: a Guest | | Terms of Use
wrong headline  Linux Geek | 10/05/09
Facts...  Joe_Raby | 10/05/09
Sounds like it is more than a simple phishing attack. They are somehow  DonnieBoy | 10/05/09
DNS  LiquidLearner | 10/05/09
Keep in mind  AzuMao | 10/07/09
login.live.co  Me_too | 10/10/09
*claps*  TylerM89 | 10/05/09
Let's wait until we see what it really is. It does sound like more than a  DonnieBoy | 10/05/09
And here I thought..  TylerM89 | 10/05/09
Go tell those hacked that 10,000 hacked accounts is nothing, they'll like  The Mentalist | 10/05/09
Way to skim the comment..  TylerM89 | 10/05/09
hacked???? Really?  pupkin_z | 10/05/09
It all depends on how they ended up at the site. If they were redirected  DonnieBoy | 10/05/09
Hold your horses  The Mentalist | 10/05/09
@Mentalist  LiquidLearner | 10/05/09
Come on, until we have more info, we can not just blame this on "stupid"  DonnieBoy | 10/05/09
Perhaps...  The Mentalist | 10/05/09
So the hundreds of people  LiquidLearner | 10/05/09
This stupid user only used Hotmail for stupid email.  No More Microsoft Software Ever! | 10/07/09
Because...  TylerM89 | 10/05/09
have you read the original story...?  doctorSpoc | 10/05/09
Hacked?  eqpc | 10/05/09
If it were a simple phishing attack, then it would not be limited to just  DonnieBoy | 10/05/09
Why do you say that?  eqpc | 10/05/09
So, just wait until you know. It would be very easy to create login screens  DonnieBoy | 10/05/09
They exist... (nt)  LiquidLearner | 10/05/09
RE: Hotmail hacked: Thousands of account details published online  mmb311 | 10/05/09
Don't be too quick to blame this on user stupidity. It sounds like they may  DonnieBoy | 10/05/09
That Is...  GuyAlanDye | 10/05/09
Well, a lot of people doing a lot of screaming BEFORE we know what happened  DonnieBoy | 10/05/09
try basic security like...  janitorman | 10/07/09
Phishing is NOT new  rogerbro@... | 10/10/09
RE: Hotmail hacked: Thousands of account details published online  mmb311 | 10/05/09
We need to wait and see what really happened. There must be a reason why it  DonnieBoy | 10/05/09
RE: We need to wait and see what really happened. There must be a reason  mmb311 | 10/05/09
Unless the DNS was hacked so that they got there by just typing in the URL  DonnieBoy | 10/05/09
Hotmail NOT hacked  Joe_Raby | 10/05/09
RE: Hotmail hacked: Thousands of account details published online  Loverock Davidson | 10/05/09
Hey Ken, did you know your hotmail account is one of those that got hacked?  The Mentalist | 10/05/09
I have it right here...  The Mentalist | 10/05/09
The AUTHOR!!!! COME CLEAN!!!! EXPLAIN THIS HACKING TO US!  pupkin_z | 10/05/09
ARE YOU COMPLETELY STUPID????  de-void | 10/05/09
rofl...  jasonp@... | 10/05/09
Sorry 'bout that wink (NT)  de-void | 10/06/09
In my defence  zwhittakerZDNet Moderator | 10/05/09
My account was HACKED!!!!  tonymcs@... | 10/05/09
Whose fault?  jpdemers@... | 10/08/09
That's not phishing  ITLeader | 10/08/09
Um... no  mmb311 | 10/08/09
wrong wrong wrong  nanotm | 10/08/09
Asking somebody for their password and saving it when they give it to you  AzuMao | 10/08/09
You need to add another update Zack  NonZealot | 10/05/09
More relevant question, can I learn if I got suckered?  Rob Oakes | 10/05/09
Poor response...  jasonp@... | 10/05/09
RE: Poor response  waltersc | 10/05/09
Point taken...  jasonp@... | 10/05/09
BBC update: It's gmail too  timisaac@... | 10/06/09
So was GMail also HACKED?  Qbt | 10/06/09
OH MY - THE SKY IS FALLING - THE INTERNET IS DEAD  de-void | 10/06/09
RE: Hotmail hacked: Thousands of account details published online  Evisscerator | 10/07/09
Furuners are behind all evil...  randysmith@... | 10/07/09
RE: Hotmail hacked: Thousands of account details published online  yankeedoodle58 | 10/07/09
RE: Hotmail hacked: Thousands of account details published online  victim43@... | 10/07/09
Clicking on links  compudog | 10/07/09
"clicking on links"  janitorman | 10/07/09
Fuzzy areas...  fjpoblam | 10/07/09
Avoiding Phishing  jpdemers@... | 10/08/09
"Phishing scam compromises thousands of hotmail accounts"  janitorman | 10/07/09
RE: Hotmail hacked: Thousands of account details published online  vilppuu@... | 10/08/09
Not a hack  sgtm8@... | 10/08/09
How many MSDN members hacked/phished?  TranMan | 10/08/09
RE: Hotmail hacked: Thousands of account details published online  drdam4n | 10/08/09
RE: Hotmail hacked: Thousands of account details published online  drdam4n | 10/08/09
RE: Hotmail hacked: Thousands of account details published online  nanotm | 10/08/09
RE: Hotmail hacked: Thousands of account details published online  Me_too | 10/10/09
RE: Hotmail hacked: Thousands of account details published online  nettechdesign@... | 10/10/09
Hotmail Phishing Scam  HT Slider | 10/28/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here