Data Storage Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Information for Data Storage Professionals
Monday, September 6th 
Home
Storage Hardware
Storage Software
Storage Networks
Storage Trends
Next-Gen Storage
Data Security
DST Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement
Data Security

Massive E-Mail Phishing Attack Hits Web

Massive E-Mail Phishing Attack Hits Web
October 6, 2009 1:42PM

Bookmark and Share
Phishers have moved beyond Hotmail and posted thousands of e-mail details from other sites, including Gmail, Yahoo, AOL Mail, Verizon and others. It's unclear who may be behind the attacks, but security researchers warn that the phishing could be the first step toward a bigger Web attack. The situation is fluid, and the phishing may not be over.


In a situation that may still be developing, major phishing exploits have hit webmail services over the past few days, including Gmail, Hotmail, Yahoo, AOL Mail, and others. As usual with mass phishing attacks -- which aim to trick people into surrendering personal details about their online identities -- it's unclear what group or groups are behind the initiatives.

The one thing that is certain is the attacks are big.

"This is on a scale that is incredibly rare," said Mike Halsey, who runs The Long Climb, a PC support site in the U.K. "I don't think it's ever happened to this extent before, at least that I'm aware of."

A Fluid Situation

The situation is unfolding rapidly. Halsey said a couple of days ago the site www.neowin.net reported that PasteBin.com had posted personal details of about 20,000 users of Microsoft's Hotmail, MSN and Windows Live services. Then on Tuesday, details about an additional 20,000 subscribers to Gmail, Yahoo, AOL Mail, Verizon and others were posted at the same site. The posts are now off-line.

It's possible the criminals have details on many more users that they haven't disclosed.

Details are sketchy, and there is no certainty that the problems are over. Sean-Paul Correll, a threat researcher with Panda Security, said he didn't see any of the data from the attacks. But he noted that phishing attacks are often precursors to other initiatives.

"It is fairly common that this would be the first stage of a larger attack. They use these e-mail addresses for something else," he said. Correll added that identifying what group or groups are responsible depends upon seeing more of the infrastructure Relevant Products/Services -- such as the scripts they are using -- than just e-mail addresses. He wasn't sure what information Relevant Products/Services might be available to researchers.

A Focus on Browser Security

The next move is up to the criminals. Halsey pointed out that browser security is vital and the size of the apparently ongoing phishing attacks should serve as a warning to browser vendors, including Microsoft, Opera, Apple and Mozilla. Luckily, these companies are focusing on improving the security of their products.

While Halsey isn't too worried about this week's activities, he is concerned about the long-term impact. "I would say this is probably isolated," he said of the phishing attacks. "The danger is that people pay a lot of attention when something like this is publicized but forget too quickly and do not learn. ... They shouldn't panic, or stop banking on the Internet or shopping on the Internet, as long as they are careful."

He added that good advice is available from a number of sources, including the British government, the FBI, and his site.

The key, according to Halsey, is to address the problem. "It is worrying from my point of view," he says. "It says people are not aware enough of what the threats are and that Internet service providers and major technology companies are not doing enough to warn people what the dangers are and how to avoid them, which is disappointing."

Tell Us What You Think
Comment:

Name:

Advertisement



 Data Security
1. Consumer Watchdog Attacks Google
2. Spammers Take Over Apple's Ping
3. VMware Reinforces 'IT as a Service'
4. Hackers Invade iTunes Accounts
5. Security Threats a Record, IBM Says


advertisement


 Most Popular Articles
1. Dell Buys Virtualization Storage Provider 3PAR
2. Patch Fixes SMB Attack That Could Come from Within
3. Intel Will Acquire McAfee To Secure Online Computing
4. Apple Issues iOS Patch To Block Hacker Bonanza
5. Intel's Deal for 'Buggy Whip' Maker McAfee Will Impact IT

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  HP vs. Dell: Behind the Showdown
  Consumer Watchdog Attacks Google
  Spammers Take Over Apple's Ping
  HP Wins 3PAR at $2.4B as Dell Quits
  Data Storage Advances Are Looming

 Technology Marketplace
Compliance
Stand out from other IS Professionals and increase your earning potential.®.
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Data Storage
Isilon scale-out storage is simple. Simple is smart.
 
Digital Life
IT PROS: Receive $10 in rewards to complete a 15 min. survey.
 
Enterprise I.T.
Stand out from other IS Professionals and increase your earning potential.®.
IT PROS: Receive $10 in rewards to complete a 15 min survey.
 
Enterprise Software
Manage limitless content today—read EMC’s 15-minute guide to ECM.
 
Mobile Gadgets
White Paper The Motorola ES400: Desktop power in a pocket-sized device
 
Mobile Industry News
The Motorola ES400: Desktop power in a pocket-sized device.
 
Mobile Phones
The Motorola ES400: Desktop power in a pocket-sized device.
 
Navigation
Data Storage Today
Home/Top News | Storage Hardware | Storage Software | Storage Networks | Storage Trends | Next-Gen Storage | Data Security
DST Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 Data Storage Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.