Unconfigured Ad Widget

Collapse

email hacked again after password change

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • tackdriver
    Senior Member
    • Jun 2009
    • 1173

    email hacked again after password change

    My Hotmail email was hacked and my friends are getting spammed by some lowlifes. I changed my Microsoft/Hotmail password after the first time and it happened again. I checked the account activity area and, odd thing is, the day/time that this spam was sent, didn't show. Also, the latest spam sent emails to people who's account I deleted MONTHS ago. Lastly, even after spending hours on it, I cannot find out how to change my "lost password security question"

    ANy of you guys who know about this stuff got any advice??
    Thx for any help

    Steve
  • #2
    Gringo Bandito
    Senior Member
    • Apr 2006
    • 1835

    Have you scanned your computer for malware? Malwarebytes is a good one.

    Sent while driving at 80mph, eating a Big Mac and using my knee to steer.

    Comment

    • #3
      ojisan
      Agent 86
      CGN Contributor
      • Apr 2008
      • 11769



      Wait a few days and try again.

      Originally posted by Citadelgrad87
      I don't really care, I just like to argue.

      Comment

      • #4
        ldsnet
        Senior Member
        • Oct 2008
        • 1418

        These days a spammer can send from "your account" without using your account - they send a crafted message to look like its from you to hide their identity.

        If the message is not in your sent folder, chances are he didn't use your account. It only took one access to get your address book and they have it.

        Pretty painful and not much you can do about it after the fact - as long as these folks don't face criminal prosecution, it will continue (but since he is probably in China or Russia, he won't be going to jail any time soon).

        Look on the bright side - its your email and not your checking account!

        Comment

        • #5
          tackdriver
          Senior Member
          • Jun 2009
          • 1173

          update

          Thx for the quick response guys. Yes, I did run the scan and am aware of the heart virus thingy. The prob (currently) is only my Hotmail account that I am having a problem with. I did change the password, but if the scum had access to my account, he may have discovered by lost password security challenge question/answer too. and change make changes to my account For the life of me, I cannot find anything that tells me how to change the security question

          Comment

          • #6
            tackdriver
            Senior Member
            • Jun 2009
            • 1173

            Idsnet, now this makes sense to what is happening. If it is, the bastard got access to my account months ago and it just now using it. It is not in my sent folder. Under properties I did find a "return path" address, (not mine) but am not sure what to do with it. As this is a different return path from my true one, can people just block this email address without it affecting my actual one?

            Comment

            • #7
              9w1911
              Member
              • Oct 2013
              • 101

              if you are sending spam from your account there is not much you can do other than keep changing your password and make it more difficult, however you may have to delete this account and start over, it sucks but it happens
              and it most likely is not a person but a group of thousands of computers affecting your and thousands of other accounts

              Comment

              • #8
                ocabj
                Calguns Addict
                • Oct 2005
                • 7924

                Get answers to some basic questions about what two-step verification is, and how to set it up and use it to help keep your Microsoft account more secure.

                Distinguished Rifleman #1924
                NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
                NRL22 Match Director at WEGC

                https://www.ocabj.net

                Comment

                • #9
                  blazeaglory
                  Calguns Addict
                  • May 2011
                  • 6370

                  Damn. I can literally watch attempts on my hotmail at least 500 times per day...lol
                  A note to the NSA or anyone gathering information on me, this disclaimer is for you..."Everything I type on this website Is purely fictional and for entertainment purposes only. None of it is true."

                  Also, sometimes I type in CAPS to emphasize a POINT. Please dont interpret that as YELLING. Sorry if I HURT any fuzzy little bunny's FEELINGS out there.

                  Comment

                  • #10
                    tackdriver
                    Senior Member
                    • Jun 2009
                    • 1173

                    Hi guys. I didn't think there was much I could do but it never hurts to ask. Only good thing to come of it is I finally got around to making all my passwords a little more complicated. One of those things that you don't think would ever happen to you!! I admit, I got off easy.

                    thx again

                    Comment

                    • #11
                      gdr_11
                      Veteran Member
                      • Feb 2008
                      • 2560

                      Thanks to the info I received here on my earlier similar thread, I implemented a two-step authorization process with my Yahoo Mail and changed my antivirus software. So far, a couple of weeks have passed and I have received only two "failed to deliver" messages indicating that a spammer had used my email address. These two efforts may well have come before I made the changes, so I am happy for the time being
                      In an emergency, always dial 1911.

                      Comment

                      • #12
                        laurelpark
                        Senior Member
                        • Aug 2011
                        • 1013

                        Two factor authorization is about the best thing you can do to protect yourself from these things. Look at all the drama people are going through right now with this Heartbleed bug. Everyone is changing their passwords at all their sites, but they don't know if the site itself has implemented the patch yet. So, as they change their password, if the site hasn't implemented the patch, they're broadcasting a new password to the bad guys. This is a gigantic problem - hardly any bad guys knew about this bug before Monday - now they're all trying to exploit it. At the same time, everyone in the world is changing passwords - so the bad guys are grabbing them like crazy.

                        Most people use the same (or just a few) passwords across all the sites that they visit. If a bad guy intercepts the password you use on one site, all they have to do is try that password at other sites - and eventually they'll hit one that works. Hopefully it's not your credit card login, bank login, mortgage login, you get the picture...

                        One-time-passwords (two factor authentication) gets around this by using a cryptographic algorithm to generate a strong one-time-password when you log in. So, even if a bad guy intercepts it, it doesn't do them any good - the password is only good once, and it's only good for about 30 seconds.

                        Shameless plug - if you're interested in how this works, here's one that I personally like because I'm affiliated with it (it's free for end-users, by the way - and I've been reaching out to the commercial firearms sites to give it to them, too):

                        Comment

                        • #13
                          Satex
                          CGN/CGSSA Contributor
                          CGN Contributor
                          • Feb 2006
                          • 3501

                          Your account didn't get hacked the way you think. Spammers don't care using your actual account, they only want valid email addresses and names. Once they get a hold of a list they use it to forge email that appears to come from you to people you know but its never sent from your account. Anyone can send email using forged headers. You learn how to do that in networking 101.

                          Comment

                          • #14
                            ocabj
                            Calguns Addict
                            • Oct 2005
                            • 7924

                            You don't learn how to forge headers in a networking course. That's application layer.

                            Distinguished Rifleman #1924
                            NRA Certified Instructor (Rifle and Metallic Cartridge Reloading) and RSO
                            NRL22 Match Director at WEGC

                            https://www.ocabj.net

                            Comment

                            • #15
                              tackdriver
                              Senior Member
                              • Jun 2009
                              • 1173

                              Hi everyone and once again, thx for the advice. I now understand what it is that's going on. I did find (on my own, really!) that if you right click the fake email, go to properties you can find the email of the butt wipe who sent it. You can then block any further emails from this sender.
                              Not as screwed as I'd originally thought, but it was an eye opener.

                              Comment

                              Working...
                              UA-8071174-1