<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:www.readwriteweb.com,2011:/1/tag:www.readwriteweb.com,2009://1.16674-</id>
  <updated>2011-08-16T16:30:52Z</updated>
  <title>Comments for Gmail, Yahoo, AOL, and Others Also Hit by Phishing Attack</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.35-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16674</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=16674" title="Gmail, Yahoo, AOL, and Others Also Hit by Phishing Attack" />
    <published>2009-10-06T13:06:00Z</published>
    <updated>2009-10-06T13:10:59Z</updated>
    <title>Gmail, Yahoo, AOL, and Others Also Hit by Phishing Attack</title>
    <summary>Yesterday&apos;s phishing attack in which several thousand Hotmail username and password combinations were leaked to the web now appears to be just the beginning of a massive phishing attack affecting users of multiple webmail services including Gmail, Yahoo, AOL, Comcast, and Earthlink. The original list was posted anonymously on pastebin.com, a site generally used by...</summary>
    <author>
      <name>Sarah Perez</name>
      
    </author>
    
    <category term="AOL" />
    
    <category term="Google" />
    
    <category term="NYT" />
    
    <category term="News" />
    
    <category term="Yahoo" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img alt="image credit:  Flickr user ToastyKen" src="http://www.readwriteweb.com/images/phishing_logo_jan08.jpg" />Yesterday's <a href="http://www.neowin.net/news/main/09/10/05/thousands-of-hotmail-passwords-leaked-online">phishing attack</a> in which several thousand Hotmail username and password combinations were leaked to the web now appears to be just the beginning of a massive phishing attack affecting users of multiple webmail services including Gmail, Yahoo, AOL, Comcast, and Earthlink. The original list was posted anonymously on <a href="http://pastebin.com/">pastebin.com</a>, a site generally used by developers sharing code snippets. Again, that site recently saw the addition 20,000 more login details from other webmail service providers, indicating what may the largest scale phishing attack to date.</p>]]>
      <![CDATA[

<h2>The Hotmail Attack </h2>

<p>In yesterday's attack, the list of comprised Hotmail accounts were limited to those where the usernames started with the letter "A" or "B." However, that seemed to imply that the posted portion might actually be a part of a bigger list containing even more login/password combinations. At the time, a Microsoft spokesperson said that the company determined "this was not a breach of internal Microsoft data and initiated our standard process of working to help customers regain control of their accounts." Instead, claimed the spokesperson, those users whose credentials were revealed were likely to be victims of an online phishing attack where a third-party website was involved.</p>

<p>Phishing attacks are typically carried out via email messages where the attacker tricks the recipient into revealing their username and password by pretending to be some sort of trustworthy entity such as the user's bank, IT administrator, a popular website, or an online service. In the case of the stolen Hotmail passwords, it's possible that the attacker sent emails which claimed to be from the end user's email provider. If the user then followed the link contained within the malicious email, they would have ended up not on the actual email provider's site, but on a third-party site whose sole purpose was to capture their username and password when entered.</p>

<h2>Beyond Hotmail: More Webmail Providers Affected </h2>

<p><img align="right" src="http://www.readwriteweb.com/images/gmail_logo.png" />According to a story in today's <a href="http://news.bbc.co.uk/2/hi/technology/8292299.stm">BBC News</a>, the most recent list of compromised accounts, which includes login credentials for Gmail, Yahoo, AOL, Earthlink, and Comcast users, contains some accounts that appear to be old, unused, or fake. However, many others listed are, in fact, genuine. </p>

<p>There's no way to be sure at this point that the new list is a part of the same phishing attack as yesterday's or if it's a new and separate scam. </p>

<p>The website where the accounts were posted - pastebin.com - is now "down for maintenance." Visitors to the site today will receive a message that reads:</p>

<blockquote>
<p><em>Pastebin.com is getting an unprecedented amount of traffic due to a news story in which some leaked Hotmail passwords have been pasted on this site</em></p>

<p><em>Pastebin.com was intended as a tool to aid software developers, not for distributing this sort of material. Filters have been put in place to prevent reoccurrence, but the current traffic level is unsustainable.</em></p>

<p><em>Pastebin.com is just a fun side project for me, and today it's not fun. It will remain offline all day while I make some further modifications</em></p>

<p><em>Paul Dixon</em></p>
</blockquote>

<p>Regardless of whether or not you think your account was compromised, today would be a good day to change the password on whichever webmail service you currently use. Better safe than sorry! </p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16674-comment:214436</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16674" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php#c214436" />
    <title>Comment from Fachri on 2010-05-28</title>
    <author>
        <name>Fachri</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>tkanks</p>]]>
    </content>
    <published>2010-05-29T04:44:08Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16674-comment:199252</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16674" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php#c199252" />
    <title>Comment from  Ilan Ben Menachem on 2010-03-25</title>
    <author>
        <name> Ilan Ben Menachem</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>That is scary!</p>]]>
    </content>
    <published>2010-03-25T19:44:25Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16674-comment:185502</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16674" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php#c185502" />
    <title>Comment from مركز تحميل on 2010-02-03</title>
    <author>
        <name>مركز تحميل</name>
        <uri>http://www.z3lanh.net</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.z3lanh.net">
        <![CDATA[<p>Phishing attacks are a waste of time for the ones who carry them. They gain too little.</p>]]>
    </content>
    <published>2010-02-03T09:21:18Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16674-comment:185210</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16674" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php#c185210" />
    <title>Comment from صور on 2010-02-02</title>
    <author>
        <name>صور</name>
        <uri>http://www.z3lanh.com/vb/f42.html</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.z3lanh.com/vb/f42.html">
        <![CDATA[<p>thanks so much 4 a nice topic. it's really a wonderful</p>]]>
    </content>
    <published>2010-02-02T19:03:15Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16674-comment:185157</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16674" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php#c185157" />
    <title>Comment from توبيكات on 2010-02-02</title>
    <author>
        <name>توبيكات</name>
        <uri>http://www.z3lanh.com/vb/f93.html</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.z3lanh.com/vb/f93.html">
        <![CDATA[<p>Twitter is in a similar situation to what Digg was when Yahoo! launched Buzz, but the difference is that Meme is better than Twitter and Buzz wasn’t better than Digg. Also, Digg wasn’t having stability issues like Twitter has been.</p>]]>
    </content>
    <published>2010-02-02T16:37:08Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16674-comment:175337</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16674" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php#c175337" />
    <title>Comment from game on 2009-12-18</title>
    <author>
        <name>game</name>
        <uri>http://www.zoombits.co.uk/games</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.zoombits.co.uk/games">
        <![CDATA[<p>The list of comprised Hotmail accounts were limited to those where the user-names started with the letter "A" or "B."Phishing attacks are a waste of time for the ones who carry them.I think this is crazy how people have nothing better to do with there time but sit around and try to destroy other peoples stuff its crazy and they need to get a life.</p>]]>
    </content>
    <published>2009-12-19T03:44:55Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16674-comment:161600</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16674" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php#c161600" />
    <title>Comment from forexthinker.com on 2009-10-07</title>
    <author>
        <name>forexthinker.com</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Phishing attacks are a waste of time for the ones who carry them.  They gain too little.</p>]]>
    </content>
    <published>2009-10-07T23:05:19Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16674-comment:161584</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16674" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php#c161584" />
    <title>Comment from Em on 2009-10-07</title>
    <author>
        <name>Em</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I use an iMAC so when I click a phishing site I get a big red warning pop-up. The truest way to identify a bogus site is this: say their from BANK OF AMERICA (as was my latest one) and you click the link, LOOK AT THE DOMAIN ADDRESS::: if it begins with a word or name OTHER THAN that which solicited your attention, it is fake. --- Em Jay</p>]]>
    </content>
    <published>2009-10-07T18:24:16Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16674-comment:161582</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16674" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php#c161582" />
    <title>Comment from jimmy on 2009-10-07</title>
    <author>
        <name>jimmy</name>
        <uri>http://jimmyteh90.blogspot.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://jimmyteh90.blogspot.com">
        <![CDATA[<p>That is scary!</p>]]>
    </content>
    <published>2009-10-07T17:44:40Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16674-comment:161577</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16674" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php#c161577" />
    <title>Comment from Chris Brown on 2009-10-07</title>
    <author>
        <name>Chris Brown</name>
        <uri>http://www.vacationrentalsad.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.vacationrentalsad.com">
        <![CDATA[<p>I think this is crazy how people have nothing better to do with there time but sit around and try to destroy other peoples stuff its crazy and they need to get a life... </p>]]>
    </content>
    <published>2009-10-07T16:51:19Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16674-comment:161481</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16674" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php#c161481" />
    <title>Comment from Wedding Photographer on 2009-10-07</title>
    <author>
        <name>Wedding Photographer</name>
        <uri>http://www.myweddingphotographer.co.za</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.myweddingphotographer.co.za">
        <![CDATA[<p>Sorry to be the stick in the mud, but I think that if someone is silly enough to be caught out by phishers then it could be a good lesson.</p>

<p>A lot is said by companies every single day about keeping your password safe, not giving your passwords to just anyone, making sure the URL points to the real site etc etc</p>

<p>I guess it's more the newbies that fall for this. Personally I've been on the net since 1995 and no Nigerian or phisher will be causing me to part with any one of my passwords :D</p>]]>
    </content>
    <published>2009-10-07T07:07:48Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16674-comment:161378</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16674" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php#c161378" />
    <title>Comment from Sarah Perez on 2009-10-06</title>
    <author>
        <name>Sarah Perez</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>what the heck is G G G mail? </p>]]>
    </content>
    <published>2009-10-06T16:41:43Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16674-comment:161366</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16674" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/gmail_yahoo_aol_and_others_also_hit_by_phishing_attack.php#c161366" />
    <title>Comment from Constant Gina on 2009-10-06</title>
    <author>
        <name>Constant Gina</name>
        <uri>http://www.vacationrentalsad.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.vacationrentalsad.com">
        <![CDATA[<p>damn...thats why I stick with G G G Mail...</p>]]>
    </content>
    <published>2009-10-06T15:23:46Z</published>
  </entry>

</feed>
