Showing posts with label Email. Show all posts
Showing posts with label Email. Show all posts

Saturday

Emails show how Clinton campaign chair was apparently hacked


WASHINGTON — New evidence appears to show how hackers earlier this year stole more than 50,000 emails of Hillary Clinton’s campaign chairman, an audacious electronic attack blamed on Russia’s government and one that has resulted in embarrassing political disclosures about Democrats in the final weeks before the US presidential election.

The hackers sent John Podesta an official-looking email on Saturday, March 19, that appeared to come from Google. It warned that someone in Ukraine had obtained Podesta’s personal Gmail password and tried unsuccessfully to log in, and it directed him to a website where he should “change your password immediately.”

Podesta’s chief of staff, Sara Latham, forwarded the email to the operations help desk of Clinton’s campaign, where staffer Charles Delavan in Brooklyn, New York, wrote back 25 minutes later, “This is a legitimate email. John needs to change his password immediately.”

But the email was not authentic.

The link to the website where Podesta was encouraged to change his Gmail password actually directed him instead to a computer in the Netherlands with a web address associated with Tokelau, a territory of New Zealand located in the South Pacific. The hackers carefully disguised the link using a service that shortens lengthy online addresses. But even for anyone checking more diligently, the address — “google.com-securitysettingpage” — was crafted to appear genuine.

In the email, the hackers even provided an Internet address of the purported Ukrainian hacker that actually traced to a mobile communications provider in Ukraine. It was also notable that the hackers struck Podesta on a weekend morning, when organizations typically have fewer resources to investigate and respond to reports of such problems. Delavan, the campaign help-desk staffer, did not respond immediately to the AP’s questions about his actions that day.

It is not immediately clear how Podesta responded to the threat, but five months later hackers successfully downloaded tens of thousands of emails from Podesta’s accounts that have now been posted online. The Clinton campaign declined to discuss the incident. Podesta has previously confirmed his emails were hacked and said the FBI was investigating.

The suspicious email was among more than 1,400 messages published by WikiLeaks on Friday that had been hacked from Podesta’s account.

It was not known whether the hackers deliberately left behind the evidence of their attempted break-in for WikiLeaks to reveal, but the tools they were using seven months ago still indicate they were personally targeting Podesta: Late Friday, the computer in the Netherlands that had been used in the hacking attempt featured a copy of Podesta’s biographical page from Wikipedia.

The US Office of the Director of National Intelligence and the Homeland Security Department have formally accused Russian state-sponsored hackers for the recent string of cyberattacks intended to influence the presidential election.

The help-desk staffer, Delevan, emailed to Podesta’s chief of staff a separate, authentic link to reset Podesta’s Gmail password and encouraged Podesta to turn on two-factor authentication. That feature protects an account by requiring a second code that is separately sent to a cell phone or alternate email address before a user can log in. “It is absolutely imperative that this is done ASAP,” Delevan said.

Tod Beardsley, a security research manager at the Boston-based cybersecurity firm Rapid7, said the fact that an IT person deemed the suspicious email to be legitimate “pretty much guarantees the user who is not an IT person is going to click on it.”

Other emails previously released by WikiLeaks have included messages containing the password for Podesta’s iPhone and iPad accounts.

source: newsinfo.inquirer.net

Tuesday

AOL Mail suffers security breach, users advised to change passwords

 
Users of America Online (AOL) Mail were advised this week to change their passwords soonest, after a security breach hit the email service.
 
In a blog post, the AOL Security Team said it is investigating the "security incident" that it said involved "unauthorized access" to its systems.
 
"We are writing to notify you that AOL is investigating a security incident that involved unauthorized access to AOL's network and systems. AOL is working with best-in-class external forensic experts and federal authorities to investigate this serious criminal activity," it said.
  
 

It said it noticed a "significant" increase in the amount of spam mail spoofing AOL Mail addresses, to trick recipients into opening the spam messages.
 
AOL added its investigation so far indicates an "unauthorized access to information regarding a significant number of user accounts."
 
"This information included AOL users' email addresses, postal addresses, address book contact information, encrypted passwords and encrypted answers to security questions that we ask when a user resets his or her password, as well as certain employee information. We believe that spammers have used this contact information to send spoofed emails that appeared to come from roughly 2% of our email accounts," it said.
 
However, it said there is no sign the attackers broke the encryption on the passwords or the answers to security questions.
 
There is also no sign so far the attack had led to the disclosure of users' financial information, including debit and credit cards, which it said is also fully encrypted.
 
Still, it urged users to change passwords as a precaution.
 
"Although there is no indication that the encryption on the passwords or answers to security questions was broken, as a precautionary measure, we nevertheless strongly encourage our users and employees to reset their passwords used for any AOL service and, when doing so, also to change their security question and answer," it said.
 
In the meantime, AOL said its security team has enhanced protective measures and is notifying potentially affected users.
 
Protection
 
Meanwhile, AOL urged users to take precautions against cyber risks, including:
 
  • Not responding to suspicious email, or clicking on any links or attachments in the email.
  • Contacting the sender to confirm that he or she actually sent an email, when in doubt about the authenticity of an email.
  • Not providing personal or financial information in an email to someone you do not know.
source: gmanetwork.com

Wednesday

Gmail bug can temporarily lock out users from accounts


Users of Gmail, Google's email service, may have to refrain from inserting images into messages, especially if they are using the Firefox browser.

This is due to a bug in Gmail that can temporarily lock out a user from his or her account, PC World reported.

"Google has acknowledged the problem but hasn't been able to stamp it out," PC World said,  adding Google had said it is "working hard to resolve this issue."

Citing Gmail's Known Issues page, it quoted Google as saying the bug is triggered under certain scenarios involving "inline images," or images inserted into the body of email messages.

But while it hits Firefox users who insert images into messages while composing or replying to email, it can also hit "users of any browser when they try to do this with large images."

PC World said the bug can also strike if one works "over time" on a draft message that has many images and attachments.

It said that for now, Google recommended that people use "a browser other than Firefox" when composing an email with images in the message body.

PC World said the bug could be linked to Google's new Compose Message window, which Google claimed is faster and simpler.

It also cited some users who said they are now "scared to continue to rely on Gmail now."

"When the bug is activated, Google locks people out of their account citing 'unusual usage' and telling them it has detected 'unusually high levels of activity.' It can take up to 24 hours for Google to lift the lockout and restore affected users' access to their accounts," PC World said. — LBG, GMA News

source: gmanetwork.com

Friday

Most Work Emails Not Important [STUDY]


You’ve got mail. But don’t worry, it’s probably not that important.

New research found that only one in four emails is essential for work. And only 14% of work emails were considered critically important.

That means nearly two-thirds of the emails in your inbox are nonessential for work. Of those nonessential emails, 11% are personal, and 7% are spam. With more than 60% of emails considered nonessential, the potential for email-based viruses and security breaches are top concerns for companies, according to the research. Increased use of remote and mobile email services only heightens concern.

“What is clear is that the average employee faces a significant challenge in simply processing the information that comes into their inbox and identifying which messages are genuinely business critical,” said Nathaniel Borenstein, chief scientist at cloud-based email management firm Mimecast, which conducted the research. “We often end up working for email, rather than having email work for us.”

“Email will remain a fundamental business tool for many years to come,” Borenstein said. “It is the global standard, but not always the gold standard. It is, therefore, vital that email can continue to develop and adapt as technology and working practices change.”

On a positive note, the study also found that businesses have finally warmed up to social media. Overall, 55% of businesses use LinkedIn, making it the most commonly used social media platform in the workplace. Facebook was the second-most popular service, used by 47% of workers.One in three respondents thought that increased use of social media in the workplace resulted in a decreased use of email. However, according to the survey, social media also increased the potential for information leaks and security breaches.

[No, Really, Facebook Makes Employees More Productive]

The research was based on the responses of 500 information technology decision-makers, 200 from the United States, 200 from the United Kingdom and 100 from South Africa. The research was conducted by Loudhouse Research for Mimecast as a part of the Shape of Email report.

source: mashable