Hacking email accounts doesn't have to be a sophisticated affair.
We are reminded once again of this fact thanks to a report released Friday by the Microsoft Threat Intelligence Center detailing how a group of hackers targeted the email accounts of journalists, government officials, and the campaign of a U.S. presidential candidate. And here's the thing, the bad actors didn't use some fancy 1337computer skills, but rather employed the oldest trick in the book: the password reset.
According to Microsoft, over a 30-day period in August and September of this year, hackers likely affiliated with the Iranian government went after 241 email accounts and successfully compromised four. The MTIC dubbed the group Phosphorous, and explained how the team operated.
"Phosphorous used information gathered from researching their targets or other means to game password reset or account recovery features and attempt to take over some targeted accounts," reads the blog post. "For example, they would seek access to a secondary email account linked to a user’s Microsoft account, then attempt to gain access to a user’s Microsoft account through verification sent to the secondary account."
Importantly, MTIC writes that the four compromised accounts were not tied to the U.S. presidential campaign. But, still, this isn't good.
Password-reset features come in many forms, from questions about where you went to high school or your mother's maiden name to sending a link or code to a secondary email address or phone number. The former opens victims up to attack by anyone who knows how Google works, while the latter makes your primary email only as secure as your linked secondary email or cell phone.
A prominent abuse of this feature came in 2008, when a 20-year-old college student accessed Sarah Palin's Yahoo email account. He used information like Palin's ZIP code and birthday to reset her account password and gain access to the email account.
"While the attacks we’re disclosing today were not technically sophisticated," explain MTIC, "they attempted to use a significant amount of personal information both to identify the accounts belonging to their intended targets and in a few cases to attempt attacks."
SEE ALSO: How to find stalkerware on your smartphoneThis warning from Microsoft should serve as a reminder to everyone online that a password alone isn't enough to protect your email — especially if someone is motivated to hack the account. Instead, use multi-factor authentication and for the love of god create a unique password.
Oh, and consider ditching those password-reset questions altogether.
Copyright © 2023 Powered by
Report: Hackers use simple trick to target U.S. presidential campaign and government officials-燕尔新婚网
sitemap
文章
84
浏览
8224
获赞
9946
You can now watch YouTube with iPhone's Picture in Picture mode without a premium account
This is a pleasant surprise: YouTube's mobile website now allows Picture in Picture mode on an iPhonYouTube will now tell you how much of your life you spend watching videos
Google is worried about your digital health. More specifically, your addiction to watching hours upoCop called on black state representative campaigning in her neighborhood has the right response
Another day, another name to add to the ever-growing list of "Black People Who Had The Cops Called OGoogle Maps now lets you control music while navigating
Switching between songs and albums can be a chore while you're in a car and following Google Maps' iThe new MacBook Air and MacBook Pro are powered by Apple's own M1 chip
Apple has officially unveiled two new pieces of hardware: the MacBook Air and MacBook Pro. Both MacBThe Zaif cryptocurrency exchange wasn't 'impossible' to hack
I guess we shouldn't be all that surprised. But still, they did say it would be practically impossibTwitter launches voter registration campaign #BeAVoter
Who said enlightened democracy was dying in the combative cesspool of social media?Twitter has launcNo, Trump can't use FEMA's emergency alerts as a Twitter alternative
UPDATE: Sept. 21, 2018, 12:35 p.m. EDT The test has been delayed until October 3. Prepare yourself a5 ways to charge your new iPhone 12
Apple did the unthinkable with its new iPhone 12: It stopped including a charging brick in the box.If these renders are for real, the iPad has never been so beautiful
We're less then ten days away from Apple's Sept.12 event, at which the company is likely to announcePlease enjoy this Spotify playlist we made for your dog
Forget Shark Week, it’s Bark Week on Mashable. Join us as we celebrate all the good dogs, whicMicrosoft says it can recover missing files following botched Windows 10 update
Microsoft abruptly paused the October 2018 Update of its Windows 10 operating system after reports tGoogle buys Fitbit for $2.1 billion
Apple Watch needs to watch out.Well, that remains to be seen, but the competition is about to get aWe are sorry to say that Don Jr. posted some Fourth of July memes of his dad
Once again, Donald Trump, Jr. has made the misguided choice to log on.The large adult son and fish pDuckDuckGo, the pro
In an age where it seems nearly every major internet service is looking to hawk your personal data,