Hacking email accounts doesn't have to be a sophisticated affair.
We are reminded once again of this fact thanks to a report released Friday by the Microsoft Threat Intelligence Center detailing how a group of hackers targeted the email accounts of journalists, government officials, and the campaign of a U.S. presidential candidate. And here's the thing, the bad actors didn't use some fancy 1337computer skills, but rather employed the oldest trick in the book: the password reset.
According to Microsoft, over a 30-day period in August and September of this year, hackers likely affiliated with the Iranian government went after 241 email accounts and successfully compromised four. The MTIC dubbed the group Phosphorous, and explained how the team operated.
"Phosphorous used information gathered from researching their targets or other means to game password reset or account recovery features and attempt to take over some targeted accounts," reads the blog post. "For example, they would seek access to a secondary email account linked to a user’s Microsoft account, then attempt to gain access to a user’s Microsoft account through verification sent to the secondary account."
Importantly, MTIC writes that the four compromised accounts were not tied to the U.S. presidential campaign. But, still, this isn't good.
Password-reset features come in many forms, from questions about where you went to high school or your mother's maiden name to sending a link or code to a secondary email address or phone number. The former opens victims up to attack by anyone who knows how Google works, while the latter makes your primary email only as secure as your linked secondary email or cell phone.
A prominent abuse of this feature came in 2008, when a 20-year-old college student accessed Sarah Palin's Yahoo email account. He used information like Palin's ZIP code and birthday to reset her account password and gain access to the email account.
"While the attacks we’re disclosing today were not technically sophisticated," explain MTIC, "they attempted to use a significant amount of personal information both to identify the accounts belonging to their intended targets and in a few cases to attempt attacks."
SEE ALSO: How to find stalkerware on your smartphoneThis warning from Microsoft should serve as a reminder to everyone online that a password alone isn't enough to protect your email — especially if someone is motivated to hack the account. Instead, use multi-factor authentication and for the love of god create a unique password.
Oh, and consider ditching those password-reset questions altogether.
Copyright © 2023 Powered by
Report: Hackers use simple trick to target U.S. presidential campaign and government officials-鼓盆之戚网
sitemap
文章
63
浏览
591
获赞
8
Encrypted Signal app downloads skyrocket amidst nationwide protests
When the police state comes knocking, a little bit of privacy goes a long way. As peaceful protesterBest deals of the day Jan. 12: Roborock S7, Lenovo Tab M8, ProForm adjustable dumbbells, and more
We've rounded up all the best deals we could find on Jan. 12 —here are our top picks:BEST FITNSTIs are rife over the holidays. Here’s how to keep yourself safe.
Let’s face it, sexually transmitted infections (or STIs) are probably not the first thing to cBrands suspend advertising on X after ads appear alongside Nazi content
Less than a week after X CEO Linda Yaccarino claimed the platform formerly known as Twitter was safeEncrypted Signal app downloads skyrocket amidst nationwide protests
When the police state comes knocking, a little bit of privacy goes a long way. As peaceful protesterReddit launches an Official label
Reddit is testing its own version of the blue check mark."Starting today, we’re beginning earlSpotify is testing an 'Offline Mix' playlist for times when signals are spotty
Isn't it annoying when you need your daily dose of music, but your internet connection is patchy, orTikTok's most viral songs in 2022
There's perhaps no social media app that has a greater influence on music right now than TikTok, soTwitter's audio tweets reveal a bigger accessibility problem
Twitter started rolling out a brand new featureearlier this week that allowed iOS users to share recSamsung sets next Galaxy Unpacked stream for July
Now that Google's first foldable is out of the way, it's time for Samsung's fifth round of bendy-scrWhat is post
As I try for the hundredth time to knock one outand inevitably fail miserably, I’m forced to rAre Twitter's birthday balloons broken?
We already know that Twitter is withering away like a sad little grape on a vine, but today it seemsDark Sky mercifully gives Android users 1 more month until shutdown
Dark Sky has been sold to Apple, there's no changing that.However, Android users of the service willBrands suspend advertising on X after ads appear alongside Nazi content
Less than a week after X CEO Linda Yaccarino claimed the platform formerly known as Twitter was safeMicrosoft's Bing and Edge features give online shopping a generative AI makeover
Microsoft's Bing search engine and the Edge browser now have AI shopping tools that work like your v