Hacking email accounts doesn't have English sex moviesto be a sophisticated affair.
We are reminded once again of this fact thanks to a report released Friday by the Microsoft Threat Intelligence Center detailing how a group of hackers targeted the email accounts of journalists, government officials, and the campaign of a U.S. presidential candidate. And here's the thing, the bad actors didn't use some fancy 1337computer skills, but rather employed the oldest trick in the book: the password reset.
According to Microsoft, over a 30-day period in August and September of this year, hackers likely affiliated with the Iranian government went after 241 email accounts and successfully compromised four. The MTIC dubbed the group Phosphorous, and explained how the team operated.
"Phosphorous used information gathered from researching their targets or other means to game password reset or account recovery features and attempt to take over some targeted accounts," reads the blog post. "For example, they would seek access to a secondary email account linked to a user’s Microsoft account, then attempt to gain access to a user’s Microsoft account through verification sent to the secondary account."
Importantly, MTIC writes that the four compromised accounts were not tied to the U.S. presidential campaign. But, still, this isn't good.
Password-reset features come in many forms, from questions about where you went to high school or your mother's maiden name to sending a link or code to a secondary email address or phone number. The former opens victims up to attack by anyone who knows how Google works, while the latter makes your primary email only as secure as your linked secondary email or cell phone.
A prominent abuse of this feature came in 2008, when a 20-year-old college student accessed Sarah Palin's Yahoo email account. He used information like Palin's ZIP code and birthday to reset her account password and gain access to the email account.
"While the attacks we’re disclosing today were not technically sophisticated," explain MTIC, "they attempted to use a significant amount of personal information both to identify the accounts belonging to their intended targets and in a few cases to attempt attacks."
SEE ALSO: How to find stalkerware on your smartphoneThis warning from Microsoft should serve as a reminder to everyone online that a password alone isn't enough to protect your email — especially if someone is motivated to hack the account. Instead, use multi-factor authentication and for the love of god create a unique password.
Oh, and consider ditching those password-reset questions altogether.
Topics Cybersecurity
Previous:The National Hologram
Next:Character Assassins
John F. Kennedy could give off serious serialPeople are terrible at remembering where they read news onlineKids absolutely lose it over football hero in this sweet videoChange this security setting on WhatsApp right nowNeed to fix your laptop or buy Coachella tickets? Float wants to offer you some tiny loansElizabeth Warren explained why #ShePersisted on 'The Daily Show'Face it, Super Liking on Tinder is for losersNo, Mark Zuckerberg isn't about to be overthrown by shareholdersRiverdale recap: Episode 3 smashes the patriarchyIn weird ad, Kellyanne Conway tells people to buy Ivanka's line of clothesApple CEO Tim Cook: Tech companies have to fight fake newsWill going public ruin Snapchat?More proof that 2017 is just 'Black Mirror' IRL: Bee dronesThis photo is why Rosie O'Donnell absolutely has to play Steve Bannon on 'SNL'Need to fix your laptop or buy Coachella tickets? Float wants to offer you some tiny loansEast Coast blizzard got you down? Cute animals in the snow are here to help.Hillary Clinton had the best response to Trump's 'Muslim ban' defeatFerocious blizzard smacks New York, but it'll be over sooner than you thinkWind power is now the top clean energy source in the U.S.Meanwhile, Australia's in the grip of an intense heatwave straight from hell A shop in Wales is selling chocolate orange and lettuce sandwiches for a very nice reason Chuck Barris, creator of 'Gong Show,' dies at 87 Women's mansplaining experiences will make you want to throw things Some of Google's Nest cameras are vulnerable to attacks Lorde, Chance the Rapper and the Killers will headline Lollapalooza British man walks over 1,500 miles to raise funds for streetchildren Netflix's 'Death Note' teaser trailer opens the book on horror and destruction Woman took out an ad on 900 taxis to propose to her boyfriend Google finally gives brands more ways to keep ads off hateful Youtube videos Emirates already tweeted a joke about the electronics ban 7 features to look forward to in Android O LeBron James to LaVar Ball: 'Keep my kids' name out of your mouth' Canada might follow the U.S. and U.K. with flight 'laptop ban' Google cancels some Fiber internet projects, latest in many setbacks for ambitious plan Drake just shattered his Spotify record with an Apple Music record Make sure your Facebook Messenger friends don't get read receipts ‘Follow your passion’ is wrong, here are 7 habits you need instead One brewery's latest beer took the trip from the toilet to the tap Sombra gets buffed and Ana gets nerfed in the latest 'Overwatch' patch #DeleteUber campaign inspired 500,000 to delete accounts in one week: NYTimes
2.2528s , 8206.1484375 kb
Copyright © 2025 Powered by 【English sex movies】,Pursuit Information Network