Google: Phishers stole e-mail from U.S. officials, others
A phishing campaign compromised hundreds of accounts with targeted messages
IDG News Service - Google has disrupted what it believes to be a targeted phishing campaign aimed at stealing e-mail from government officials, contractors and military personnel.
The criminals behind the campaign have broken into hundreds of Gmail accounts belonging to "U.S. government officials, Chinese political activists, officials in several Asian countries (predominantly South Korea), military personnel and journalists," among others, Google said in a blog post published Wednesday.
The company believes that the accounts were compromised "likely through phishing" by a cyber campaign run out of Jinan, China. That's the city whose Lanxiang Vocational School was linked in a New York Times report last year to the December 2009 attacks on Google's back-end systems. The targets of the 2009 campaign were human rights activists, and activists were also hit by this recent phishing campaign, Google said.
The phishing campaign was first publicly disclosed by the blog Contagio Malware Dump, which reported in February that government personnel and contractors were being hit with what are known as spear-phishing attacks. These attacks use specially crafted e-mail messages, written to appear like they come from someone known to the victim.
Victims were sent spoofed e-mail messages that looked like they came from friends or partner agencies, including targets in the U.S. Department of State, the Office of the Secretary of Defense, and Defense Intelligence, Contagio Malware Dump reported. "The message is crafted to appear like it has an attachment with links like View Download and a name of the supposed attachment. The link leads to a fake Gmail login page for harvesting credentials," Contagio Malware Dump said.
Once they had access to the Gmail accounts, the hackers then forwarded e-mail to their own addresses and harvested the data they found in order to launch future attacks.
Although these spear-phishing attacks didn't affect a lot of users, attacks on Web-based e-mail accounts have become a common problem for companies such as Google, Microsoft and Yahoo. Just last month Microsoft patched a Web programming bug in its Hotmail service that allowed hackers to break into e-mail accounts. Security vendor Trend Micro said that that flaw was used to steal e-mail messages.
Webmail accounts are often hit with less sophisticated, widespread attacks, too. Scammers like hacked e-mail accounts because they can use them to circumvent spam filters. Even users who do not handle sensitive information routinely find their Webmail accounts broken into and used to promote things such as illegal pharmaceutical websites.
Google has notified the victims of the attack and secured their accounts. The company has also "notified relevant government authorities," it said in its blog post.
- Michaels breach exposes nearly 3M payment cards
- Teen nabbed in Heartbleed attack against Canadian tax site
- Heartbleed bug can expose private server encryption keys
- FTC can sue companies hit with data breaches, court says
- 5-year-old hacks Xbox, now he's a Microsoft 'security researcher'
- State AGs probe Experian subsidiary's data breach
- NSA sniffing prompts Yahoo to encrypt traffic between its data centers
- Banks withdraw data breach claim against Target
- Bank abandons place in class-action suit against Target, Trustwave
- Banks' suit in Target breach a 'wake-up call' for companies hiring PCI auditors
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts