Google: Phishers stole e-mail from U.S. officials, others
A phishing campaign compromised hundreds of accounts with targeted messages
IDG News Service - Google has disrupted what it believes to be a targeted phishing campaign aimed at stealing e-mail from government officials, contractors and military personnel.
The criminals behind the campaign have broken into hundreds of Gmail accounts belonging to "U.S. government officials, Chinese political activists, officials in several Asian countries (predominantly South Korea), military personnel and journalists," among others, Google said in a blog post published Wednesday.
The company believes that the accounts were compromised "likely through phishing" by a cyber campaign run out of Jinan, China. That's the city whose Lanxiang Vocational School was linked in a New York Times report last year to the December 2009 attacks on Google's back-end systems. The targets of the 2009 campaign were human rights activists, and activists were also hit by this recent phishing campaign, Google said.
The phishing campaign was first publicly disclosed by the blog Contagio Malware Dump, which reported in February that government personnel and contractors were being hit with what are known as spear-phishing attacks. These attacks use specially crafted e-mail messages, written to appear like they come from someone known to the victim.
Victims were sent spoofed e-mail messages that looked like they came from friends or partner agencies, including targets in the U.S. Department of State, the Office of the Secretary of Defense, and Defense Intelligence, Contagio Malware Dump reported. "The message is crafted to appear like it has an attachment with links like View Download and a name of the supposed attachment. The link leads to a fake Gmail login page for harvesting credentials," Contagio Malware Dump said.
Once they had access to the Gmail accounts, the hackers then forwarded e-mail to their own addresses and harvested the data they found in order to launch future attacks.
Although these spear-phishing attacks didn't affect a lot of users, attacks on Web-based e-mail accounts have become a common problem for companies such as Google, Microsoft and Yahoo. Just last month Microsoft patched a Web programming bug in its Hotmail service that allowed hackers to break into e-mail accounts. Security vendor Trend Micro said that that flaw was used to steal e-mail messages.
Webmail accounts are often hit with less sophisticated, widespread attacks, too. Scammers like hacked e-mail accounts because they can use them to circumvent spam filters. Even users who do not handle sensitive information routinely find their Webmail accounts broken into and used to promote things such as illegal pharmaceutical websites.
Google has notified the victims of the attack and secured their accounts. The company has also "notified relevant government authorities," it said in its blog post.
Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com
Data breaches
- Schnucks wants federal court to handle data breach lawsuit
- Microsoft brushes off claim Xbox Live accounts were compromised
- Twitter aims to become safer with two-step sign-in
- Yahoo Japan says 22 million user IDs may have been stolen
- Payment card processors hacked in $45 million fraud
- The Onion explains how its Twitter account was hacked
- Name.com forces customers to reset passwords following security breach
- Systems manager arrested for hacking former employer's network
- Dutch bill would give police hacking powers
- After hack, LivingSocial tells 50M users to reset passwords
- The 20 Best iPhone/iPad Games of 2013 So Far
- 9 Steps to Build Your Personal Brand (and Your Career)
- 7 Consumer Technologies Coming to an Enterprise Near You
- 11 Signs Your IT Project is Doomed
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
Rising salaries boost IT optimism, though not everyone is feeling upbeat. Our survey of 4,000+ IT workers shows who's riding the wave and why. Use our interactive tool and compare your own paycheck. Read more...
