Thousands of hacked Hotmail passwords posted

More than 10,000 user names and passwords for Hotmail and other Microsoft services were anonymously posted over the weekend at a free site for programmers, it was reported Monday, prompting security experts to recommend that users change their passwords.

Microsoft said it was investigating the posting to a coding site called pastebin.com, which hinted at a much bigger password collection: according to tech news site Neowin.net, the account names all started with A or B.

The company said it got the data removed and was “working to help customers regain control of their accounts.” It said the information was compiled as the result of a phishing scheme, in which users are tricked into giving up personal information.

Hacked email accounts have lower value in underground commerce than do banking logins. But they can be useful to criminals as a tool for getting additional access to financial or other sensitive data. Reading old mail can turn up log-in information for corporate accounts, as Twitter learned, and it can lead to social networks.

Compromised social networks accounts, in turn,  are more effective in inducing connected individuals to click on malicious links that install software for stealing all data entered on the peoples’ machines.

It remains unclear why someone would post a password list for free, instead of trying to sell it on an online forum. But compromised credit card numbers are often “dumped” in such a manner, spreading the fraud around and muddying the waters for investigators trying to sort out who first misused a set of accounts.

FT techfeed

Tech Blog

Analysis & reviews

About this blog Blog guide
Richard Waters, Chris Nuttall and April Dembosky in the FT's San Francisco bureau share their views - plus tech insights from Tim Bradshaw and Maija Palmer in London and Robin Kwong in Taipei.



Read about the authors


To comment, please register for free with FT.com and read our policy on submitting comments.

All posts are published in UK time.

Contact the FT Tech Hub team: richard.waters@ft.com, chris.nuttall@ft.com, april.dembosky@ft.com, maija.palmer@ft.com, robin.kwong@ft.com and tim.bradshaw@ft.com.

See the full list of FT blogs.

Archive

« Sep Nov »October 2009
M T W T F S S
 1234
567891011
12131415161718
19202122232425
262728293031  

Tech analysis and reviews

Coding for dummies

Execs learn geek techniques

Time for smartwatches?

Sony synchronises watches with smartphones

Tags

advertising android apple AT&T Electronic Arts Europe Facebook funding google hacking hewlett-packard HP htc instagram intel iPad iphone IPO Jawbone Lenovo London megaupload microsoft Mobile Netflix Nintendo nokia nokia lumia patents privacy samsung smartphones social media social networking Sony SOPA Spotify story of the week Tablets Toshiba twitter venture capital Wikipedia Yahoo Zynga