ie8 fix

40,000+ email addresses and passwords discovered on phishing site

By | November 14, 2011, 8:00pm PST

Summary: Over 40,000 Hotmail and MSN email addresses, along with passwords, have been discovered on a phishing Web site. Read about the incident here.

You know those spam emails that ask you to provide your username/password credentials for your bank, email, Facebook, or otherwise? Well, one user on Reddit decided to take a closer look at the Web site of a link included within one of those emails, and what they ultimately found was a text file filled with ~47,000 email addresses and passwords belonging to Hotmail and MSN users.

Though it’s unclear as to if these were successfully-phished email addresses or email addresses being used solely to send out phishing emails, the individual on Reddit wrote a script in Python to test the validity of the addresses and found that ~85% out of ~2000 were accessible via the passwords accompanying them. Many of those accounts show inbox activity as well, as seen in the sample below:

In the end, the Redditor reported their find to Microsoft (since Hotmail/MSN are Microsoft services). To quote:

Just finished talking to Microsoft. They have the list. The server hosting the files has been down for at least 2 hours, I don’t know if it’ll ever come back. Guys at Microsoft were extremely nice, and it also felt like I had actually done something.

If you’re a Hotmail or MSN user and you suspect you may be a victim of phishing, it wouldn’t hurt to go ahead and change your password. Overall, this is most likely nothing to be alarmed about; however, these types of lists are far more common than readily meets the eye. With a little bit of advanced Google search querying, it’s fairly easy to dig up these lists residing in wide-open directories on phishing Web sites.

Last of note, if you’re curious to see if an email/username of yours has been discovered within any type of list like this that’s gone public, check out pwnedlist.com. They’re a reputable site that currently houses almost 5 MILLION email addresses and usernames in their database that you can check for (assuming you trust they won’t store your email address once you enter it to search for). Needless to say, if an email address or username of yours is confirmed there, you might want to change all associated passwords for that email address/username.

-Stephen Chapman

Related Content:

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Stephen is a freelance writer based in Charlotte, NC.

Disclosure

Stephen Chapman

Stephen Chapman is a freelance writer and content strategist. All work that Stephen does for ZDNet is on a contractual basis.

It is left to Stephen's discretion whether or not to accept assignments from prospective clients who discover him through ZDNet. Such endeavors have no association with ZDNet and, unless otherwise agreed upon, are kept separate and private in the interest of all parties involved. You may freely contact him for consulting, training, and/or public speaking inquiries.

While Stephen may accept complimentary passes, waived fees, payment, and/or covered travel costs to industry-related events (conferences, expos, etc.) as an attendee or a speaker, acceptance of such offers is not considered payment for, or exclusive guarantee of, any particular blog coverage of the event attended.

Biography

Stephen Chapman

Stephen is a freelance writer based in Charlotte, NC.

The discussion hasn’t started yet. Why don’t you begin it?

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix