Hotmail, Gmail or Yahoo email user?

If you have most of your email transactions going through a hotmail, gmail (google mail) or Yahoo email account then you need to read this!

Many of the organisations I work with use their domain name as the primary email account. Some use their Broadband Service Provider’s domain name, and some others use Hotmail, Gmail and Yahoo.

Whatever you use, have a backup email account. Here is what has happened to one organisation I have been helping this month. As a result of this they have lost their primary email address for at least a month.

Help I am stuck in Ukraine!

I received a message like the one below, I have seen these before, I have removed the email address in this case.

How are you,

Sorry for any inconvenience, I’m in a terrible situation. Am stranded here in Ukraine since last night. I was hurt and robbed on my way to the hotel I stayed and my luggage is still in custody of the hotel management pending when I make payment on outstanding bills I owe. Am waiting for my colleagues to send me money to get back home but they have not responded and my return flight will be leaving soon. Please let me know if you can help and I will refund the money back to you as soon as I get back home.

Please let me know if you can help.

Kind Regards
<name removed>

This message was received from a legitimate email account, and one that I built a website for over 2 years ago. The source was their hotmail.com account.

I speculated that there are several things that may have happened here, one is a trojan virus has been loaded onto someone’s computer, the address book has been copied and sent to some third party, and they are now mailing this person’s contact list in the hope that someone might bite.

The formatting of the complete message included a formatted footer from the organisation as well. So the message was possibly sent from the hotmail account.

I contacted the organisation and advised them that I had received the message and that they should check their systems for viruses/ trojans. I also advised them to change the password on the hotmail account.

Two hours later I received a phone call from the manager of the organisation, things were actually worse than I had assumed. They never received my email.

Hackers attack email accounts too

Someone had hacked into their hotmail email account. They had changed the password for it, we may also speculate that they had also sent this message to everyone in the address book associated with the account.

A local IT person had been into the office to see if they could resolve the problem. Their recommendation was to contact me, and take out a replacement email address using the domain name (same domain as their website) rather than hotmail.

This is a solution to the problem but one that only works over time; however this leaves a gap, which is not easy to resolve in the short term.

  • All of their current and past conversations have been via xxxx@hotmail.com
  • They are locked out of hotmail and cannot get back in. While they can escalate this to Microsoft, there is a one month period where they cannot use this email account assuming that they could get it back.
  • If they were not using outlook to retrieve mail (and have local copies of email), and were only using hotmail.com (webmail) to access their account, then they have also lost their address book and their old mail.
  • For any organisation this will be a massive headache and could stop an organisation from functioning.
  • If this master email account is also used with other services then it is conceivable that the hacker could access the website and other areas of the organisations business.  This is because the hotmail address would be used to recover passwords for other accounts that used this address as the primary contact email address.

What can be done?

I had another case with someone on a personal hotmail account, the password was changed, forgotten, and then a one month grace period was allowed to elapse before the account could be accessed again. I don’t think there is a way around it.

In this particular case, all mail routed from the website is actually routed via an email account associated with the domain. However it may just be a forwarder to the hotmail account. If it is a real email account, then at least mail from the website will be caught there. They can start using that email address, and if requested I can amend their site to inform people that the primary email account has changed on the home page.

The manager of this organisation will need to go back through records and establish where the hotmail email address has been used as a primary email contact account and change them all.

Antivirus software will need to be run on all of the machines in the office to establish whether something was capturing passwords from the computer, and this is how someone accessed the account, or whether it is was simply hacked online.

Bolting the stable door after the horse has gone

Of course all of these things are after the fact. It will create a great deal of problems for this organisation before things settle down again. However the first and foremost problem is regaining some level of control, and keeping a clear head, and not panicking.

Some things to think about for your organisation

1). Always use a strong password. I cannot tell you how many times I come across passwords like Maisy123 or John21. Use passwords that contain letters (upper and lower case), numbers and symbols. Yes you have too many passwords, but sadly it is the only way to manage this. Ensure they are more than 8 characters long, preferably longer.

2). Don’t have a master password for websites. Tempting as that maybe. Personally I have different passwords for everything, they are located in different places. That way if one is compromised, everything else isn’t.

3). Keep them secure, for example on an iPhone/ mobile device which also requires a password. Some password managers will allow three attempts at accessing the account and if they are all wrong, then the password file will be deleted. (Just in case you lose your phone).

For Gmail, and possibly for Hotmail and Yahoo as well there are additional security mechanisms available which will limit who can access the account and from where. Use them. They are there to protect you. They come in the form of Two factor logins. This means that something like a mobile phone is also required to access your account.

For example, if I log into my gmail account from a device or computer that I have not used before, then I have to provide some additional information. In this case Google sends me a text message to a registered phone. I enter the text they send to me into the website and this confirms I am who I say I am.  There are a number of themes like this, they are there to protect you from this type of problem.

Finally consider the following: You do not pay anything to use Gmail, Yahoo or Hotmail. If you don’t pay anything to use them, why should you expect a service when a problem occurs? If your BT email account was compromised, there will be someone you can talk to, to help you to regain control. That is not the case with these free email services. 99% of the service is automated. It is good, but only if you put the protection in place before a problem occurs like this one.

Looking broadly at communications

My recommendations for any organisation is to have at least two email accounts in use for communications. One, the primary one, should be based on your domain name. (xxx@mydomain.org.uk). This is held in an area where you ultimately have control. so if it is compromised you can reset it through your control panel. This is not the case with hotmail, gmail or yahoo. You do not have that level of control on those free email accounts.

Secondly have at least one external email account. Maybe through your service provider (xxxxx@btconnect.com) however do not use this as a primary method of communication as it is tied to your service provider, and if you move you lose it.  You can also consider using Yahoo, Gmail or Hotmail, these services are great provided you use them with tough passwords, and turn on the various other security mechanisms available to stop a third party accessing your account.

Don’t forget to run your anti-virus/ security

I cannot over-emphasise the importance of running a good quality anti-virus/ security application on your computer. I personally use eset smart security and have done so for around 18yrs. Symantec, McAfee also provide market leading products. Do be very careful with anything that is free!

It takes a considerable investment to research and maintain a database for viruses and other malware. Ask yourself how is it being paid for if your AV package is a free one?

Make no mistake…..

I get literally a hundred messages a day from the websites I have built (and this is just the tip of the iceberg), the majority of these inform me of failed logins to WordPress websites, they originate from all around the world, mostly China, Brazil, Russia and Eastern Europe. There is a whole parallel universe out there with people that are trying to hack into email accounts, websites; anywhere where there is a user name and password required. It is going on all of the time 24/7. Don’t get caught out just because you are unaware that it is happening.

Leave a Reply

Your email address will not be published. Required fields are marked *

Wingrove-Services
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

You can adjust all of your cookie settings by navigating the tabs on the left hand side.

My privacy policy can be located here: Wingrove Media Privacy Policy (opens in a new window)

My Cookies Policy can be found here: Wingrove Media Cookies Policy (opens in a new window)