Your email account has been hacked, emails

Many of our users have seen this type of email in their spam filters, most don’t actually get through to your account, although the odd one might. That is all the spammers, who are usually organised crime syndicates, need and rely on.

A full version of the email is at the bottom of this post.

What are these emails and why do some of them have my password in them?

These emails raise many questions and I will try to answer most of them here.

It is of course possible for what they say in the email to be true, but in most cases it is not. There have been many hacked websites over the years and there are now plenty of lists of people’s usernames and passwords, that have been compiled from these hacked websites. There are now two or three main lists that have been compiled and in turn these in to one list of over 500,000,000 usernames and passwords. Security researchers use this list to determine things like frequency of passwords, your chosen password is probably not as unique as you think it is; monkey, password, 123456, abc123 were the top password for many years and although recent research shows that they have moved about, they are still in the top 15.

The bad guys use these username and password lists to try to gain access to your accounts on other wesites and even your email account. Now some bright spark has decided to take your username and password combination where your username is your email address and send an email to you, firstly showing your password to you and secondly faking the sending address, which is trivialy to do, and then tells you that they know something about you that you don’t want revealed to others. This is a typical phishing scam in that they don’t have any access to your email (that is not say that they don’t but they tend to use other scams that are more profitable when they actually have access to your email).

NOTE: If you receive these emails to your inbox, then please contact your hosting provider or website maintenance company or computer support company in order to ensure that your SPF records and spam filtering are setup correctly. Our clients can submit a ticket here anyone else who needs help can submit a support ticket here and we will see if we can help. (WARNING – incorrectly setting up SPF records can cause you to stop receiving legitimate emails and still allow spam through as well as prevent your emails from reaching their destination, it also requires those sending you legitimate emails to have their email system correctly configured with or without SPF records).

Facebook, Vodafone and Dropbox are all examples of large databases of usernames and passwords that have been stolen as well as many smaller companies that have lost control of their databases and not had them properly encrypted. Even those that are encrypted with a basic hash can still be deciphered using rainbow tables. Sites need to hash passwords using individual salts and store the salt in a different database to the username and password database, but that is starting to get technical so I won’t go further in to that.

What is important is that if you, like many people, use the same password on multiple sites then you need to change your password immediately on all sites where the password has been used. You should really consider using a password manager to save individual unique passwords for each site. We could go in-depth in to the various password managers and the pros and cons of each and which ones to avoid completely but that is for another time, for now we will just recommend our own ConnectID which is available with all of our cloud accounts to manage your websites and web apps and auto log you in without you needing to remember your passwords. If you would like more details on this then go here and here or submit a ticket here.

If you have received one of the emails that is warning you that your account has been hacked, then you probably do not have too much to worry about (note that there is some worry as mentioned above). The email suggests that you have had your computer hacked as well and that malicious software has been installed. Whilst this could be true in some cases it is not for most and it is just a phishing exercise to get people to pay up. Email addresses are easy to spoof. These emails can usually be deleted. DO NOT click any of the links in the email as bad things may happen. They can then install a virus which can watch or steal passwords and bank details or do worse things. If you have clicked the link you should take immediate precautions to secure your PC, run antivirus on the highest level or deepest scan and perhaps get in contact with your support company, we can provide remote support, please click here to submit a ticket or here to signup and then call or submit a ticket from your account.

This scam should not be confused with real hijacking of your data, Ransomware is around, just like the radio advert says and they will take your money and not necessarily give you your data back. It costs businesses millions of pounds in lost earnings whilst trying to get things fixed. See our articles on this subject here. It is a very real and serious problem if you get ransomware in to your network. You should ensure you have backups that protect against this, as not all backups will. Backups should be Ransomware proof, like our backup ShareSync, available as a standalone product or with our cloud accounts. As far as we know it is the only one to give this protection as well as the file sharing capabilities of Dropbox or Box, OneDrive or iCloud. If your data is hijacked and you don’t have sufficient backups then you could lose your data completely as has happened to many people and businesses, including a Police station in the USA. The same thing that happened to the NHS in England some months ago which caused operations to be cancelled and days of disruption to the service it provides before it was finally fixed (see BBC news article here).

I digress, but it important to note the difference between ransomware and these opportunistic phishing emails which are trying to scare people into handing over cash. In the last few days they have increased dramatically as others have taken the idea and have now started to send these emails, without the password, to any and all email addresses they have.

The short side of this story is, make sure your email is setup correctly and your spam filtering is doing its job and delete these emails if they get through without opening them and definitely don’t click any link in the email, in fact, never click the link in an email unless you are expecting it and you have made sure it comes from the person you are expecting it from.

Some of these are bound to get through your spam filtering at some point, just delete them.

If your computers are important to you or your business, make sure that you have sufficient backups and your computer and network are checked and maintained regularly by someone trained and experienced in computer and network security.

Below is a couple of examples of the email as it is being sent out:

Hello, my victim.
I know your password – {a password}

That is my last warning.

I write you inasmuch as I set a trojan on the net site with pornography that you have visited.
My spyware grabbed all your own personal information and switched on your web cam which captured the procedure of your masturbation.
Right after that trojan stored your contact list.
I will remove the compromising video and all the information if you pay me 600 USD in bitcoin.
This is wallet address for payment : 1HqUTGvbvDWCSTFDdYtPVviPW2iF8HsNUc
(you can google on “how to buy bitcoin”)

I give you twenty four hours once you view my message to make the payment.
When you see the email I’ll know it right away.
It’s not required to inform me that you have delivered BTC to me. This address is connected to you, my script will erase everything instantly after payment confirmation.
You are able to visit the police but no one can not help you.
In the event that you try to cheat me, I’ll see it straight away!
I don’t live in your country. So no one can not track my place even for 9 months.
Don’t forget about the disgrace. Your life may be ruined.

Another:

Dear user of xxxxxxxxxx.xx.xx!

 

I am a spyware software developer.

Your account has been hacked by me in the summer of 2018.

 

I understand that it is hard to believe, but here is my evidence:

– I sent you this email from your account.

– Password from account xxxxxxxxxx@xxxxxxxxxx.xx.xx: xxxxxx (on moment of hack).

 

The hacking was carried out using a hardware vulnerability through which you went online (Cisco router, vulnerability CVE-2018-0296).

 

I went around the security system in the router, installed an exploit there.

When you went online, my exploit downloaded my malicious code (rootkit) to your device.

This is driver software, I constantly updated it, so your antivirus is silent all time.

 

Since then I have been following you (I can connect to your device via the VNC protocol).

That is, I can see absolutely everything that you do, view and download your files and any data to yourself.

I also have access to the camera on your device, and I periodically take photos and videos with you.

 

At the moment, I have harvested a solid dirt… on you…

I saved all your email and chats from your messangers. I also saved the entire history of the sites you visit.

 

I note that it is useless to change the passwords. My malware update passwords from your accounts every times.

 

I know what you like hard funs (adult sites).

Oh, yes .. I’m know your secret life, which you are hiding from everyone.

Oh my God, what are your like… I saw THIS … Oh, you dirty naughty person … 🙂

 

I took photos and videos of your most passionate funs with adult content, and synchronized them in real time with the image of your camera.

Believe it turned out very high quality!

 

So, to the business!

I’m sure you don’t want to show these files and visiting history to all your contacts.

 

Transfer $847 to my Bitcoin cryptocurrency wallet: 1GXazHVQUdJEtpe62UFozFibPa8ToDoUn3

Just copy and paste the wallet number when transferring.

If you do not know how to do this – ask Google.

 

My system automatically recognizes the translation.

As soon as the specified amount is received, all your data will be destroyed from my server, and the rootkit will be automatically removed from your system.

Do not worry, I really will delete everything, since I am ‘working’ with many people who have fallen into your position.

You will only have to inform your provider about the vulnerabilities in the router so that other hackers will not use it.

 

Since opening this letter you have 48 hours.

If funds not will be received, after the specified time has elapsed, the disk of your device will be formatted, and from my server will automatically send email and sms to all your contacts with compromising material.

 

I advise you to remain prudent and not engage in nonsense (all files on my server).

 

Good luck!

 

There are other variants as well with other messages in them to catch other people out, these are just two examples we hae seen.

Stay Safe.

CritchCorp Computers Ltd.