hotmail hacked

If your friends and contacts have received an email or IM message from your Hotmail account with wording along the lines of “I would like to introduce a good company who trades mainly in electronic products… etc” – it is highly likely that your Hotmail account has been compromised.

IF YOU ARE THE POOR SOUL THIS HAPPENED TO, THEN YOU SHOULD READ ON AND FOLLOW THE INSTRUCTIONS AT THE BOTTOM OF THIS ARTICLE.

In most cases when a spam email is sent in your name to someone else, the spammer doesn’t need access to your account. All they need to do is spoof your email address – i.e. make it look like it was sent from you. That’s very simple to do, and is very common.

However, the latest spate of spam from Hotmail accounts is different in that the attackers actually hack into your Hotmail account and then do some or all of the following things:

  • They send a spam email to all your contacts.
  • They may send a spam IM message to all your Messenger contacts
  • They may delete all your Hotmail contacts
  • They may set your autoresponse (the one you set when you go away) to send this spam message
  • They may set your email signature to include the spam message

You know that they have hacked into the account because you can see clearly that they have sent an email from it to all your contacts, or even an instant message. They would not be able to do this if they did not have access to the account.

HOW IT HAPPENS
I don’t have a definitive answer, but I do have a theory which, based on the evidence, looks likely. If your password is a common name or a word that appears in a dictionary, then your account is vulnerable, even if it has a year of birth or number attached to it.

This is how the hackers do it:

  • They employ an automated script that is fed your Hotmail address and then goes to work./li>
  • It feeds the entire dictionary and common passwords and names into Hotmail one by one, trying to log in.
  • After several attempts Hotmail “locks” the account and present a CAPTHCA (i.e. a string of wonky letters and numbers that are supposed to stop scripts from doing exactly that, because only a human can read these letters, supposedly).
  • Unfortunately the CAPTCHA method no longer stops scripts, because hackers have found ways around them. One of those ways works by using sophisticated character recognition software that can read the wonky letters. Another is to feed the letters to “CAPTHCA farms” – the letters are fed to human users, employed by the hackers to read and enter CAPTCHAS, and they are often paid by the number of CAPTCHAs they enter (for example 1 cent per entry). This becomes viable financially if the spam is part of a bigger scam. The scale of the deception means it makes more money, especially because people are much more likely to trust spam messages sent by their friends. This achieves greater returns for the hackers and means they can attack many accounts, bypassing email security systems.
  • Sometimes the scripts do their work over days, and sometimes weeks, to escape being caught by Hotmail’s attack detection systems.

There are of course other ways for hackers to achieve this kind of attack, such as spyware on your computer, or you being deceived by a rogue website. My instructions below would help you tackle these as well.

WHAT SHOULD I DO IF MY HOTMAIL ACCOUNT GOT HACKED?
Go through the following steps, one by one:

1. Before you do anything else, change your Hotmail account password to something very safe. Not a dictionary word or name, or even a word and numbers. Use symbols such as $ and & in your password, and make it long. I know it is difficult to remember, but if you don’t want to be hacked, you’ll have to start using strong passwords.

2. Now check that your autoresponse and email signature on Hotmail do not have any spam text added to them, as this would go out to your contacts automatically.

3. Then check that your computer does not have spyware or viruses, by following the instructions here.

4. From now on keep your passwords safe, and be extra careful when using public computers (such as those in Internet cafes). If in doubt – change your passwords.

5. You may want to alert Hotmail support to the problem. It seems to be happening all over the place, and the more they know about it, the better it is for their efforts to address it.

And please note: if for some strange foolish reason you decide to go to the site advertised by the spammers, and you are even more foolish and decide to buy something on it, don’t be surprised if it never arrives. This is a well known scam, and you will never get your goods, you muppet.

Technorati Tags: , , , , , ,

Tagged with:
 

430 Responses to What to do if your Hotmail account got hacked – the recent spate of attacks on Hotmail accounts

  1. Sam says:

    Ive been hacked by the group Anonymous and they have sent all sorts of things to my gf!! how do you get all this to stop???

  2. tavi says:

    it’s very nice to tell me to change my password
    however the hacker has changed my password so i cannot get in

  3. Frank Gennaro says:

    I have commented many times on this website about Hotmail. Get rid of your Hotmail account as they seem to be very easy to hijack. Get a Gmail account, choose a 100 character password that you do NOT have to remember (let’s see a hijacker guess that password) and choose a 100 character answer to a secret question that makes absolutely no sense to anyone but you. Then get a LastPass.com account, and finally get a YubiKey, and NO ONE will ever hijack your Gmail account by guessing your password or secret question answer! By the way, the last time I checked, Hotmail allows a max of about 20 characters for a password. However, I believe that hijackers get into Hotmail accounts EITHER because a user chose a secret answer that is easy to guess OR M$ internal security is suspect OR a PC you use is infected with malware. In any case, you are fully protected with a YubiKey and LastPass account.
    How does all of this work??? Simple, the only password you need to know is your LastPass.com password, and they will log you into your new Gmail account using your Gmail 100 character password that you could NEVER remember.
    So what is so secure about LastPass.com and why is it almost impossible for someone to hijack it to gain access to your Gmail account or personal information like bank account information??? Because the hijacker would have to know your password and also have your YubiKey that plugs into any PC. That YubiKey is unique to you! But doesn’t LastPass.com store my passwords and other personal information??? Yes but only as encrypted data! That encrypted data is encrypted on the PC you are currently using BEFORE it is sent to LastPass.com.

  4. Car says:

    My account was hacked several months ago & hotmail support didnt do anything to help me. The hacker changed my password & also my secret answer so theres no way of retreiving your account back. HOTMAIL SUCKS!

  5. Rebecca Copping says:

    My message is very much the same as “CAR” writer.

    Hacker changed my password and I cannot let contacts in my address book know that is is hacked.

  6. B says:

    Mine must have been hacked because it sent an email to all my contacts. Luckily I have very few contacts and it didn’t change my password so I can still get in. The thing is, my password was very strong. It was a word in a completely different language, had capital letters, and included numbers. I’m not sure how they could’ve got into my account. I did tell all my contacts to not open the email or sweep their computer if they did, so hopefully every thing is all right.

  7. thomas brandis says:

    my hotmail account was hijacked and then hotmail advised me that my hotmail account is blocked and the only way to unblock it was to recieve a text message with a new code that would allow me to get at my account…..i dont have texting on my cell phone….what else can i do????

  8. thomas brandis says:

    my hotmail account was hijacked and then hotmail blocked me out saying they would text me a code to reopen it….i dont do texting so how else can i cure the problem?????

  9. SOCIALBUTTERFLY says:

    Hacked wass even the word for it. Send a message out requesting $1,000.00 becuuse I was in the UK, being treated for cancer and they needed the money IMMEDIATELY. AS HOLES IS WHAT THEY R. NO ONE BELIEVE IT WAS ME. HOOE YOU ARE ABLE TO SEE THIS MESSAGE, THAT WAS SENT OUT.

  10. zain says:

    My account was hacked hotmail support didnt do anything to help me. The hacker changed my password & also my secret answer so theres no way of retreiving your account back.

  11. Ryan says:

    They’re telling me to change my password but I can’t access my account to do that shit, so they said they’d send an email to the account that I can’t open?! WTF?!! BTW obviously that email address doesn’t work anymore.

  12. Gavski says:

    My account has been blocked due to unauthorized activity – I’ve followed the instructions but sadly in order to activate my account they need to send me a code to my other email – this sadly is also hotmail and has been blocked – i can not seem to find away round it – can anyone please help. I’m not the greatest on PC’s but I’m very careful so this is very frustrating to me

  13. ahmed abdul aziz says:

    plz help me . my hotmail account have been blocked due to hacking last wendnesday , i work as doctor and i have very important mails and contacts there.

    i dont know how to contact custormer service of microsoft..i changed my password alot but they didnt respond to me

    send me on

    thanks

  14. UniqueThrows4Less says:

    Guys- you CAN get your hotmail accounts back! Just contact Hotmail, and prove who you are (Name of email folders you had. Last sent email (likely to be), Last received email…how many folders you had- anything that will prove that it is YOUR account. I had this happen and I contacted them at
    https://account.live.com/password/reset

    I got an auto message that I responded to and within a day I got a reply with an email requesting additional info only I would know. I was in my account immediately, as soon as they confirmed it was my account. don’t give up! Change that password as soon as you’re in. I haven’t had any problems since.

  15. Frank says:

    Do NOT waste your time contacting M$. No matter what anyone says, most of you will NOT recover your hotmail account. Even with my credit card number and also as member of the Microsoft Development Subcription Network (costs ME several thousand dollars annually to be a member), I STILL CANNOT GET MY HIJACKED hotmail account back! Dump hotmail and get gmail where you can enter a far more complicated password of up to 100 character if you so desire. I firmly believe M$ has some security flaw that allows others to hijack their accounts. M$ has been issuing security updates for their operating systems for years, BUT NEVER ONCE HAVE I EVER HEARD ABOUT SECURITY UPDATES FOR HOTMAIL!!!

  16. UniqueThrows4Less says:

    I’m sorry to hear there’s so many problems. I didn’t run into any–if for some reason you can’t access your alternate email (i.e. hacker changed it so you can’t get in), go to the Windows Live Recovery

    https://security.live.com/acsr.aspx

    You will be asked for your personal info to identify you to your account- it’s another way around the alternate email, because most people either don’t have that old email or the hacker slyly made it his own

    Best to you guys. I sure hope this gets resolved for you. I know switching to another email account is not convenient, and it doesn’t get your personal info back, so give this a try. i hope it helps

  17. Fergie says:

    Trying to speak to a real person at Microsoft is a complete waste of time you phone numbers and they tell you to go to a website and that is not even available.
    There help is non existant

  18. RGR says:

    They verified me as the user and I did all the steps but STILL my Hotmail is blocked. It’s fine and good to get another account, but I really would like to get some info out of this one first if at all possible. Maybe if tech support wasn’t in the same countries where a lot of this is BEING DONE, maybe it wouldn’t be such a mess! I am ANGRY to say the least.

  19. mr ng says:

    hey can anyone tell me what to do to recoever my msn and email if anyone know can u plz tell me thanks really got urgent thing over there

  20. shamy says:

    sum girl haz hacked my account and i want my hotmail to get blocked so no one can use it

  21. kurmat says:

    Hotmail, Gmail and Yahoo! let you set up an alternate email address. You can get a reset password sent to this address. That will let you take back your main address.

    Hotmail, Gmail and Yahoo! also let you add a cellphone number to your account as well. This can be used to verify and take back your account. However, you need to set this up before the account is hacked.

  22. Mark Salisbury says:

    Have tried to get into my account for 4 days with no success! I am angry, your “change your password” does not work, goes nowhere. I need to get into that account. I was verified as the user of my old account but still can’t get in. Your recovery process is awful!!

  23. Pam Knapp says:

    Yesterday on June 28, 2011 I was foolish and gave out just enough info (not my password) to a hacker e-mail about windows Live deleting my Hotmail account. This hacker has changed my password so that I can no longer access my e-mail account. This person has been sending spam e-mails to many of my contacts. I have tried to change my password (but you have to have your old password in order to change)–so that was a no go. I was unsuccessful when I tried to reset my password and also to recover my e-mail account. Hotmail did not do anything to try and help me with this situation. I worked on it for many hours today, June 29, 2011. It is still not resolved and I am very disgusted with the whole fiasco! Like others who have written comments, I don’t think I will ever be able to recover my e-mail account and be able to transfer info to a new e-mail account. How ridiculous is this?!?!!!!

  24. sam says:

    As like everone else my old hotmail account dissapeared
    of the face of the planet, totally gone. My new Live
    account was hacked within twenty minutes, and my second one within several hours. Infact, although the hacker now
    owns it, I’m actually using its username to send this correspondence. Truth is, because it was new, there wasnt
    really anything of worth in it. However,as the old sayng goes ….. be careful what you wish for …. because spammers and hackers can also be spammed and hacked. If
    you get my meaning…..

  25. s cormie says:

    Wish i would have known this before I got blocked. Is there any way to retreive my contacts and warn them? I still can get into my email with my blackberry

  26. Sandra Melville says:

    Yup, I just joined this group on July 4th! Son phoned and told me about his scam email. I tried to change my password, verify myself etc. NO GOOD! The acct has been blocked. MSN free acct, = NO CUSTOMER SERVICE!!
    I can’t access my msn at all! I asked for a phone number, which doesn’t exist. The last message from them, after almost a week was ‘there will be no more communication unless you can be verified’. I can’t get to the account verification page or ANYTHING. VERY FRUSTRATED!! I had this acct since the late 90′s. F&*^%K!

  27. Swole says:

    Wtf I can’t log into my hotmail… Its saying my password is wrong… Fukin nerdy little fukn pussys hacked my email.. Lucky I can’t trace and find out where it was hacked from ide fuk the him up!!! Lost all da pics from when I was little.. Pretty fucked up

  28. kurmat says:

    http://www.telegraph.co.uk/technology/microsoft/8640230/Hotmail-users-to-be-forced-to-change-123456-passwords.html also mentions new feature to report other hijacked accounts.

  29. Frank says:

    M$ hotmail has a problem: Hijacked accounts. The easiest way to prevent a hotmail account from being hijacked to to STOP using hotmail! There is power in numbers: Get rid of you hotmail account! Ever since my wife’s hotmail account was hikacked, and she had a complicated password, I have been able to get many of my friends to drop their hotmail accounts.

  30. h4cked says:

    just got hacked too. The spammer sends to my contacts a http link that ends in test.php?html44 on my behalf.
    To hackers do something better than annoying people. Get a life out of your screen.

  31. kurmat says:

    https://security.live.com/acsr.aspx goes through steps to recover your hotmail account. See also Kim Komando’s hints at http://www.komando.com/tips/index.aspx?id=11153&utm_medium=nl&utm_source=totd&utm_content=2011-08-01-article-1&utm_campaign=end-b&page=1

  32. helen says:

    i got hacked as well

  33. akii says:

    even my account got hacked.. since i’v joined hacking classes i’v cum to knw dat it’s been hacked.. cuz my url shows his email-id n nt mine 1nce i sign in.. so wat do i do nw/? jus keep a long password!? dat’s it? i tried tracing him.. bt i can’t see dat chut’s OS! they’r good.. so m improvising on it.. i traced him dwn to nigeria.. it goes frm newyork to a few places n ends thr.. so wat can i do? his ip’s still alive….

  34. tasmia says:

    mannn damn shit”!!!email account got hacked by the hacker so i could nat get in what can i do···············

  35. Mayaaa says:

    The main thing to do, is NOT PANIC!! It’s not a big deal. Also, after you’ve received that message, you HAVE to go to your history and delete any possible pages that might have to do with hotmail. Then you will be able to visit the hotmail homepage and create an account where you need to put any data you can recover that was in your email. then make sure to write all the information that you can get into that email in a safe place. Also, you need to remember, (I don’t mean to sound like a pessimist, I’m just warning people) no matter how strong your password is, if people know your email THEY CAN HACK IN EASILY. you need to have a backup plan.

  36. shannon says:

    Just got hacked too. I can’t believe that there are people with so little else going on in their lives that they get a kick out of doing this. I hope the laws soon catch up with technology and make it a FELONY to hack into and mess with someone else’s email account!

  37. don brewin says:

    My hotmail account was hacked into. Like others I have been trying Microsoft but they will not help. The online service now says I have tried to access too many times!
    Any good ideas of non-microsoft honest means to find the new password?

  38. Nancy says:

    HACKED! I did try to reset my password, but, I figured if they got it the first time then they would get it again. I just opened a new account under a different name. Hopefully my friends will resend me their information.

  39. laurie says:

    So my e-mail account just got hacked. I’m told that hotmail is the worst. I have changed my password and will change my e-mail and most like change email service. This is crappy! This took hours out of my day to address and there is no site on hotmail or MSN that is available to respond.

  40. kurmat says:

    LIVE.COM is part of MSN.
    https://security.live.com/acsr.aspx goes through steps to recover your hotmail account. See also Kim Komando’s hints at http://www.komando.com/tips/index.aspx?id=11153&utm_medium=nl&utm_source=totd&utm_content=2011-08-01-article-1&utm_campaign=end-b&page=1

  41. Hannah says:

    Please help! I can’t change my password or answer my secret question and I’ve been hacked! When I try to change it it just sends the E-mail to the account that’ been hacked! The hacker already sent an offensive message to my friend! Please tell me what to do.

  42. Amy says:

    Hello there- just to say thank you very much for this wonderfully informative article! My account was ‘compromised’ rather than fully hacked and I’ve followed your advice and randomly generated a gobbledeegook 15-character password that includes symbols so hopefully I’m safe(r) now. I can’t seem to find out how to contact hotmail about this so I’ve given up trying.
    Anyway- the main purpose of this message was a big fat thank you! Not only do I feel like I’ve (hopefully) resolved the issue but I also understand why.
    Thank you!!

  43. Parmvir says:

    Someone hacked my hotmail account what do I do ? And the person sent a message to my 2 best friends please help me!!

  44. TrevorOT says:

    Sounds like I have the same situation ans a few others a hacker got in and sent al email saying I quote as follows:

    http://goo.gl/MrGZd – this URL has been disabled.
    Note that goo.gl short URLs may be disabled for spam, security or legal reasons.

    Suggestions:
    Return to the previous page.
    Try searching to find what you’re looking for.
    © 2011 Google Help Report Spam Privacy Policy Terms of Service Google Home

    Most of my friends could ot pen this and like most of you I did as imstructed by Hotmail in changing my password. THey immediateley blocked my access to my account and I cannot get through to them to re open it Nothing works not even the verification and I completed this at least a dozen times and still nothing.
    Short of opening a new account can anyone advise me what to do. I have been using incredimail to access my Hotmail account and all was well until a couple od days ago.
    Can anyone help me please.

  45. tauqeer says:

    plz reset my acount
    plxxxxxxxxx
    plxxxxxxxxxx
    problem hai plzzzzz

  46. was hacked too says:

    https://security.live.com/acsr.aspx does not work as hacker collects all new info as soon as you type it in so save urself the headache and save all ur important info to a second place.

  47. hotmail-hater says:

    Well get this, 5 years ago i followed the procedures of closing/deleting my hotmail account – confirmed account was closed/deleted….. past 5 years some tidley pork chop mo fo bandit selling iPhones emails me from the deleted account!! Which hotmail confirmed they deleted……. Their so call help via their maze style website has you going round in circles & being non the wiser on what to do and how to resolve things – HOTMAIL are as good as an idiot telling depressed patient who’s just had both legs amputated to the groin – oh did you know runnings good for depression?! Fancy it????

  48. Hotmail-Who says:

    My advise to you ALL is to delete your Hotmail Account NOW along with all your contacts – OH SORRY YOU CANT CAUSE YOU’RE ACCOUNTS BEEN HACKED!!!! Seriously get yourself you own domain its £4!! I pay £20 per annum for domain & hosting plan which is basically an email account. that’s what hotmail is …. you get what you pay for guys! $0…….zero support, zero resolution, and zero email as hotmail account’s been hacked…… mmmmmmm now did I mention the the lack of support?

  49. Hacked......off Hotmail says:

    i’m hacked off hotmail accounts been hacked after I closed/deleted account 5 years ago – they deleted my last comment I submitted – told a good joke too! I’m still hacked off with hotmail – hot being the key work – stolen goods!!!!

  50. Hacked-off says:

    HELP IS HERE!………….. forget hotmail they’re jokers!!!

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Please leave these two fields as-is:
Set your Twitter account name in your settings to use the TwitterBar Section.