Could Hotmail password theft be due to a trojan?

A researcher says there is evidence that not all of the Gmail and Hotmail account passwords were taken as a result of phishing.

A security researcher has claimed that some of the passwords stolen from Hotmail, Gmail and other webmail services were the result of a data theft trojan rather than a phishing attack.

Originally 10,000 Hotmail passwords were leaked onto the pastebin website, posted by an anonymous user. Later on, Google confirmed Gmail had been targeted as well.

Although Microsoft and Google have both said that the passwords were taken as a result of phishing, ScanSafe security researcher Mary Landesman said there was no way that the companies could have been totally sure of this.

Speaking to IT PRO she said: "No offence to, and I don't mean to undermine either Microsoft and Google, but certainly neither one of them can actually definitively either."

"I think they came out with phishing as the most likely explanation in their minds without having really gone over the lists in great detail," she added.

Landesman said that there were a lot of indicators in the password lists that are consistent with data theft rather than phishing.

"It doesn't mean that 100 per cent of the list was derived from either source [phishing or trojan], more likely a combination of sources," she said.

The researcher said that one tell-tale sign of a possible trojan was that 1,369 of the account records appeared more than once and as some as many as five times.

"Phishing scams do not typically vet the usernames and passwords when they receive them," she said.

"The fact that there actually seems to be failed login attempts is much more indicative of a keylogger or some sort of trojan capture."

She also said on her blog post that previous lists of known phished accounts generally saw some victims left nonsensical messages as they realised that they were being phished, but this list had no such entries.

She said that although '123456' did appear in the list as a password, it still only appeared 63 times out of the 10,000 records, and by and large most of the users had respectable passwords, so were potentially less likely to fall for a phishing scam.

Microsoft and Google had not responded to our request for comment on Landesman's remarks at the time of publication.

Featured Resources

The definitive guide to warehouse efficiency

Get your free guide to creating efficiencies in the warehouse

Free download

The total economic impact™ of Datto

Cost savings and business benefits of using Datto Integrated Solutions

Download now

Three-step guide to modern customer experience

Support the critical role CX plays in your business

Free download

Ransomware report

The global state of the channel

Download now

Recommended

Google’s Grace Hopper subsea cable lands in Cornwall
Infrastructure

Google’s Grace Hopper subsea cable lands in Cornwall

15 Sep 2021
South Korea fines Google for abusing Android dominance
Policy & legislation

South Korea fines Google for abusing Android dominance

14 Sep 2021
Google handed user data to Hong Kong authorities despite pledge
privacy

Google handed user data to Hong Kong authorities despite pledge

13 Sep 2021
Google and Microsoft's hybrid work battle shows the narrative is just as important as the technology
collaboration

Google and Microsoft's hybrid work battle shows the narrative is just as important as the technology

9 Sep 2021

Most Popular

What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

8 Sep 2021
The technology powering the future of shopping
Technology

The technology powering the future of shopping

16 Sep 2021
Citrix mulling potential sale after tumultuous 2021
mergers and acquisitions

Citrix mulling potential sale after tumultuous 2021

15 Sep 2021