IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Could Hotmail password theft be due to a trojan?

A researcher says there is evidence that not all of the Gmail and Hotmail account passwords were taken as a result of phishing.

A security researcher has claimed that some of the passwords stolen from Hotmail, Gmail and other webmail services were the result of a data theft trojan rather than a phishing attack.

Originally 10,000 Hotmail passwords were leaked onto the pastebin website, posted by an anonymous user. Later on, Google confirmed Gmail had been targeted as well.

Although Microsoft and Google have both said that the passwords were taken as a result of phishing, ScanSafe security researcher Mary Landesman said there was no way that the companies could have been totally sure of this.

Speaking to IT PRO she said: "No offence to, and I don't mean to undermine either Microsoft and Google, but certainly neither one of them can actually definitively either."

"I think they came out with phishing as the most likely explanation in their minds without having really gone over the lists in great detail," she added.

Landesman said that there were a lot of indicators in the password lists that are consistent with data theft rather than phishing.

"It doesn't mean that 100 per cent of the list was derived from either source [phishing or trojan], more likely a combination of sources," she said.

The researcher said that one tell-tale sign of a possible trojan was that 1,369 of the account records appeared more than once and as some as many as five times.

"Phishing scams do not typically vet the usernames and passwords when they receive them," she said.

"The fact that there actually seems to be failed login attempts is much more indicative of a keylogger or some sort of trojan capture."

She also said on her blog post that previous lists of known phished accounts generally saw some victims left nonsensical messages as they realised that they were being phished, but this list had no such entries.

She said that although '123456' did appear in the list as a password, it still only appeared 63 times out of the 10,000 records, and by and large most of the users had respectable passwords, so were potentially less likely to fall for a phishing scam.

Microsoft and Google had not responded to our request for comment on Landesman's remarks at the time of publication.

Featured Resources

The state of Salesforce: Future of business

Three articles that look forward into the changing state of Salesforce and the future of business

Free Download

The mighty struggle to migrate SAP to the cloud may be over

A simplified and unified approach to delivering Enterprise Transformation in the cloud

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

The Total Economic Impact™ Of IBM FlashSystem

Cost savings and business benefits enabled by FlashSystem

Free Download

Recommended

Google urges Apple to embrace RCS as standard, ditch SMS for Android texts
Mobile

Google urges Apple to embrace RCS as standard, ditch SMS for Android texts

10 Aug 2022
North Korean-linked Gmail spyware 'SHARPEXT' harvesting sensitive email content
Security

North Korean-linked Gmail spyware 'SHARPEXT' harvesting sensitive email content

4 Aug 2022
Google reveals new office in Atlanta and $1 million in funding for local communities
Careers & training

Google reveals new office in Atlanta and $1 million in funding for local communities

28 Jul 2022
Hackers hiding malicious links in top Google search results, researchers warn
malware

Hackers hiding malicious links in top Google search results, researchers warn

21 Jul 2022

Most Popular

Why convenience is the biggest threat to your security
Sponsored

Why convenience is the biggest threat to your security

8 Aug 2022
How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

29 Jul 2022
Microsoft successfully tests emission-free hydrogen fuel cell system for data centres
data centres

Microsoft successfully tests emission-free hydrogen fuel cell system for data centres

29 Jul 2022