Phishing attacks over the Hotmail accounts?

Nov 29, 2007 11:29 GMT  ·  By

Although it wasn't confirmed yet, it seems like a sort of attack was launched over several Hotmail accounts as numerous users were asked to reset their passwords. The folks at FaceTime Security Labs wrote that there's no sign of a phishing attack although the affected users were redirected to the Password Reset screen. In addition, it seems like several eBay accounts were affected by the same problem, probably in a move meant to obtain login credentials. There wouldn't be such a major problem to reset your password but the secret question is in Chinese so... what would be the answer?

"Yes, your secret question is now in Chinese...then don't panic, because you're not alone. There seems to be a little outbreak of Hotmail accounts being compromised (likely via Phishing, though we have no evidence of the method used yet), and then from there, EBay accounts are hijacked. Most likely, this is to use those EBay accounts to sell dubious merchandise (or, more likely, pretend to sell merchandise then run away with the profit, leaving you with bad feedback galore)," the blog post on the FaceTime Security Labs reads.

Sure, there's no evidence of a phishing attack but it certainly looks like one. First of all, it redirects the affected users to a password reset screen which requires them to enter the answer to the secret question. As you probably know, this answer could be used for password recovery in case you forget your password or something similar.

Since you're required to enter your private information, the details could be sent to any location in the world and used by the hackers to compromise an account. Just like any phishing attack which attempts to get the potential victims on copies of famous websites and asks them to enter the login credentials. Once the details are entered, they are automatically transferred to the attacker's database and stored for anytime use.