Hacked Gmail Accounts Hawking Viagra

The first reports trickled in about a week ago, but the level of spam seems to have increased in the last couple of days. We contacted Google, and the company urged anyone who believes their account has been compromised to immediately change their password, and follow the security tips here. A spokesperson for the company also wanted to make clear that the hack is in no way related to the recent revelation that Google's unified log-in system, Gaia, had been compromised.
Details are slim, but we do know that the spam messages are reportedly being sent via Gmail's mobile site, leading some to suspect there may be a bug in the product. Google told us that its investigation had not revealed any vulnerabilities in Gmail (either the mobile or full desktop versions), and speculated that it might be simpler for an automated bot to be programed to use the mobile version.
It's likely that the log-in credentials for these accounts were harvested using traditional phishing techniques or malware, hardly a Gmail-specific issue. As usual, much of this problem probably could have been avoided with good browsing habits. [From: SFGate]





The List #0147: Escape a Car Underwater
Visit the Maldive Islands Before It's Too Late
H&M's Plus-Size Model Jennie Runk Says She Chose To Gain Weight
Okla. Sheriff's Deputy Finds Dog Guarding Body Buried Under Destroyed Home
Reptiles Make Home in UK Man's Cable Box
Springtime Budget-Busters -- Savings Experiment
Is This Woman Too Pretty To Work?
Mariah Carey Suffers Wardrobe Malfunction on Good Morning America
Parents Face Tough Choice When Tornadoes Bear Down
The Story Behind Hairspray















Comments
20
Subscribe to commentsLuddyApr 23rd 2010 2:42AM
HAH! Just one week ago? it happened to me about a month ago, to two of my accounts. They were hawking viagra, as well as sending tons of emails to craigslist. And if that wasn't enough I was locked me out of facebook and my world of warcraft account.
And I didn't log in with my credentials except for secure servers and my phone. 18 years of safe browsing under my belt so don't say otherwise.
ChadApr 23rd 2010 7:50PM
As an internet professional I can say with absolute certainty that I was not phished and that I don't have any malware. However, yesterday my gmail was hacked. I'm pretty sure google has an issue and is being less than forthcoming about it.
Thomas HoustonApr 23rd 2010 8:02PM
@Chad did you lose access to the account? We've heard of other reports of gmail being hacked lately.
thomApr 23rd 2010 11:28PM
This just happened to me, and I did absolutely nothing. Somebody logged into my account from a Mobile phone connection. How irritating.
jimApr 24th 2010 3:57PM
This happened to me a couple of weeks ago too. It ran through a bunch of my contacts in about 2 minutes time. It hasn't happened since. I scanned immediately after and have yet to find any malware.
SarahMay 1st 2010 2:24AM
Mine was hacked this morning and was sending out links to Canadian pharmaceuticals. I doubt the theory that this is strictly a mobile problem because the account that was hacked has never been accessed on my handset.
NickMay 8th 2010 7:30PM
Wow! I thought it was only an isolated incident, but looks like a lot of accounts had been compromised too. The same is true for my account which sent out a spam mail to a certain mailing list. Hope this will be sort out quickly.
jtpeterson219May 10th 2010 12:35PM
I was hacked today while I was on my account. I accidentally logged out, then logged back on, and it wouldnt let me because of "suspicious activity". It had me put in my phone number, and then gmail texted me a passkey so i could get back into my account, and then it had me change my own password. I went to my inbox and i saw an unopened email. It was a failed delivery notice of an email I sent to my bro in law with a link in it to a site selling ED drugs. So i guess gmail was able to stop anything from happening. But that phone number system doesnt seem very secure to me. Anyone that tried to log into my account during that time frame could have changed the password, and I wouldnt have been able to do anything about it.
Arunvasu1986May 12th 2010 11:40PM
Hai my google account has been hacked please help me
DanielleMay 22nd 2010 11:31PM
I've also been hacked in the last 24 hrs. According to the Gmail Activity Report, it was from a mobile connection in Indonesia. Extremely miffed to see all the out of office replies from those that received the spam messages, the annoying spam in my sent messages, and error messages from failed deliveries.
Quite annoying -- my blackberry is now having trouble fetching the Gmail messages and a listserv moderator is upset with me. Ugh! Will be much more diligent with my passwords updates and security measures.
ChrisMay 23rd 2010 1:26AM
Just got hit by this on an old gmail account that hasn't been used (no sent mail) since 2005. One of the contacts on the old account was my new gmail account and I noticed a spam message hawking something in a foreign language.
I use Ubuntu primarily and I seriously doubt this is malware related as I haven't logged into that account in literally *years*. I logged into the account after getting the spam and noticed the last logins were a few days ago (twice) from Poland on a mobile connection.
My pop was apparently also enabled and I have no idea if my emails from college were downloaded or not. Quite disconcerting.
I have since completely removed that account from Google through their product deletion page.
I don't think this is phishing activity or malware related. Some gmail related service or large google/non-google database has been compromised.
StephanieMay 26th 2010 8:03AM
Mine was hacked this morning as well. Tried to log in to check email and it said my account had been temporarily disabled due to violation of Terms of Service. Did the mobile phone verification (couldn't anyone just do this?), logged back in, and changed password. I noticed a spam email sent to an old contact that didn't go through and access from a weird IP. I never check my email by phone, so I think there's some larger compromise going on here...
goodspellerJun 10th 2010 11:10AM
mineses got hacked two
BaileyJun 14th 2010 9:33AM
Mine was hacked sometime between last night and this morning.
I was woken up by a text message from my email account with a website I've never visited.
I did a quick check to make sure no other web accounts were compromised. Was going to check my banking password before I realized it was quite possible I had someone watching me.
I went to the website text messaged to me after I warned my friends and family and it was some sort of medical/cardiology website, very sparse. I looked in my spam and I had apparently sent MYSELF Viagra and other ED related messages. I'm doing an anti-virus check to see what pops up, but I'm relieved I'm not the only one to have this happen to and that it might be segregated to gmail.
While I'm upset that gmail couldn't stop this from happening. People make mistakes and I'd much rather it be gmail's problem than my computer's.
loridarlin.alwaysJun 17th 2010 9:20AM
My gmail was hacked yesterday!! My sis-in-law called me to find out why i was sending Viagra advertisements!! It also sent to many other contacts!! Is this a problem only with gmail or others? I can't afford to use an email account that is not secure!!
MPJun 22nd 2010 12:36AM
I just created a gmail account because today my yahoo account was compromised and a spam email with a link was sent out to my entire address book. I'm very angry and embarrassed, but I'm also dismayed to see that this seems to be both a Yahoo and a Google problem. It doesn't make me feel very secure. I've spent most of the day today reading up on this issue, running scans (all have come up clean and I run all scans regularly anyway), added a 4th spyware program to my machine (also clean), changed all my passwords to something different from one another and made them 15 characters long. I deleted all my contacts after I had printed them out (have I gone back to the dinosaur era?) and created another yahoo account. And after all that, I still don't feel safe.
cwcookJun 24th 2010 5:17PM
Gmail just disabled my account due to suspicious activity from China. Sure enough someone from China sent emails to several of my contacts from my gmail account hawking an electronic products site named www.jopshop.com. I got about 10 Delivery Status Notification Failure messages. Who knows how many messages got sent under my name before it was caught. I have now changed my password but I hope Google, with all its resources, can prosecute the Chinese perpetrators.
JeffJul 4th 2010 2:52AM
This same thing happened to my girlfriend a month ago, and just now to me. I've worked in IT a long time, and can't for the life of me figure out how this could have happened. Mine appears to have been hacked from this address in Spain:
213.60.5.140
gbJul 6th 2010 9:53AM
Just happened to me last night, someone was sending spam from my account through Cambodia.
I was sent a verification number via mobile SMS, and was able to regain control over my gmail account.
I trace the even to several days ago when I put an add on Craigslist. Unfortunately, I had opted to have the add respond to my own gmail address instead of through Craigslist routing process. Makes me wary of using Craigslist in the future.
DeborahJul 12th 2010 4:48PM
My gmail was hacked on July 9th. A bogus email was sent to 600 people in both my gmail account and my outlook account. The email stated I was stranded in London and to send money. I received a gmail alert that my account was being accessed from Nigeria. Is gmail safe to use??