My email account was hacked this morning

12 replies
One of my web based email accounts was hacked this morning. I have no idea how it was done. The hacker attempted to log in to my PayPal account, but did not succeed. They also tried to get a password change with one of my domain registrars, but did not succeed. All passwords have been changed, even on the accounts which were not breached, as a routine precaution.

The incident once again emphasizes the importance of maximizing security on the Internet. I don't claim to be an expert, or anything remotely approaching one, but I will share what I have learned from the incident and hope it helps somebody.

Always use a different password for every account

Think about it. I have no idea how this hacker managed to get in to my web based email account. If they had my password, imagine what might have happened if that password also happened to give them access to my PayPal or hosting account. Make EVERY password different.

If you have Hostgator hosting, use their random password generator to generate passwords for all of your accounts

The Hostgator control panel has a password generator which randomly creates very strong passwords, which you are encouraged to use for all Hostgator email accounts, domains, MySQL databases etc. Do that, but also generate strong random passwords and use them for all of your other accounts as well. You can only have one password for each account, so make it as strong as you can.

Don't leave important emails in web based accounts

It is easy to do, isn't it? Your new hosting company sends you an email with your user name and password. You leave it in your email account so that you can just copy and paste them into your FTP client and C-Panel log in. Think what would have happened to me if I had done that? The email would have been right there for the hacker to read, giving them instant access to my hosting account.

Don't keep any email on file which contains sensitive data of any kind. Always try to keep your email accounts as empty as possible. If you need something, copy it out and then delete the email. All the hacker who breached my account got was a few emails from Yahoo Freecycle telling them who was offering to give unwanted items away, and a couple of emails from railway companies confirming the booking of advance train tickets. To collect these tickets, the hackers would need the booking reference (which they now have), and the card the tickets were booked with (which they do not).

Don't keep large amounts of money in PayPal, or in any bank account linked to it

This is a security precaution for more reasons than one, given PayPal's record of freezing accounts on a whim. Don't necessarily empty a PayPal account completely every time, nor the attached bank account, but make sure that serious money is kept elsewhere. I strongly believe in spreading your money between several accounts, only one of which should have any link to PayPal.

Flash Drive and CD

The easiest way to manage these randomly generated passwords which can never be remembered is to store them in text files on flash drives and CD. The flash drive is what you would use to get in to your accounts - just stick it in the USB socket, open up the appropriate text file, copy the password, and paste it into the input field. You can then use the flash drive in all of the computers you own, and there is no need to store the passwords on the machines themselves.

The CD would just be there as a safety back up. If your flash drive freezes, you don't want to suddenly lose all of your passwords. Just put the CD into the drive, and you've got them back again. Of course, every time you open a new account or change a password, you need to either update or create a text file on the flash drive, and you will need to burn a file to your CD. It should become a routine habit soon enough. Flash drives are so cheap I recommend having one just for passwords and nothing else. You can keep it on your person at all times.

Keep CD back ups hidden

What if a burglar broke into your home, and found a CD next to the computer with "Passwords" written on it? Don't you think they would stick it in the CD drive to see what they could get access to? If you have a large collection of music CDs, you can conceal the CD amongst those easily. You probably get free CDs with your Sunday newspaper every week, many of which you will never listen to. Throw the CD out, and put your passwords CD in the cardboard folder.

Put it somewhere amongst your music CDs. You will certainly remember that you don't like X singer and that his CD is really your passwords, but is a burglar going to go through your entire CD collection in the hope of finding some passwords? Even if the burglar took your entire CD collection away with him, you could still change your passwords immediately and permanently invalidate the contents of the CD.

Security is so important that I really think there should be a section of the Warrior Forum dedicated to it. Anyway, please feel free to add any of your own suggestions to this thread, because this is one case where we definitely are all in this together. We may never be able to eliminate hacking completely, but we need to have more cases of it ending as mine has done, with no serious losses incurred.

Thanks for reading,
Andrew
#account #email #hacked #morning
  • Profile picture of the author tehnolife
    Banned
    Thanks , very important things. The security on the internet is very important right now!
    {{ DiscussionBoard.errors[2467943].message }}
  • Profile picture of the author GerryMedia
    Thanks for the warning.

    Remembering random generated passwords can be daunting so I may also suggest using a password manager like Keepass or Lastpass.

    And yes, I do agree do not send passwords and save website/server login info in Google sites, gmail, Google docs, etc.

    Thanks for the warning and reminder.
    Signature

    I.M. ControlPanel - See why this online software is your key to success!
    Lifetime Membership WSO

    Learn. Take Action. Learn. Teach.
    {{ DiscussionBoard.errors[2467949].message }}
  • Profile picture of the author born2drv
    Damn that sucks, glad nothing was compromised.
    {{ DiscussionBoard.errors[2467958].message }}
  • Profile picture of the author jonat2005
    I will learn from this sad incident and make sure i generate long and a little bit complicated passwords for my logins
    {{ DiscussionBoard.errors[2468066].message }}
  • Profile picture of the author akmanda
    Thanks...i'll more careful since i read this post...
    {{ DiscussionBoard.errors[2468078].message }}
  • Profile picture of the author sbucciarel
    Banned
    The last time a thread like this was posted, I was using the same lame password for all my accounts.

    Since then, I've changed every password and made each one very random ... nonsense words that have no meaning combined with numbers and have a different password for every account.

    Better safe than sorry. I've heard of Godaddy domains being transferred out ... all of them for one account, Paypal funds being drained and on and on.
    {{ DiscussionBoard.errors[2468112].message }}
  • Profile picture of the author tpw
    Remember also not to set your password reminders with publicly available info... Think back to how easy it was for a 15-yo to hack Sarah Palin's email account at Yahoo, because she used personal info as her reminder keys for her Yahoo email password.
    Signature
    Bill Platt, Oklahoma USA, PlattPublishing.com
    Publish Coloring Books for Profit (WSOTD 7-30-2015)
    {{ DiscussionBoard.errors[2468162].message }}
    • Profile picture of the author Heuristic
      One of the biggest threats is keylogger trogens. In fact, most people don't even know they are infected - and not all anti-virus software will pick it up.

      As a precaution, I take things to great lengths when it comes to anything sensitive such as domain passwords, hosting, paypal, and my personal banking passwords.

      I type out all the letters of the alphabet and the numbers from 0-9. I then create complex alpha-numeric combinations and copy/paste each individual character to form a password in Notepad. I save several passwords like this.

      Whenever I log onto something sensitive, I copy/paste the pre-formatted password - quick and slick and no worry about any keylogger trogen sending my vital info back to some criminal.

      Steve
      Signature

      {{ DiscussionBoard.errors[2468417].message }}
      • Profile picture of the author mogulmedia
        Originally Posted by Heuristic View Post

        One of the biggest threats is keylogger trogens. In fact, most people don't even know they are infected - and not all anti-virus software will pick it up.

        As a precaution, I take things to great lengths when it comes to anything sensitive such as domain passwords, hosting, paypal, and my personal banking passwords.

        I type out all the letters of the alphabet and the numbers from 0-9. I then create complex alpha-numeric combinations and copy/paste each individual character to form a password in Notepad. I save several passwords like this.

        Whenever I log onto something sensitive, I copy/paste the pre-formatted password - quick and slick and no worry about any keylogger trogen sending my vital info back to some criminal.

        Steve
        Nice idea dude!
        Signature

        Converting sales copy and professional press releases -> Here <-

        {{ DiscussionBoard.errors[2470083].message }}
  • Profile picture of the author Orator
    Great tips, and a good reminder.

    It's very easy to get sloppy when it comes to passwords.

    I change mine weekly on all my important accounts, and always make sure there are at least two numbers in them. I suppose it might be a bit on the paranoid side, but I consider it an acceptable pain.
    {{ DiscussionBoard.errors[2468424].message }}
    • Profile picture of the author mello
      Timely reminder - thanks. I had some websites hacked at the beginning of the year and in all the business I've been lax on security overall. Off to change my key passwords now. Cheers.
      Signature
      Everything is doable ... if you take action
      Internet Marketing
      PLR
      {{ DiscussionBoard.errors[2470057].message }}
  • Profile picture of the author Dheer
    yeah sorry to hear that but nice tips.
    {{ DiscussionBoard.errors[2470099].message }}

Trending Topics