CHUD.com Community › Forums › DVD, HOME THEATER, & GADGETS › Chewer Tech › Has Anyone Else Been Fucked By Gmail?
New Posts  All Forums:Forum Nav:

Has Anyone Else Been Fucked By Gmail?

post #1 of 26
Thread Starter 
So I wake up this morning to frantic phone calls asking me if I'm okay, alive, and not in Africa.
Apparently, over night my Gmail account was hijacked, and spam was being sent out by someone posing as me, stuck in Nigeria without a passport or anything, and requiring $16,000.
The spam was sent out to everyone in my address book, and since this is Gmail, that's everyone who I've ever emailed or been emailed by.

Phone calls and text messages from friends and family come pouring in, as I realize they've changed my password, and as I use an old Yahoo account from over a year ago to contact those I can, word comes trickling in. The bastard is using the same story over Gchat as well, actually holding conversations with my contacts, explaining yes, it's me, and that they're really in need of help. Some of my friends were smart enough to tell it that they were tracking their IP address, someone who hardly knows me tested it by asking what my birthdate was, to which the reply was "I've lost everything!"
My wife gets called in the middle of her classes by people asking if I'm okay, same with my parents and siblings, I've been fielding calls and texts all day.
A new message was sent out after one of my relatives asked facetiously how I would get to an upcoming family function if I was in Africa. The new message incorporated the details as a plea to get me out of Nigeria in time to make it to the event.

I tried to contact Gmail or Google right away and they have only one form you can fill out if you can't get into your account in a matte like this. I've filled it out 3 times and haven't received a single reply. I called the one number I could find for Google's offices, but it's only for advertising and employment.
Apparently, this has been happening a lot the last few months, and Google has done shit for anyone.
Examples I found:
http://www.notquiteblue.net/rosabelle/?p=68
http://www.notquiteblue.net/rosabelle/?p=66
http://www.seroundtable.com/archives/014377.html

The Gmail boards have a number of threads of people with similar issues, but no one seems to know what to do.

This has fucking gone too far.
As a last ditch attempt (and since I know how much we all love shills and hackers on this site), anyone here know how to help?
post #2 of 26
1) GMail is free, so don't expect rapid response time unless you happen to be paying for their business class service.

2) How bad was your password that a cracking tool bounced it easily? I'm guessing a 5-6 letter English word, no numbers or mixed case? Change that practice immediately.

3) More important to you right now is checking to see if they used any personal information to gain access to your real identity. Hit https://www.annualcreditreport.com and run a free credit report from at least one of the main credit bureaus. Look for anything regarding new credit applications, and start monitoring all of your existing charge/bank accounts.


Also...it now sucks to you be you.
post #3 of 26
Yeah, I would start working with more secure password. Secondly, try to think of any phishing scams you may have mistakenly participated in.

Thirdly, if you are worried about rampant identity theft check out this blog and register an some sort of fraud protection service just in case.
http://dridentity.com/blogs/dr_identity/


And lastly, you might be able to get your old email address black listed by contacting sites such as http://www.spamcop.net/. And inform all your friends that you communicated with using that account. And pray you didn't have any personal information through that account. If you did, start closing accounts.
post #4 of 26
Well, after hearing about this nightmare, I now have a much more secure password.
post #5 of 26
That's generally a good idea. I go a little overboard, but it comes with my job. I use a tool called password safe.

http://passwordsafe.sourceforge.net/

It has a tool to auto generate strong passwords. The problem though, is I need this thing if I want to access any of the websites I frequent because I have unique strong passwords for each website.
post #6 of 26
That's definitely key in the digital world right now. Also key is having a completly different password for every web site you log into. That way, if someone downloads your id from CHUD, they don't also have your Citibank login/password.

To make that easy, download a password tracking program (here's a nice freeware one: http://passwordsafe.sourceforge.net/) You put all of your user names/passwords into one file, and only have to remember the file's password to get access to all of them. Password Safe has a nice click to copy to clipboard option, so you can use outrageously difficult passwords and never have to remember/type them. Just make sure no one ever gets a hold of your password file (i.e.. don't put it up on a web site for global access).

Edit: BillyLove, apparently great minds think alike
post #7 of 26
Great minds and all that...
post #8 of 26
Quote:
Originally Posted by Death Surge
Just make sure no one ever gets a hold of your password file (i.e.. don't put it up on a web site for global access).

Edit: BillyLove, apparently great minds think alike

Probably not a big deal since the file is encrypted with some very good encryption. But, abstain from it just in case.
post #9 of 26
True indeed, but since some guy figured out how to use a PS3 to crack passwords 100 times faster than on a PC, let alone the computational power of a spam bot network, I always recommend erring on the side of caution.
post #10 of 26
Quote:
Originally Posted by billylove
That's generally a good idea. I go a little overboard, but it comes with my job. I use a tool called password safe.

http://passwordsafe.sourceforge.net/

It has a tool to auto generate strong passwords. The problem though, is I need this thing if I want to access any of the websites I frequent because I have unique strong passwords for each website.
Awesome program, will definitely grab that when I'm home.
post #11 of 26
Thread Starter 
The thing that really pisses me off is, I had a combination letter and number password, I always signed in using the https:// site, and check my computer daily for ad/spyware and viruses.

Obviously, whoever did this was a pro.

Apparently this happened recently to a friend of mine, but hers was only hacked so that she was sending/getting spam, and not that they completely conquered her account.
post #12 of 26
I've been contemplating abandoning Gmail -- can't stand the fact that it automatically adds anyone I email to my contact list with no way to turn the feature off. This might be the final nudge.
post #13 of 26
Quote:
Originally Posted by Wadeisdead
The thing that really pisses me off is, I had a combination letter and number password, I always signed in using the https:// site, and check my computer daily for ad/spyware and viruses.

Did you use the same username/password elsewhere? They may have picked it up from the user database of a less secure website, hence the advice to always use different combos at every site. It's also possible that someone is just working a fairly good social engineering game on Google, which makes anyone vulnerable, anywhere.

Crime in cyberspace is at an all time high, and it doesn't look like it's going to be getting any better.
post #14 of 26
Quote:
Originally Posted by Richard Dickson
I've been contemplating abandoning Gmail -- can't stand the fact that it automatically adds anyone I email to my contact list with no way to turn the feature off. This might be the final nudge.
Really? Wow. It never occurred to me to care that it keeps email addresses. If anything, it's handy to find the address of people I don't have listed in my Plaxo (like my mother's half-sister's husband when I have to be her secret santa).
post #15 of 26
Quote:
Originally Posted by Belethedheliel
Really? Wow. It never occurred to me to care that it keeps email addresses. If anything, it's handy to find the address of people I don't have listed in my Plaxo (like my mother's half-sister's husband when I have to be her secret santa).
I was going through my contacts and found all these customer support and online order addresses cluttering up the thing. Sure I can just go through and delete them, but it annoys me that it thinks this is some kind of helpful feature. They say something about it helping with spam filtering, but I don't want commercial sites automatically added so I can get their emails.
post #16 of 26
Quote:
Originally Posted by Richard Dickson
I've been contemplating abandoning Gmail -- can't stand the fact that it automatically adds anyone I email to my contact list with no way to turn the feature off. This might be the final nudge.
They've been slowly adding little add-ons and features (group chat) in the past several weeks, so I'm interested to see what else they add on. Besides, as far as free email services go, I think it's the best one right now.
post #17 of 26
Quote:
Originally Posted by Richard Dickson
I've been contemplating abandoning Gmail -- can't stand the fact that it automatically adds anyone I email to my contact list with no way to turn the feature off. This might be the final nudge.
Yep.

My gmail email address forwards to another email account and deletes the messages. But, it keeps a copy in the deleted folder for 30 days.

So, if anyone hacks that account, they will see my correspondence for the last 30 days.

I too am thinking about deleting the account.




The problem with "free" email services is no direct line of support. Now if you use a paid email account you will hopefully get better support, or have some sort of administrative access so you can go in and remove the account if it's been hacked.

This is the same reason I don't use myspace or those other networking services, because if they are hacked, no one is going to give a damn about it except you.
post #18 of 26
I'm sorry, but this thread reminds me of the new Futurama movie.

"Ha, ha. We took all your stuff."
post #19 of 26
Thread Starter 
Oy.
Last night I watched the Futurama movie at a friend's place, and asked him to pause the movie when the spam/scam aspect kicked into high gear.
I took a deep breath, collected myself, and continued the movie. Despite hitting too close to home, it was an awesome movie, and was better than The Simpsons Movie.

Then today I received an email from google to the other address I had given, saying that I could reclaim my account now, so at least I can get the contacts and such to import to my new email.

Despite it all, I still think GMail is the best free mail available.
Maybe I'm just stupid that way, but I can't think of anyone else I'd rather use until I get my website address running.
post #20 of 26
Quote:
Originally Posted by billylove
My gmail email address forwards to another email account and deletes the messages. But, it keeps a copy in the deleted folder for 30 days.

So, if anyone hacks that account, they will see my correspondence for the last 30 days.
It only keeps stuff in the trash can b/c Google doesn't really enourage deleting anything. They only added any kind of "delete" function after a whole lot of pressure.

Also, you can always just empty the trash can and perm delete it all.
post #21 of 26
It's has become incredibly slow. I'm not alone, it's all over twitter now.
post #22 of 26
It took me a few days to load my work email which is a gmail addy yesterday, but I usually ignore those messages so it's not a big issue for me. I feel sorry for the people who regularly use it though.
post #23 of 26
Anyone?
post #24 of 26
I sent a file to myself via my Droid, but sending from my gmail account to my gmail account, and got it 12 hours later.
post #25 of 26
I just sent an email from my work email (Outlook) to my Gmail address and got it right away.
post #26 of 26
Not having any trouble with my gmail account, and I'm in the process of switching phones right now. Everything is pushing through fine on my laptop, my Blackberry, and my Android phone.
New Posts  All Forums:Forum Nav:
  Return Home
  Back to Forum: Chewer Tech
CHUD.com Community › Forums › DVD, HOME THEATER, & GADGETS › Chewer Tech › Has Anyone Else Been Fucked By Gmail?