A lady friend of mine had a hotmail account that was hacked into this AM EST. I found this out before she did. I received a E mail from her address this AM about her being stuck in a hotel in Nigera, and she can't get out. I E'd her back asking why she sent me this E that it looked like spam mailing I get. I got a reply stating that it was really her that she needs to get out of Nigera...of course asking for money with contact info. She lives in my city, I called her to see what was going on. She didn't know anything about it. She tried to get in her hotmail account, her password didn't work. Aparently the hackers changed her password...and the account is still active in their control. I had her download Zone Alarm Security Suite for protection.

How is it that they hacked in that account? Is there a way to catch them...and or is there a goverment anti-hacking site to send this problem too? What would be the best way to prevent this problem again? The other thing is I'm not sure if this section of the fourm is the proper place to post this problem. I saw the thread on hacking, but I felt this is a time critical issue to get fixed ASAP...that's why I posted. Thanks, Steve

Dani AI

Generated

This looks like a real account takeover rather than simple spoofing. was right that headers can be faked, but the fact the password no longer works (as pointed out) is a strong sign an attacker has control. A quick technical check is to view the full message headers and look at the Received: chain and any SPF/DKIM/Authentication-Results lines — they show whether the message actually originated from the provider’s servers.

Immediate, practical steps to limit damage and recover control:

  1. Locked out: collect copies of the suspicious messages and timestamps (for support or police), warn friends/contacts from a different account not to respond, and run full anti‑malware scans on every device that has ever accessed the account using reputable scanners or a rescue disk.
  2. Regained control: set a brand‑new, long unique password; enable two‑factor authentication; sign out all sessions; remove any unknown mail‑forwarding rules and connected apps; review Sent/Deleted for abuse and inform anyone who may have been targeted.
  3. General hardening: change passwords on any other site that reused the old password, check router DNS/settings for tampering, and monitor financial accounts for unexpected activity.

Longer‑term prevention: use a password manager and unique passphrases, turn on two‑step verification where available, keep OS/browser/antivirus up to date, be cautious about links and credential‑phishing pages, and avoid security questions whose answers are discoverable on social media.

Reporting and follow‑up: report the incident to the email provider’s abuse/security team and preserve evidence; consider filing a report with the appropriate internet‑crime authority (local law enforcement or a national complaint center). Installing ZoneAlarm was a reasonable quick step (), but follow it with full system scans and the account hygiene above — network firewalls help, but credential theft and malware need dedicated cleanup and password recovery.

Recommended Answers

All 3 Replies

It is most likely a spammer forging her email address in the header...... (Does she get alot of spam in that account?)

>It is most likely a spammer forging her email address in the header......

No, it's most likely a hacked hotmail account. When your email password is changed without your knowledge, that's usually a subtle hint that someone else has access to your account. :icon_rolleyes:

If you haven't tried already, use the 'forgot password' link in Hotmail. If they've already changed your security question, contact hotmail support. Give them details, such as your IP address (they can probably check the logs to see if it matches up), when you got the strange emails, your old password, your security question/answer (if you remember it), any other details you can possibly remember about your account you should give them.

oops i didnt see where he said her password was changed (Gotta read better)

Thanx John :)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.