The link above this is to a report on Mashable that one day after 10,000+ hotmail accounts had their usernames and passwords posted on-line due to a phishing scheme, today the same problem has hit GMail, Yahoo, AOL, Earthlink and Comcast accounts bringing the total number of compromised accounts to over 30,000. Google has already taken steps to correct this by forcing password resets on all affected accounts. All are advised to check their accounts.

Dani AI

Generated

Good call, — that October 2009 credential‑harvest was a large, multi‑provider phishing incident that resulted in thousands of webmail logins being posted online; providers moved to block affected accounts and require password resets while investigators traced the harvesting to phishing kits. (theguardian.com)

Why it spread so fast: attackers used realistic fake login pages and collected credentials that many people reused elsewhere. Analysis of the exposed lists at the time showed a high proportion of trivially weak passwords, which makes credential reuse especially dangerous because one stolen pair can unlock many services. (wired.com)

Practical steps (applies whether you were affected in 2009 or are cleaning up after any later credential leak):

  • Change the email password from a secure, clean device and stop reusing that password elsewhere.
  • Enable strong second‑factor protection (2‑Step Verification / passkeys) and prefer phishing‑resistant methods (security keys or passkeys) where possible. ()
  • Check account recovery settings, active sessions/devices, and mail‑forwarding rules; revoke any unfamiliar app access or authorized devices.
  • Use a reputable password manager to generate and store unique passwords. Official guidelines on authentication lifecycle support unique credentials and modern authenticators. (pages.nist.gov)
  • Check whether your address appears in known breaches (for example, Have I Been Pwned) and assume any exposed password should be treated as compromised. Scan your devices for malware if you entered credentials on a suspicious page. (haveibeenpwned.com)

Replying to and the forum question about provider responsiveness: companies did act (blocking and forcing resets), but recovery depends on whether users changed reused passwords and enabled extra protections — the long‑term fix is not reactive resets but unique credentials plus phishing‑resistant 2FA/passkeys. (allthingsd.com)

For historic context and further reading, consult the contemporaneous coverage and the linked practical guides above.

Recommended Answers

All 2 Replies

Thanks for this important advisory notice. This is also a very real remainder to all to constantly change their login information. This is surely a real threat to our online identities.

Thanks for this important advisory notice. This is also a very real remainder to all to constantly change their login information. This is surely a real threat to our online identities.

I would be interested to know if this affected anyone in this forum and if so how proactive the app it affected you in was in correcting the issue.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.