CFO Expectations of IT


Follow us





Gmail accounts hacked by drug-dealing spammers

Hackers break into Gmail accounts to flog Viagra

Google is investigating a growing number of reports that hackers are breaking into legitimate Gmail accounts and then using them to send spam messages.

The problem started about a week ago but seems to have escalated over the past few days.

"The Gmail team takes security very seriously and is investigating the reports we've seen in our user forums over the past few days," Google said on Tuesday. "We encourage users who suspect their accounts have been compromised to immediately change their passwords and to follow the advice at the following page: http://www.google.com/help/security/."

Gmail accounts are often compromised after phishing attempts or via malicious programs, which can seek out and log online credentials from a hacked computer.

It isn't clear what's behind this wave of Gmail compromises. But in forum posts, Gmail users note that the hackers appear to be sending spam via Gmail's mobile interface - which gives mobile-phone users a way to check their Gmail accounts - and wonder if there may be a bug in the mobile interface that is allowing criminals to send the spam.

Most of the victims are reporting that their accounts were accessed via the mobile interface when the spam was sent. They are reporting any security problems on their machines. Gmail users can check to see how their accounts were accessed at a given time by clicking on a "Details" button at the bottom of the Gmail page.

Google says there's no Gmail bug. "Our investigation has not given any indication of a bug in Gmail, either in the mobile interface or otherwise," the company said. "Spammers may sometimes use a mobile interface to access accounts they have already compromised because it's simpler for bots to use this method at large scale."

The New York Times reported on Monday that Google's centralised login system, code-named Gaia, was compromised by hackers in late December. But this seems unrelated to the Gmail problem because of the different nature of the two incidents - the December attack was a sophisticated attempt to steal data and intellectual property from Google; the Gmail spam is hardly sophisticated. It's being used to flog Canadian pharmaceutical websites that promise to send cheap drugs to US customers.

Antispam vendor Cloudmark noticed an upsurge in Gmail-based pharmaceutical spam just a few days ago, according to Jamie Tomasello, the company's abuse operations manager. "We really saw this activity pick up on Friday and Saturday," she said.

Cassandra Robertson walked into a Gmail spam mess on Monday morning. "I noticed I had all these returned messages from people who were vaguely irate that I had sent them something that appeared to be spam," she said.

About 250 of her Gmail contacts received messages that contained a link to a website called Canadian Health&Care Mall, which offers Viagra for just $1.85 per pill.

That was embarrassing, said Robertson, a project manager with a Portland, Oregon, engineering firm. "I sent out that email to everybody in my address book, which included people I had sent résumés to when I was job searching," she said.

"A lot of people were very savvy and said 'you've been hacked,' but some said, 'Why are you shilling for Viagra?'"

She has no idea how her account was compromised, but the spam was sent via a mobile connection from Serbia, she said.



Email Updates

CIO Newsletters: Expert insight, advice and tools for technology, business, leadership and the CIO career.


Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

The cloud 2015 vision

Cloud computing is an important transition and a paradigm shift in IT services delivery - one that promises large gains in efficiency and flexibility at a time when demands on data centers are growing exponentially. The tools, building blocks, solutions, and best practices for cloud computing are evolving and challenges to deploying cloud solutions need to be considered.

The consumerisation of technology

iPads are the must-have fad. Android is the rising mobile platform -- Everywhere you turn, the news is about personal, smart, mobile devices and their impact on business and on IT.

Big data analytics

Broadly, there are two ways to think of Big Data technologies. The first is as an extension of what many organisations are already doing with business analytics. Gaining insight from business information is something that has been happening for decades, but the challenges and opportunities are now greater than ever before.

Virtualisation: benefits, challenges and solutions

The majority of organisations have already implemented server virtualisation and most intend to implement additional server virtualisation during the next year. The primary factors driving the movement to deploy server virtualisation are cost savings and the ability to dynamically provision and move VMs among physical servers. There are however, a number of significant challenges associated with server virtualisation.


CIO UK - Business - Technology - Leadership

On Demand Webcast
Analyse Data In Real Time


Increasingly businesses require the ability to analyse information quickly. Find out how to handle growing data volumes more efficiently while reducing the cost of managing your organisation's IT landscape

Watch now

SAP Logo

What do CFOs expect from IT?


Watch our sister publication's latest webcast.
Hear a case study from the Guardian News and Media's Technology Director, Andy Beale, and join the discussion on the role of the CFO in technology innovation.

Watch Discussion

CFO World webcast in assocation with Google

On Demand Webcast:
Maximising business flexibility with virtualisation


Register for this on demand webcast and find out how technologies can enable cost effective and secure virtualisation from your server deployments.



Watch now

Dell VMware logo


CFO Expectations of IT


* *