E-Mail may have been compromised, trying to figure out how


Recommended Posts

I am wondering if this happened to anyone else, or they know someone who it happened to. I am trying to figure out if I have been hacked or not, and if so to what extent.

About a month ago my cousin's G-Mail account started sending mass-spam to everyone on his contact list, so he changed his password. It happened twice again though until he added two-step verification. Thing is, he hasen't used his pc in months if not years, he pretty much does everything from his phone and tablet, so it was very unlikely to have been a hack on his PC. I know smartphones aren't immune to viruses, but its not rooted and he hasen't installed anything outside of the Android Market and Amazon Market. His tablet is WebOS so theres practically no chance that one was hacked. And no, hes not stupid enough to fall for phishing or fake e-mail links.

Anyway, this morning this happened to me. Strangely though, none of my g-mail accounts were comprimised, my AOL account (which happens to be my main account) was... This makes even less sense. The e-mails all contained no subject and all the body had was a link to a web domain. However, they were all different domains, which resolved to different IP addresses in different countries and registered in differnet YEARS....... but they all ended with the same HTML page: "mronimer1.html". Googling the domains and html page gave me nothing. (e.g. (no, these are NOT real) www.site1.com.tr/mronimer1.html www.site2.eu/mronimer1.html, www.site3.tr/mronimer1.html, etc). Unless this guy has been registering random domains all over the world for the last 5-10 years and sprung his trap now, or hacked all of these sites and planted this mronimer1.html on all of them, this is just plain confusing to me.

I would chalk this off as my e-mail address being spoofed rather than hacked............. except that these were all sent to people on my contact list (mostly auto-reply bots from various web forums and onlinr stores). So... I guess thats not so much my contact list as its people who have sent me an e-mail at one point.... but anyway. They woulden't have access to this information if it was just a spoof right?

Any ideas how I can track down how I was hacked? Any way I can see how much of my system and passwords were compromised? The problem is although I changed it, I don't REMEMBER my AOL password, and although I have dozens of passwords, I very likely used it on many other sites if they got a hold of it. (Hey, I am literally subscribed to hundreds of websites, forums, etc for the last 15 or so years, I can't possibly come up with a new password for each one and REMEMBER it, many of these were before firefox and keychain-type apps).

not much you can do. perhaps you logged into an unsecure computer at one point, perhaps you have a short and simple password, perhaps you registered somewhere and someone was able to get your email address and other information that could possibly lead to being able to gain access to your email account.

My gmail account was compromised, I was able to quickly change my password prior to being blocked. I logged into a unsecure computer/virus infected computer which is what caused it. No big deal, most of my other accounts don't use the same password and any that did were changed.

  • 2 weeks later...

Sorry that its been a while since I replied.

It almost looks like my address was spoofed, except for the fact that they were sent to addresses on my contact list.

Whats weird though is that all those e-mails that were supposedly sent, none of them appeared in my outbox/sent folder. Is that normal? If they were sent from my account, would they have to appear there, or can they be hidden?

You really need to see the headers of one of the sent messages to see if actually sent from gmail system.

As to spoofing, its quite easy to make an email look like it came from any address at all. Be it [email protected] or [email protected]

You need to look at the headers of the email to know what server the email actually originated from, could be some zombied box in china or Ukraine, etc.

As to access to your contacts - quite possible this was given away freely by you when you signed up for some service. Lots of services being both legit and noso much legit ask for access to your contacts so they can spam them that you are using such a service, etc.

if we could see the headers of such a sent message to one of your contacts that said it came from you, we could clearly see if sent from gmail or not, etc.

How do you know the contacts were just not from some other message that you sent to all users in your list, and they got compromised and the infection on their part just picked a random address from the listing to say its from that address. This is quite common currently.

You normally do not want to actually send from the email address of the account or machine you have control over - it makes it too easy to track down the source. It's better to just pick a random from a list of names that are from a shared contact list or email and say it came from one of those, and just cycle through them as you send out the junk.

How do you know the contacts were just not from some other message that you sent to all users in your list, and they got compromised and the infection on their part just picked a random address from the listing to say its from that address. This is quite common currently.

Because the vast majority of them were sent to addresses which had sent me an e-mail but I never sent one nor added them to my address book (usually "do not reply" type addresses that I am subscribed to or confirming registration on a forum), but they were also sent to everyone on my contact list as well, I rarely send an e-mail to more than at most, two people at once.

Also, this was my AOL account that was infected, not my Gmail account.

AOL account -- really?? People still use that for email?

but again look at the headers and you can see if it came from one of their servers or not. Take 2 seconds to verify.

This occurred to me last year. The only reason i knew about it was because a friend of mine phoned me up after receiving porn spam(other users received it). i also did not login for 6 days. Google showed me the ip address in the logs(it was a thief who was in india) so after i was notified i cleared all cache+history before and after i changed the pass and other info.

+BudMan: he should be careful as even opening the mail could infect him with malware.

Sorry but its not possible to infect yourself by just opening an email -- you have to run code.. Unless your email client auto runs code, who and the F would use such client? Then no there is NO FREAKING WAY to infect your self by reading email in plaintext.. Which is how email was designed to be read in the first place ;)

If you want to know where an email came from -- then you have to look at the actual headers, period.. Any 8 year old that can google can send email "from" any name they wish.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • AnyDesk 9.7.8 by Razvan Serea AnyDesk is a fast remote desktop system and enables users to access their data, images, videos and applications from anywhere and at any time, and also to share it with others. AnyDesk is the first remote desktop software that doesn't require you to think about what you can do. CAD, video editing or simply working comfortably with an office suite for hours are just a few examples. AnyDesk is designed for modern multi-core CPUs. Most of AnyDesk's image processing is done con­currently. This way, AnyDesk can utilize up to 90% of modern CPUs. AnyDesk works across multiple platforms and operating systems: Windows, Linux, Free BSD, Mac OS, iOS and Android. Just 7 megabytes - downloaded in a glimpse, sent via email, or fired up from your USB drive, AnyDesk will turn any desktop into your desktop in se­conds. No administrative privileges or installation needed. AnyDesk 9.7.8 fixes: Fixed a bug that could lead to a crash Download: AnyDesk 9.7.8 | 8.0 MB (Free for private use, paid upgrade available) Links: AnyDesk Home Page | Other platforms | Release History | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • My comment was intended to be humorous. I believe scientists already knew it since they comprehend relatively. Maybe I'm assuming that.
    • Surprise Execs are dumb. I hope the rehired engineers said were not coming back until we get 2x our salary.
    • Ford execs say they made a mistake when they replaced human engineers with AI by David Uzondu Ford recently announced that over the last three years, it's had to rehire about 350 "gray beard" engineers to mentor younger staff and reprogram diagnostic systems and AI tools that were failing to meet up to quality expectations. The company's VP of vehicle hardware engineering, Charles **** said that leaders overlooked the deep experience of veterans who survived many product cycles. **** admitted that simply replacing them with AI was a huge mistake, and that while AI is "a fantastic tool," it remains "only as good as the information you use to train it." The rehired engineers now run mandatory meetings to troubleshoot vehicles and reprogram automated engineering software and AI tools to prevent glitches before production. These technical specialists hunt for failure points before parts ever reach the plant floor, helping prevent the massive recalls and defects that previously cost the company billions as it aims to cut one billion dollars in expenses this year. In last year's JD Power Quality Survey, an annual study that measures the quality of a car during the first three months of ownership, Ford finished 10th among mainstream brands and scored below the industry average. But this year, JD Power ranked the automaker as the top mainstream brand, placing it above the likes of Toyota Motor Corp. and Honda Motor Co. Ford attributed this massive improvement directly to the expertise of these returned engineers. Ford's realization that AI cannot magically design and test quality vehicles without senior human oversight is just the tip of the iceberg. When Careerminds looked at companies that conducted AI-driven layoffs, researchers found out that 35.6% of those companies had to rehire more than half of the employees they previously fired. Another 32.7% had to rehire between 25% and 50% of them. In 2024, Sebastian Siemiatkowski, CEO of Klarna, proudly announced that its new chatbot was doing the work of 700 full-time customer service agents. As a result, the fintech company froze hiring and cut hundreds of positions. But by mid 2025, and into 2026, Klarna was scrambling to recruit human agents again because customer satisfaction had plummeted. It turns out, while AI is very good at answering basic questions like how to check an account balance, when faced with complex customer issues that require nuance, the thing usually resorts to the unhelpful, robotic corporate jargon we all know and love.
    • Free AI in IDEs is shifting to paid models Or you know, you could just learn to actually design and code apps, use frameworks to handle the repetitive parts and not use AI at all - and voila... free for life!
  • Recent Achievements

    • Week One Done
      xvvxcvv earned a badge
      Week One Done
    • One Month Later
      xvvxcvv earned a badge
      One Month Later
    • Enthusiast
      Xonos went up a rank
      Enthusiast
    • Conversation Starter
      Admir earned a badge
      Conversation Starter
    • First Post
      The_Focal_Point earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      405
    2. 2
      +Edouard
      169
    3. 3
      PsYcHoKiLLa
      129
    4. 4
      neufuse
      69
    5. 5
      Xenon
      68
  • Tell a friend

    Love Neowin? Tell a friend!