Google says phishers stole e-mail from US officials, others

A phishing campaign compromised hundreds of accounts with targeted messages

Google has disrupted what it believes to be a targeted phishing campaign aimed at stealing e-mail from government officials, contractors and military personnel.

The criminals behind the campaign have broken into hundreds of Gmail accounts belonging to "U.S. government officials, Chinese political activists, officials in several Asian countries (predominantly South Korea), military personnel and journalists," among others, Google said in a blog post published Wednesday.

The company believes that the accounts were compromised "likely through phishing" by a cybercampaign run out of Jinan, China. That's the city whose Lanxiang Vocational School was linked in a New York Times report last year to the December 2009 attacks on Google's back-end systems. The targets of the 2009 campaign were human rights activists, and activists were also hit by this recent phishing campaign, Google said.

The phishing campaign was first publicly disclosed by the blog Contagio Malware Dump, which reported in February that government personnel and contractors were being hit with what are known as spear-phishing attacks. These attacks use specially crafted e-mail messages, written to appear like they come from someone known to the victim.

Victims were sent spoofed e-mail messages that looked like they came from friends or partner agencies, including targets in the U.S. Department of State, the Office of the Secretary of Defense, and Defense Intelligence, Contagio Malware Dump reported. "The message is crafted to appear like it has an attachment with links like View Download and a name of the supposed attachment. The link leads to a fake Gmail login page for harvesting credentials," Contagio Malware Dump said.

Once they had access to the Gmail accounts, the hackers then forwarded e-mail to their own addresses and harvested the data they found in order to launch future attacks.

Although these spear-phishing attacks didn't affect a lot of users, attacks on Web-based e-mail accounts have become a common problem for companies such as Google, Microsoft and Yahoo. Just last month Microsoft patched a Web programming bug in its Hotmail service that allowed hackers to break into e-mail accounts. Security vendor Trend Micro said that that flaw was used to steal e-mail messages.

Webmail accounts are often hit with less sophisticated, widespread attacks, too. Scammers like hacked e-mail accounts because they can use them to circumvent spam filters. Even users who do not handle sensitive information routinely find their Webmail accounts broken into and used to promote things such as illegal pharmaceutical websites.

Google has notified the victims of the attack and secured their accounts. The company has also "notified relevant government authorities," it said in its blog post.

Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags governmentsecurityinternetGoogleintrusionU.S. Department of DefenseU.S. Department of State

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Robert McMillan

IDG News Service
Show Comments

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?