Hot mail accounts being hacked

This story is doing the rounds at the moment. No doubt youll cover it in the next risky biz. I would like to add my 2 cents.
I use hotmail rarely, only to keep my real email address secret. In any case I might log in once every week or two. I only ever log in from three machines. My work laptop, a home laptop and a home desktop. All have proper AV installed and firewalls and the rest, just as it should be.
Last Sunday I received an email from my hotmail account to my ISP account. Now as I know I had not sent the email, alarm bells went off. I logged into my hotmail account to check and everybody in my contact list had been sent an email advertising cheap iphones.
I quickly changed my email password and a few other passwords from the laptop which I regard as most secure, and then proceeded to scan all my pc’s that I had used to access the hotmail account.
Nothing. All AV update, all fully patched, no viruses, no nothing out of order. Now if anybody else was to tell me this story I would just assume they’d been compromised and whatever. But I’m not your average man in the street when it comes to IT security. I cannot see how they got this information from me.
And then this story breaks, like lots and lots of email account being compromised in the same way. The latest report says it can’t be a phishing scam as the number of accounts being compromised is too high. The reports are now blaming key loggers. But this doesn’t sound right either. I mean if you had a key logger that was this hard to detect and this prevalent, would you use it to send spam from hotmail?
Anyway, you can discount the whole thing cause you don’t know me and I probably got compromised downloading a program to make my computer faster and whatever. I’m just saying that based on my personal experience, something’s up here.
User login
Recent podcasts
-
"Mostly pointless" research yields interesting results...
-
All your patchings are belong to big vendors...
-
An interview with IT lawyer Erhan Karabardak...
-
Has much changed in 10 years?
-
When can the feds demand your encryption keys?
Recent comments
- There's a lot of stuff out
1 day 2 hours ago - Very cool, I really liked it.
1 day 5 hours ago - not broken
1 week 7 hours ago - I didn't think of that
1 week 2 days ago - Not dead, but definitely delayed...
1 week 2 days ago - Its all about the $$$$
1 week 3 days ago - I think it's worth noting
2 weeks 1 day ago - It can't snowball as further
2 weeks 2 days ago - AFP podcast
2 weeks 2 days ago - Hey pat;
The latest podcasts
2 weeks 6 days ago

Because I'm travelling through Europe...
No doubt by the time I'm back in .au there'll be a bit more known about precisely what's happened. One thing that's interesting is it's getting play on all the USA/EU cable news networks. That sort of initial news cycle prominence tends to lead to good follow up reporting.
But thanks for letting us know -- it's certainly worth a look when I get home.