Close Menu
    Facebook X (Twitter) Instagram
    Trending
    • 5 Active Malware Campaigns in Early 2025: What You Need to Know
    • 10 Critical Network Pentest Findings IT Teams Overlook
    • Report Phishing Instantly with PhishAlarm
    • Password Reuse Epidemic: Nearly Half of User Logins Compromised
    • Women in Cybersecurity: Interest, Exposure, or Just Stereotypes??
    • Stay Ahead of Scammers in 2025
    • Cybersecurity Alert: Risks of Abandoned Websites
    • DHS Unveils Playbook for the Deployment of Artificial Intelligence for the Public Sector
    Fordham University Information Security and Assurance
    • Information Security and Assurance Homepage
    • Privacy Blog
    • About
    Fordham University Information Security and Assurance
    You are at:Home»Security Awareness»Article: Three Telltale Signs a Hacker Has Been in Your Account
    Security Awareness

    Article: Three Telltale Signs a Hacker Has Been in Your Account

    By Gerald Johnson Jr.July 27, 20176 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Copy Link

    Via: Imperva.com

    “Imperva’s latest Hacker Intelligence Initiative (HII)report, Beyond Takeover – Stories from a Hacked Account, was just released. With this research, we set forth to learn about the dynamics of phishing attacks from the victim’s perspective and shed some light on attacker practices. Our intent was to learn how accounts are taken over once credentials are compromised through a phishing campaign.

    To achieve this, we maintained 90 personal online accounts (“honey accounts”) over nine months in platforms that are well-known phishing targets. We invited attackers in by leaking the credentials of these accounts to selected phishing campaigns and traced their activity.

    One of the more interesting areas of the research was uncovering which practices attackers used to cover their tracks, destroy evidence of their presence and activities in the account, and evade detection. In this post, we’ll share attacker techniques, how they cover their tracks, and three signs that indicate your account has been hacked.

    Phishing: A Glance at Attacker Practices

    What Do Attackers Look For?

    After leaving the front door open, it was interesting to watch what happened in the house once a burglar got in. We spread decoys as breadcrumbs to lure attackers into our traps and we saw many take the bait. We collected and analyzed alerts to reach the (not too surprising) conclusion that attackers first and foremost are looking for sensitive information, such as passwords and credit cards numbers.

    Phishing decoys - types by percentage - 1

    Figure 1: Distribution of accessed decoy data types

    Manual Labor or Automatic?

    We were curious to know if the attackers worked manually or used automated tools. To answer this, we checked timing of triggered tokens. We noticed that attackers approached tokenized items selectively rather than sequentially, e.g., only part of tokens were approached and not in any visible order. The time intervals between approaches were very different and ranged from a few seconds to over 10 minutes. Moreover, we saw that 74% of the first decoys were accessed within three minutes of account penetration, which indicates that attackers access the content online manually and do not download and examine it with automated tools. These observations together indicate that exploration of the accounts was primarily done manually.

    How Attackers Cover Their Tracks (But Not All Do!)

    Attackers can leave tracks behind during the attack process, such as generating suspicious new-device login alerts or spam messages in the sent items folder. Erasing evidence of a compromise is mandatory for an attacker who wants to remain obscure, continue using/exploring the account and avoid a trace back. We observed three different techniques attackers use to cover their tracks:

    • Delete sign-in alerts from the inbox (and permanently delete them from deleted items/trash)
    • Delete sent emails and failure notification messages
    • Mark read messages as unread

    Our research also showed that not all attackers take equal care in covering their tracks. We were surprised to find that only 17% made any attempt to cover their tracks. And those who did sparingly used track covering practices (see Figure 2):

    Percentage of track cover and track cover practices - 2

    Figure 2: Percentage of track covering and track covering practices

    Attackers’ oversight in covering up their tracks is key to identifying if an account has been hacked.

    The Telltale Signs

    Since not all attackers cover up their tracks, that means many leave evidence behind. This allows users to be aware that a hack has taken place if they’re looking for the right things in the right places. Here are three telltale signs that an attacker has been in your account.

    Telltale Sign #1: Suspicious Sign-In Email Alerts

    Following a hacker’s penetration into an account, a lot of visible hints are likely to remain which can be seen by a simple search for suspicious sign-in alert emails in the inbox.

    In only 15% of the account penetrations, we saw that new sign-in alert emails were deleted from the inbox (see Figure 2). Even then, they were usually forgotten and left in the trash folder—only 2% of the attackers deleted a new sign-in alert permanently. Users should be on the lookout for suspicious sign-in email alerts in their inbox and periodically scan deleted items or trash folders for them as well (see Figure 3).

    undeleted sign-in alert found in Gmail trash - 3

    Figure 3: New sign-in alert found in Gmail trash, not deleted by a hacker

    Telltale Sign #2: Messages Marked as Read (That You Didn’t Read)

    Another technique we saw was attackers marking email messages as unread after opening them to bring the mailbox back to its original condition. Following is an example from a Yandex email log (Figure 4). Yandex is an email provider and search engine used in Russia, the Ukraine, Belarus, Kazakhstan and Turkey (their search engine has about a 65% market share in Russia). It’s used as an example here as other mail providers (such as Gmail, Yahoo and Microsoft Hotmail/Outlook) don’t contain activity logs for read/unread messages. This type of strange read/unread email activity indicates a hacker has been in the account.

    email messages marked as unread 4

    Figure 4: Examples in a Yandex activity log of a perpetrator marking email messages as unread after opening them.

    Telltale Sign #3: Sent Items (You Didn’t Send) and Delivery Failure Notification Messages

    Thirteen percent of attackers deleted emails they sent from compromised accounts (such as those sent to launch a new phishing campaign) as well as the failure notification messages, which inform the sender about the inability to deliver a message. These emails are typical when using the account for spamming purposes when the email provider identifies the spamming attempt and blocks the burst of spam emails. Of course, if 13% deleted sent items and failure notifications, then the vast majority—87%—did not and left evidence behind that they hacked the account.

    Protecting Accounts

    Despite the various actions attackers used for covering their tracks, many of them left considerable traces in the hacked accounts, showing that in some ways hackers are no different than their victims. Users can be lax when it comes to security awareness and get themselves in trouble by not being more attentive of their actions. Hackers can be sloppy too—their lack of attention can alert a victim that their account has been compromised.

    If an account has been compromised, the first course of action should be to change the password. Two-factor authentication remains the tool of choice for protecting accounts from takeover, or at least a recovery email or phone number to be immediately alerted to alternative accounts/devices about possible threats to the account’s security. However, being watchful for attack hints like suspicious items in the sent items or trash folders, suspicious sign-in messages and messages marked as read which users don’t remember reading, can lead to early detection of account takeover and give the victim the opportunity to take back control of their account.”

    Source: https://www.imperva.com/blog/2017/07/three-telltale-signs-a-hacker-has-been-in-your-account/

    Share this:

    • Click to share on X (Opens in new window) X
    • Click to share on Facebook (Opens in new window) Facebook
    • Click to share on LinkedIn (Opens in new window) LinkedIn

    Like this:

    Like Loading...
    Previous Article“Wire Transfer” Scam Email Sent to the Fordham Community on July 5, 2017
    Next Article Suspicious Email with Subject “Scanned image from MX-2600N” Sent to the Fordham Community on 7/31/17 –

    Related Posts

    5 Active Malware Campaigns in Early 2025: What You Need to Know

    10 Critical Network Pentest Findings IT Teams Overlook

    Report Phishing Instantly with PhishAlarm

    Follow Us on Twitter!
    Follow @FordhamSecureIT
    My Tweets
    Archives
    Categories
    • AI (1)
    • Alerts (384)
    • CISO (19)
    • Cyber Security Awareness Month Tip (150)
    • Data Privacy Week (2)
    • Executive Director (1)
    • Exploits and Vulnerabilities (35)
    • General Information (34)
    • Identity and Access Management (12)
    • Identity Theft (26)
    • Jason Benedict (19)
    • Legitimate Email (14)
    • Malicious Email (24)
    • Mobile (25)
    • Network Security (2)
    • News and Events (143)
    • Newsletter (13)
    • Password (17)
    • Phishing (333)
    • Phishing Email (340)
    • Privacy (10)
    • Ransomware (9)
    • Scam (104)
    • Security Awareness (262)
    • Security Guides (34)
    • Social Engineering (12)
    • SPAM (40)
    • Suspicious (6)
    • Telework (2)
    • Teleworking (3)
    • Trojan (7)
    • Uncategorized (9)
    • Virtual Meeting (4)
    • Virus (28)
    • Viruses (8)
    • World Backup Day (1)
    • Zoom (6)
    Tag Cloud
    Alerts Artificial Intelligence Backups cell phones CISO Cybersecurity Awareness Month Tip Cybersecurity Month Data Privacy Device email Exploits and Vulnerabilities fordham fraud Identity and Access Management Identity Theft Information Security Guides Jason Benedict Legitimate Email malicious email Mobile Multi-Factor Authentication networks Network Security News and Events Newsletter online safety Online Shopping Password Phishing Phishing Email Privacy ransomware scam scams Security Awareness social engineering Social Media spam trojan Virus Viruses Wireless wire transfer scam World Backup Day zoom
    About
    About

    Founded in 1841, Fordham is the Jesuit University of New York, offering exceptional education distinguished by the Jesuit tradition to more than 15,100 students in its four undergraduate colleges and its six graduate and professional schools.

    Copyright © Fordham University
    Facebook X (Twitter) Instagram YouTube LinkedIn
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    %d