Hi
My hotmail (outlook.com) account experienced an intrusion by a spoofed e-mail which was deemed by Outlook support to have "Softfailed" Outlook's
Fraud detecion tests. I have some unanswered questions about this incident:
1) I have already taken action by doing virus and spyware scans and changing my password. I have also, just for extra protection, started accessing the account in question from a different computer, in case there was persistent malware infecting the computer
I mainly used before. Do you think these are sufficient protection measures I have taken?
2) If I think I know the person who was responsible because there was a clue in the e-mail or I was able to track the third party IP address, what could I do about the compromise? Was it an illegal action? Can Outlook or Microsoft do anything about it for
me? Is it a police matter? I think I know who was responsible. I think this was a targeted attack rather than a random one. What should I do now?
3) Is the e-mail itself still a danger? I have left it in my inbox in case of investigation. Is that OK, or should I forward it to another e-mail client and delete it from Outlook?
4) Since the spoof e-mail was sent from an alien IP address, is it possible that the spoofing of my e-mail address was done without direct access to or compromising my Outlook account, or is the only way to spoof an Outlook account to have internal access
to and control of that account?
5) Please precisely define a "Softfail". Does it mean the text in the body of the e-mail
was allowed through with an appended warning, but active links or attachments were disabled? Or does it just mean that the e-mail was allowed through exactly with active links and attachments, just as the sender intended but only with an attached warning
that it had not passed Outlook's fraud detection tests?
6) I understand the default Softfail SPF setting in Outlook can be changed to Hardfail, by Registry Editing, to give better protection against future attacks. Can I do this? If so, how do I do it?
7) If Outlook has reset my account and I have changed the password and am using a different computer to access my account, could the spoofer still have access to my account or would they have to attempt a further attack on my account to try and access it?
8) Is there any quick, simple method of exporting all e-mails (sent and received), all attachments to e-mails and all contacts from one Outlook account and importing them into a separate Outlook account.
Thank you, in advance.
Rgds
SDBB_869
Recent Comments