One of the simplest methods for hijacking a person’s e-mail address may also be the most dangerous. According to a new security study published by Google on Thursday, so-called manual attacks, made without the use of botnets or other automated tools, can inflict an enormous amount of damage on e-mail users.
Although exceedingly rare in comparison with other kinds of attacks, Google said it sees nine attacks per million users everyday. The company reported it had more than 425 million users in 2012, meaning that thousands of people are victims of manual attacks a day.
Labor Intensive, But Dangerous
As their name suggests, this type of attack is labor intensive. Manual attacks spend a considerable amount of time to gain access to a single user’s account. Once in, a hijacker will spend more than 20 minutes in an account trying to exploit the account for maximum gain, inflicting maximum damage in the process. Often, the attacker will change the password to lock out the owner, then attempt to glean other account details such as access to financial and social media accounts.
One of the most effective ways of hijacking an e-mail account is through phishing tactics, according to Google. A phishing attack involves sending deceptive messages meant to trick users into handing over their username, password, and other personal info. After successfully hijacking one user’s account, an attacker will frequently send phishing e-mails from the victim’s account to contacts in their address book. People in the contact list of hijacked accounts are 36 times more likely to be hijacked themselves.
The Google study found that some fake Web sites created by would-be hijackers worked a 45 percent of the time. On average, people visiting the fake pages submitted their info 14 percent of the time, and even the most obviously fake sites still managed to deceive 3 percent of people. Around 20 percent of hijacked accounts are accessed within 30 minutes of a hacker obtaining the log-in info.
A Full-Time Job
Identifying hijackers who can hide their activity through proxies can be difficult, but the majority of hijackers implementing manual attacks seem to be based in five main countries, according to Google: China, Ivory Coast, Malaysia, Nigeria and South Africa. These types of hackers often approach their work like a full-time job, with regular hours of operation and lunch breaks.
They have also proved resilient, flexible, and quick to respond to counter-measures Google has attempted to enact. Once the company started asking users to verify suspicious activity by confirming their city of residence, hackers began sending phishing e-mails to obtain the correct information almost immediately.
Despite hackers’ ability to adapt to new security measures, Google found that many existing security features can be highly successful in preventing manual attacks. One example is two-factor authentication, a verification procedure in which users have to confirm their identity through a secondary channel, often via an SMS sent to a mobile phone. Google has also recently launched a feature that will allow clients to use a USB stick as an authentication tool.
The problem, according to the company, is that too few users are aware of or implement these tools.
“While phones provide a good user experience, we are exploring alternatives for people who don’t have a smartphone (erg. emerging countries) or want a separated physical device,” Google said in its report. “We hope to see more research done in this space as there is a clear need of innovation in term of usability and accessibility.”
