I had a Macbook Air that runs OSX version 10.6.8. The computer was stolen
last week and unfortunately I didn’t have iCloud or another app that I could
use to track it. Interestingly, my email was hacked a few days later. Although
my username was saved on my browser, my password was not. All the people in my
address book received an email from me with no subject and only one line link
in the body. I already read your article, “Why am I getting or sending an email
that only contains spam from my contacts?” and I’ve been following your
suggested steps. I changed my password and my password recovery settings and I
checked my other Gmail settings like forwarding, signature and so forth.
However, I believe my case is somewhat unique because I don’t have my original
computer anymore so I can’t follow other suggested steps such as installing a
firewall or checking for viruses. If there’s a relationship between my computer
being stolen and my email being hacked, I’d like to know what all I can do to
protect my account in the future.
In this excerpt from
Answercast #94 I look at the repercussions of having your computer stolen –
one of which is easy access to your email.
]]>
<
This does appear to be too much coincidence to dismiss. But, how much overlap can there be between these extremely disparate classes of criminals: the thief of opportunity at some local coffee shop or library, and the link spammer? And, how much cooperation would there be between the two? I can’t help but doubt that some ruffian who snatched an unattended computer would have any incentive to use an email access for spam purposes.
On the other hand, I *would* change all those online banking and paypal passwords. If I had a stolen computer and a mind to exploit it, those are the websites I would be checking out, not email services.
On your stolen PC the spammer can easily see your address book, and your mail address. So he simply spoofs the “From” field; which is easy.
Change your passwords, and be alert for anything unusual in the coming weeks.
Leo mentioned that the password might be found in the browser cache. I’d add that it can also be found in the swap-file.
Erasing the swap-file every time you shut down seems like unnecessary overkill. What I’ve done a couple times when traveling, is to use the bios password.