Ask the Community
Groups
My compromise report shows fake accounts such as info, spam for my domain - Connect IT Community | Kaseya
<main> <article class="userContent"> <p><strong>QUESTION</strong></p> <p>We are getting compromise reports for the following addresses on almost every single customer/domain.</p> <p> Observed user names in email addresses are as follows: </p> <ol><li> <strong>info@</strong>domainname.com</li> <li> <strong>admin@</strong>domainname.com</li> <li> <strong>contact@</strong>domainname.com</li> <li> <strong>sales@</strong>domainname.com</li> <li> <strong>spam@</strong>domainname.com </li> </ol><p><strong>ANSWER</strong></p> <div>This is representative of a rogue actor being interested in gaining unauthorized access to user accounts. They create a list of accounts and passwords to try and compromise a service on the domain. Whether the account exists or not, or the password is accurate or not, it is indicative that someone is interested in exploiting the domain(s) specifically.</div> <div> </div> <p><strong>REFERENCE</strong></p> <p><a rel="nofollow" href="/home/leaving?allowTrusted=1&target=https%3A%2F%2Fdoubleoctopus.com%2Fsecurity-wiki%2Fthreats-and-tools%2Fpassword-spraying%2F">Password Spraying (Low and Spray)</a></p> <p><a rel="nofollow" href="/home/leaving?allowTrusted=1&target=https%3A%2F%2Fen.wikipedia.org%2Fwiki%2FCredential_stuffing">Credential stuffing</a></p> <div> </div> </article> </main>