Link to home
Start Free TrialLog in
Avatar of litmic
litmicFlag for Hong Kong

asked on

Fraudulent e-mail

Receive a Fraudulent e-mail from bitcon with subject of my email password. How bitcon know my email password?
ASKER CERTIFIED SOLUTION
Avatar of Hello There
Hello There

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
EXPERT CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Hello There
Hello There

Some good practices to prevent this in the future:
  • Do not use the same password for multiple accounts
  • Use strong passwords = lowercase letters, uppercase letters, numbers, special characters.
  • Do not store your passwords in plain text.
  • Change your passwords on a regular basis
EXPERT CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
The spam source as coming from Bitcoin as was pointed out is a phishing  to combine two items to make it appear as though ...
If not mistaken,bitcoin is the more widely known.
Your post included the have  I been hacked link where you can search by the email address and it will tell you which compromised entities this leaked from.

Not make sure where available that you use MFA/2FA mechanism. Use different security questions for important type of accounts.
The ideal thing is to use a separate email account for your Finances, and maybe a separate one just for bitcoin.  Don't use your name in any part of that email, and don't use it for anything else.  Isolate the email and you can isolate the spam.
To provide secure password management:
• Create complex passwords; Create passwords or passphrases that are hard to guess but easy for you to remember.
• Apply multi-factor authentication.
• Increase password complexity depending on the importance of the data/services.
• Ensure that these passwords are changed regularly, not reused, and not used on multiple systems/services.
• If you have trouble keeping track of your passwords, use a password manager.
• Avoid recording passwords. However, when necessary, be sure that any such files of recorded passwords are encrypted.
• On websites that you rarely visit, consider initially setting a random complex password,. When you need to visit the site again, click the forgot password link to reset the password and gain access.