📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Hacked by adding a Workplace or school account

Options
I don't know how my friends have so many problems with Windows but I've never seen this one before. Windows 10 with mcaffee.  They have a local admin account only. Someone/thing had managed to add a "Workplace or school account" called order-update@payment-authorise-pay-pal.com This is a dummy account as Microsoft didn't recognise the account, but real enough to be a profile in Edge and an email account in MS Outlook (Home and Business 2016).
You can probably guess what happened next.  This spurious new email account sent lots of emails demanding invoice payment.  This was achieved via a docx template containing the invoice text and excel spreadsheet of email addresses (NOT the computer owner's address book).
Anybody know how this account could have been created?
If you put your general location in your Profile, somebody here may be able to come and help you.

Comments

  • pramsay13
    pramsay13 Posts: 2,154 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    No, I assume your friend has fallen for a phishing email or clicked on a dodgy link which has given someone access to their computer system.
  • grumpycrab
    grumpycrab Posts: 5,026 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Bake Off Boss!
    pramsay13 said:
    No, I assume your friend has fallen for a phishing email or clicked on a dodgy link which has given someone access to their computer system.
    Yes, an email seems to be the source of the issue.  Doesn't look as if mcaffee traps this kind of thing. Perhaps webmail is safer?
    If you put your general location in your Profile, somebody here may be able to come and help you.
  • Taking the laptop offline and doing a full factory reset would be my recommendation right now, doesn't matter where the malware came from, it is clearly capable of propagating more phishing emails which unfortunately will result in somebody somewhere also getting malware and potentially being hacked/losing money/data etc.

    McAfee or any antivirus, in fact, isn't foolproof when it comes to phishing attempts, hackers can spin up a new domain in minutes and send a phishing email out to millions of people before any AV or ISP has a chance to detect or block it.
  • forgotmyname
    forgotmyname Posts: 32,928 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Have they called McAfee or Paypal or Microsoft because of a popup?  Have they added or any trace of anydesk or similar?

    Thinking they got a fake message to call and they installed remote access software where they may still have access.

    Censorship Reigns Supreme in Troll City...

  • grumpycrab
    grumpycrab Posts: 5,026 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Bake Off Boss!
    Have they called McAfee or Paypal or Microsoft because of a popup?  
    No, but I know somebody else who called a "mcafee agent" and paid £300 for a 10 year license. And they thought they were getting a good deal. 
    If you put your general location in your Profile, somebody here may be able to come and help you.
  • forgotmyname
    forgotmyname Posts: 32,928 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Watched some scam baiter videos and shocked at the amount of money the scammers get. I think more needs to be
    done to alert people to these scams.

    Censorship Reigns Supreme in Troll City...

Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.6K Spending & Discounts
  • 244K Work, Benefits & Business
  • 599K Mortgages, Homes & Bills
  • 177K Life & Family
  • 257.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.