Hacked by adding a Workplace or school account

in Techie Stuff
6 replies 283 views
grumpycrabgrumpycrab Forumite
5K Posts
Part of the Furniture 1,000 Posts Name Dropper Bake Off Boss!
Forumite
I don't know how my friends have so many problems with Windows but I've never seen this one before. Windows 10 with mcaffee.  They have a local admin account only. Someone/thing had managed to add a "Workplace or school account" called [email protected] This is a dummy account as Microsoft didn't recognise the account, but real enough to be a profile in Edge and an email account in MS Outlook (Home and Business 2016).
You can probably guess what happened next.  This spurious new email account sent lots of emails demanding invoice payment.  This was achieved via a docx template containing the invoice text and excel spreadsheet of email addresses (NOT the computer owner's address book).
Anybody know how this account could have been created?
If you put your general location in your Profile, somebody here may be able to come and help you.

Replies

  • pramsay13pramsay13 Forumite
    1.7K Posts
    Part of the Furniture 1,000 Posts Name Dropper
    Forumite
    No, I assume your friend has fallen for a phishing email or clicked on a dodgy link which has given someone access to their computer system.
  • grumpycrabgrumpycrab Forumite
    5K Posts
    Part of the Furniture 1,000 Posts Name Dropper Bake Off Boss!
    Forumite
    pramsay13 said:
    No, I assume your friend has fallen for a phishing email or clicked on a dodgy link which has given someone access to their computer system.
    Yes, an email seems to be the source of the issue.  Doesn't look as if mcaffee traps this kind of thing. Perhaps webmail is safer?
    If you put your general location in your Profile, somebody here may be able to come and help you.
  • tallmansixtallmansix Forumite
    1.8K Posts
    1,000 Posts Fourth Anniversary Name Dropper Photogenic
    Forumite
    Taking the laptop offline and doing a full factory reset would be my recommendation right now, doesn't matter where the malware came from, it is clearly capable of propagating more phishing emails which unfortunately will result in somebody somewhere also getting malware and potentially being hacked/losing money/data etc.

    McAfee or any antivirus, in fact, isn't foolproof when it comes to phishing attempts, hackers can spin up a new domain in minutes and send a phishing email out to millions of people before any AV or ISP has a chance to detect or block it.
    YNAB enthusiast and extreme coupon-er.
    Discounts, coupons and cashback:
    2019 = £1,443.52
    2020 = £1,191,76
  • forgotmynameforgotmyname Forumite
    32.2K Posts
    Part of the Furniture 10,000 Posts Name Dropper
    Forumite
    Have they called McAfee or Paypal or Microsoft because of a popup?  Have they added or any trace of anydesk or similar?

    Thinking they got a fake message to call and they installed remote access software where they may still have access.

    Censorship Reigns Supreme in Troll City...

  • grumpycrabgrumpycrab Forumite
    5K Posts
    Part of the Furniture 1,000 Posts Name Dropper Bake Off Boss!
    Forumite
    Have they called McAfee or Paypal or Microsoft because of a popup?  
    No, but I know somebody else who called a "mcafee agent" and paid £300 for a 10 year license. And they thought they were getting a good deal. 
    If you put your general location in your Profile, somebody here may be able to come and help you.
  • forgotmynameforgotmyname Forumite
    32.2K Posts
    Part of the Furniture 10,000 Posts Name Dropper
    Forumite
    Watched some scam baiter videos and shocked at the amount of money the scammers get. I think more needs to be
    done to alert people to these scams.

    Censorship Reigns Supreme in Troll City...

Sign In or Register to comment.
Latest MSE News and Guides

Did you know there's an MSE app?

It's free & available on iOS & Android

MSE App

Regifting: good idea or not?

Add your two cents to the discussion

MSE Forum

Energy Price Guarantee calculator

How much you'll likely pay from April

MSE Tools