Spam through compromised passwords: can it be stopped?
ID: 5249772a-20ac-5953-b379-e6e2227deb62
STIX ID: report--5249772a-20ac-5953-b379-e6e2227deb62
Feed Name: The Spamhaus Project
**Executive summary:** The report explains how compromised user accounts on legitimate mail servers—obtained through password guessing, phishing and keystroke‑logging malware—are a major vector for high‑volume spam, malware distribution and fraud; it details why current operational responses and blocking measures are ineffective and recommends Mail Submission Agent (MSA) and administrative mitigations such as per-account rate limits, authenticated-account logging in logs and headers, per-account monitoring and alerts, weak-password rejection, and authentication rate‑limiting to reduce this threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
