logo

Spam through compromised passwords: can it be stopped?

ID: 5249772a-20ac-5953-b379-e6e2227deb62

STIX ID: report--5249772a-20ac-5953-b379-e6e2227deb62

Feed Name: The Spamhaus Project

Threat Score
60/100

Date Published: 2012-05-09

Date Updated: 2026-04-30

Author: The Spamhaus Team

...
...

**Executive summary:** The report explains how compromised user accounts on legitimate mail servers—obtained through password guessing, phishing and keystroke‑logging malware—are a major vector for high‑volume spam, malware distribution and fraud; it details why current operational responses and blocking measures are ineffective and recommends Mail Submission Agent (MSA) and administrative mitigations such as per-account rate limits, authenticated-account logging in logs and headers, per-account monitoring and alerts, weak-password rejection, and authentication rate‑limiting to reduce this threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.