My e-mail has been compromized.
... / My e-mail has been compro...
BMPCreated with Sketch.BMPZIPCreated with Sketch.ZIPXLSCreated with Sketch.XLSTXTCreated with Sketch.TXTPPTCreated with Sketch.PPTPNGCreated with Sketch.PNGPDFCreated with Sketch.PDFJPGCreated with Sketch.JPGGIFCreated with Sketch.GIFDOCCreated with Sketch.DOC Error Created with Sketch.
Question

My e-mail has been compromized.

by
charlotte Verstraeten
Created on 2025-02-10 15:27:03 in Sécurité

My e-mails (info@hvchemicals.be and wverstraeten@hvchemicals.be) were compromized and someone intercepted my mails. They were able to send under my name false information to my customer, especially for money transaction matters.

How can I avoid this situation and how can I check if this scammer is still actif on my mail adress.

Thanks for your advice

best regards

walter Verstraeten


1 Reply ( Latest reply on 2025-02-10 16:41:54 by
fritz2cat 🇧🇪 🇪🇺
)

Hello,

In order to block the scammers, please connect to your customer area (from www.ovh.com) .

Urgently go to the e-mail section, and change the passwords of all e-mail mailboxes that may be compromised. Or change them all in doubt.

Unfortunately, you have no access to the logfiles documenting the last time an e-mail has been sent from your address.

Next activate 2FA '2-Factor-Authentication' on your OVH customer account, if not already done. You may choose amongst Google Authenticator, SMS, ...

2FA will really add an extra layer of security. BTW you should also generate 10 backup codes (in case your phone is not accessible, or for your Business Continuity Plan). Print them and put them in your safe. Each time a code is used, it becomes invalid and is not reusable.

By default, Internet provides almost no security for authenticating the real sender of an e-mail. Even if you are not compromised, a scammer could send e-mails pretending to originate from your address.

The security protocols such as SPF, DKIM and DMARC are useful for authenticating genuine e-mails but are not mandatory. If a sending domain sets the correct policies for rejecting falsifications, any receiving server adhering the policies published by the sending domain would reject these scams.

Your SPF "v=spf1 include:mx.ovh.com ~all" is moderatly strict. (explanation: https://powerdmarc.com/spf-all-vs-all/ )