Compromised email accounts used to illegally access cryptocurrency accounts: Police警方:被盗用的电子邮件账户被用于非法访问加密货币账户。
Members of the public who have cryptocurrency accounts should take the necessary steps to safeguard their linked email accounts.Police said in a crime advisory on Saturday (Sept 12) that they have noticed an increase in cases involving unauthorised access to cryptocurrency accounts — through compromised linked email accounts — since mid-August. Investigations found that several of the affected email accounts...

Members of the public who have cryptocurrency accounts should take the necessary steps to safeguard their linked email accounts.
Police said in a crime advisory on Saturday (Sept 12) that they have noticed an increase in cases involving unauthorised access to cryptocurrency accounts — through compromised linked email accounts — since mid-August.
Investigations found that several of the affected email accounts had previously appeared in data breaches on other platforms. This suggests that the victims' credentials may have already been exposed.
The perpetrators may have then exploited this and used the compromised credentials to access victims' cryptocurrency accounts, taking advantage of those who reused the same passwords across multiple online services.
While it may appear that there are several "layers" for perpetrators to cross, it is not impossible.
This can be achieved by searching a victim's compromised email account to identify cryptocurrency platforms or exchanges used by the victim.
Once identified, inbox rules can be set to automatically archive, forward or delete emails from cryptocurrency exchanges to avoid detection.
Meanwhile, perpetrators may also initiate password reset requests for cryptocurrency exchange accounts and intercept password reset links, one-time passwords or verification emails sent to a victim's compromised email account.
If a victim uses the same password across multiple online services, including their cryptocurrency account, then, perpetrators can simply use the credentials obtained through data breaches to gain access.
How to protect yourself
Members of the public should use strong and unique passwords for each online account and avoid reusing passwords across multiple services.
In addition, they should always enable multi-factor authentication (MFA) or two-factor authentication (2FA). Where possible, the use of an authenticator application would also improve account security.
They should also regularly review the security settings of their email account, including looking out for unauthorised inbox rules, email forwarding settings and suspicious login activity.
When prompted of data breaches by service providers, those affected should immediately change their passwords and ensure that 2FA or MFA is enabled.
Meanwhile, cryptocurrency accounts should be regularly reviewed, with account activity notifications enabled.
Those who believe that their email and/or cryptocurrency account has been compromised should immediately contact their service provider to secure or freeze the affected account.
They should also report the matter to the police.
拥有加密货币账户的公众成员应采取必要措施保护其关联的电子邮件账户。
警方在周六(9 月 12 日)发布的犯罪通告中表示,自 8 月中旬以来,他们注意到通过被盗用的关联电子邮件帐户非法访问加密货币帐户的案件有所增加。
调查发现,部分受影响的电子邮件账户此前曾在其他平台的数据泄露事件中出现过。这表明受害者的凭证可能已经泄露。
犯罪分子随后可能利用这一点,使用被盗用的凭证访问受害者的加密货币账户,因为有些人会在多个在线服务中重复使用相同的密码。
虽然看起来作案者需要跨越好几层“障碍”,但这并非不可能。
这可以通过搜索受害者被盗用的电子邮件帐户来识别受害者使用的加密货币平台或交易所来实现。
一旦识别出加密货币交易所的电子邮件,可以设置收件箱规则,自动归档、转发或删除这些邮件,以避免被检测到。
与此同时,犯罪分子也可能发起加密货币交易所账户的密码重置请求,并拦截发送到受害者被盗用电子邮件账户的密码重置链接、一次性密码或验证电子邮件。
如果受害者在多个在线服务(包括加密货币账户)中使用相同的密码,那么犯罪分子就可以利用通过数据泄露获得的凭证来获取访问权限。
如何保护自己
公众应为每个在线账户使用强密码和唯一密码,并避免在多个服务中重复使用密码。
此外,他们应该始终启用多因素身份验证 (MFA) 或双因素身份验证 (2FA)。如果条件允许,使用身份验证器应用程序也能提高帐户安全性。
他们还应定期检查电子邮件帐户的安全设置,包括查找未经授权的收件箱规则、电子邮件转发设置和可疑的登录活动。
当服务提供商提示发生数据泄露时,受影响的用户应立即更改密码,并确保启用双因素身份验证 (2FA) 或多因素身份验证 (MFA)。
同时,应定期检查加密货币账户,并启用账户活动通知。
如果用户认为自己的电子邮件和/或加密货币账户已被盗用,应立即联系服务提供商,以保护或冻结受影响的账户。
他们还应该向警方报案。