« Introducing IBM Shortcuts podcast... | Main| SnTT (yeah, I remembered ;-) ): Couple of Notes frameset tips »

Chalk one up for the good guys - and thanks to MSN Hotmail Tech Support

QuickImage   
Category
Bookmark : del.icio.us  Technorati  Digg This  Add To Furl  Add To YahooMyWeb  Add To Reddit  Add To NewsVine 



I recently announced that I had a problem - someone was impersonating me with a MSN Hotmail account. Well, to make a long story short, I am happy to report that MSN Hotmail Technical Support has acted upon my reporting of this issue, and has closed the abusive account in question:

Hello Rocky,

This is to inform you that we have received your fax of earlier today in regards to impersonation using the account rocky_oliver@hotmail.com.

The following action has been taken in this case. After reviewing the information provided, we have found the account mentioned does violate the MSN Terms of Use agreement.

The account specified has since been closed, and the information provided has been posted with the account for research.

Sincerely,

Sherry B.


So, this is GREAT news! Many thanks to the folks at MSN Hotmail Tech Support - I appreciate your quick response once you had the evidence in hand.

Now, if you want to know the whole story of my dealings with MSN Hotmail Tech Support, please read on...

After Rich Schwartz contacted me and let me know about the spoofing of my identity, I posted the aforementioned announcement about it - I posted it here and in various internal forums. Afterwards I decided to go ahead and contact MSN Hotmail Tech Support and see if I could get any assistance in having this account deleted. I filled out the support form with the following description:

--- Original Message ---
From: ** my notesdev.ibm.com email addy**
Sent: Friday, July 28, 2006 9:49:12 PM UTC
To: support_x
Subject: MSN Hotmail:I need something fixed:Other
Full Name: Rocky Oliver
Primary e-mail address/member ID associated with the account you are inquiring about: rocky_oliver@hotmail.com
Be specific when describing your problem. The details that you include enable us to promptly send you the most likely solution to your issue.

Someone has registered my name with Hotmail *which isn't that big a deal*, but they are sending emails to people who have responded to my blog * http://www.lotusgeek.com *. These emails contain web pages from my site packaged up in CHM files, and may have an undetectable trojan payload. The email looks like it is from me, since it contains pages *which seem randomly chosen* from my site.

I would like to ask you to cancel this account for abuse, identity theft, and for distributing potentially malicious software.
If you have any other questions, please ask. I want to thank you in advance for helping me resolve this matter.
Incidentally I have a Passport account **removed from email**, but I do not have a hotmail account at all.
Sincerely,

Rocky Oliver
Senior Software Engineer
IBM Corp/Lotus Software


Well, I received the following reply about 24 hours later:

Hello Rocky,
Thank you for writing to MSN Hotmail Technical Support.

This is Cristina and I have read that someone created a Hotmail account under your name. I have noted that this account is being used to send replies to message on your blog pretending to be you.I apologize for the delay in answering your e-mail. We appreciate your patience as we handle every customer request as quickly as possible.

I understand how upsetting this matter can be for you, especially because this is a case of impersonation. I apologize for the inconvenience this issue has caused you. However, while I would like to immediately close the account we need a statement from you denying any involvement with the account and/or knowledge of who registered the account. In other words, you should state: "I did not create this account. It is being used to impersonate me. I have no knowledge of who created this account.". We need documented proof of the impersonation or misrepresentation of you on Hotmail. If you do not have an actual e-mail message, please send us a detailed written explanation of why you believe that you are being impersonated. If you are being impersonated in a chat forum or on newsgroups, we need copies of the chat message or the newsgroup posting, the Hotmail name used in the chat session or posting, and an explanation of the extent of the impersonation that is taking place. Please reply to this e-mail message with the information requested above. (emphasis mine **rock) As soon as we have all the information, we will take appropriate action against the account for violating our Terms of Use.

We are pleased to be of assistance to you.

Sincerely,

Cristina C.
MSN Hotmail Technical Support


Well, I followed the instructions - which as noted in the emphasized text above was to email the information - and I emailed the following response to "Cristina C":

From: "Rocky Oliver"
Sent: Monday, July 31, 2006 4:25:34 PM UTC
To: support_x_EN_SY
Subject: RE: SRX1018043006ID - MSN Hotmail:I need something fixed:Other

I am sending this in response to instructions sent to my by Cristina C, MSN Hotmail Technical Support. She provided me the following instructions:

"However, while I would like to immediately closethe account we need a statement from you denying any involvement with theaccount and/or knowledge of who registered the account. In other words,you should state: "I did not create this account. It is being usedto impersonate me. I have no knowledge of who created this account.". We need documented proof of the impersonation or misrepresentation of you on Hotmail. If you do not have an actual e-mail message, please send us a detailed written explanation of why you believe that you arebeing impersonated. If you are being impersonated in a chat forumor on newsgroups, we need copies of the chat message or the newsgroup posting, the Hotmail name used in the chat session or posting, and an explanationof the extent of the impersonation that is taking place. Please replyto this e-mail message with the information requested above."

Here is my official statement:
I did not create this account. It is being used to impersonate me, and is being used to send questionable attachments with what appears to be potential viral/trojan payloads to people who know me. I have no knowledge of who created this account. Please see the two included emails below. The first is to another IBMer, David Stephens, whom I have never met. I wrote him after learning of the use of my identity to see if he had received anything, and in fact he had - the included email. The second was to a friend of mine, Richard Schwartz. Richard received a forwarded version of the email sentto David Stephens. Richard sent me his email as a text file included in"rocky _oliver_spoof_msg.zip", attached. He sent it this way because the original email was getting caught in the IBM spam/virus filters.

I believe that this person used my blog to find people who respond to posts on my blog, then went to find the emailsof these people (I do not publish the emails of my repondents on my blog) so that the attachment could be mailed to them. Both of these people have email addresses that can easily be discovered online - in David's case he is a sales rep, so his email is everywhere; in Rich's case he used to own a consulting firm, RHS consulting, and the email address used to deliver the payload to him ( **removed from this post ** ) is posted on his website ( http://www.rhs.com/ ).

Please let me know if you need any additional information. I am eager to get this account terminated so that further attempts to discredit me are avoided.

Thanks so much for your help.

Sincerely,

Rock
_________________________________________________________
Rocky Oliver
Senior Software Engineer
IBM Corporation | Lotus Software


Well, I received this reply yesterday:

Dear Rock,
Thank you for writing back to MSN Hotmail Technical Support.

My name is Jeffry and I read your e-mail exchange with Cristina regarding your impersonation complaint against rocky_oliver@hotmail.com. I understand how important it is to resolve your concern and I apologize for the confusion.

Rock, if you think your name is being used in conjunction with a Hotmail account that you did not establish, we need a statement from you denying any involvement and knowledge of who registered the account. We need documented proof of the impersonation or misrepresentation on Hotmail (for example, a message sent from the impersonator proving they are trying to impersonate you). If you do not have an actual e-mail message, please send us a detailed written explanation of why you believe that you are being impersonated. If you are being impersonated in a chat forum or on newsgroups then please provide the following:
- Copies of the chat message or the newsgroup posting
- The Hotmail name used in the chat session or posting
- Explanation of the extent of the impersonation that is taking place

Please fax your complaint to 1 (425)-936-7329 with the subject "Attention: MSNABUSE". (emphasis mine **rock) Include a copy of your photo ID, all requested documentation, and a text saying: "I did not create the account, rocky_oliver@hotmail.com." If you do not have access to a fax machine, please mail the information to the following address:
Attn: MSNABUSE
Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399


We will investigate this issue as soon as we receive the needed information. You are valuable to MSN and our top priority is to provide you consistent and effective service.

Sincerely,

Jeffry F.
MSN Hotmail Technical Support


Well, to be honest I was beginning to get a bit miffed - I mean I followed the directions given to me by "Cristina C" and I had mailed in the information. Now "Jeffry F" wants me to FAX the same information, along with a photo ID, to them. I was beginning to feel like I was going to get the runaround, like I did in the ICQ fiasco. But, I carefully prepared a fax - 11 pages in all - with all of the required information. I included my statement, a scanned image of my license, all of the example emails (which, incidentally, this impersonator had sent a second set of emails out during this time - I sent them four examples), and copies of the original email correspondence with their tech support folks.

I faxed that earlier today, not expecting a reply for awhile. Well, I would guess about 3 hours after faxing that information off I received the email in the first part of this post indicating the account had been deleted.

This is MOST excellent!

I am very grateful to MSN Hotmail Tech Support for responding relatively quickly to my issue - it is refreshing to get such a prompt reply and action.

I am curious, however, about one part of the final reply:

The account specified has since been closed, and the information provided has been posted with the account for research.


I wonder what "the information provided has been posted with the account for research" means?

Anyone have a clue?

Anyways, if you ever have such a problem, I can heartily recommend you contact MSN Hotmail Tech Support - they are ready, willing, and able to help you resolve the matter.

Oh, and it is good to be back

Rock
**If I could talk to the animals, I'd tell them about their lousy personal hygiene. And then I'd buy Proctor & Gamble stock, because there are a lot of animals out there.

Comments

1 - hi rock
I can't open my hotmail. Is there something technical going on that I don't know about, or has hotmail stop my account if so how can I get my contacts sent to me.

2 - Hey Rock, good to see you back here! This sounds like an aweful story, but I'm surprised it was resolved this (fairly) easily. Concerning the final remark, I'd assume the go about some forensics to figure out who had done this and how they might be able to prevent this from happening in the future.

Good thing to know some companies care about personal rights online and identity theft violating those. Surprising to see that Microsoft is that upfront among them.

3 - <just kidding>

4 - I seem to recall there was an attachment in the bogus email "from" you to Rich? A .CHM file unless my memory is failing me. That would be a Windows compiled help file and exploits using these are fairly common but would be picked up by AV unless this was a new exploit. What happened to that file? Did you submit it to any malware researcher for analysis?

5 - I presume that means that although they have closed the account, they are reserving the right to continue to research the matter, figure out what exploit was used to get one of their servers to send the mail and get it past their outbound spam filters, try to track down the offender. I doubt they'll actually do much with it; but maybe they will, and they certainly want you to think that they will.

6 - Hi
I am wondering how I can get several large attachments (emails) deleted from my inbox.I can sign in and actually see my inbox-junk mail and sent folders.....but when I click on them they won't open.I am sure that there are several emails inbound that are plugging my email.Do you have a phone number or url that I can contact to get these emails deleted so that I can access my inbox.Thanks heaps
Lori:-

7 - I have been trying to contact MSN Hotmail for an email issue and have not had much luck. Do you have the email address you communicated to this "Christina" with. I haven't been able to get into my hotmail account and cannot even reset the password because my security question answer is wrong according ti their system. I have to have them send the reset email to my alternate email or reset the password for me. I have called countless numbers and sent a thousand emails including one verifying my information. I am very frustrated. Any advice you may have would be great!

Meet Rocky

Rocky Oliver
Rocky Oliver
If you see me at a conference, please stop me and say hi!

Calendar

Search

Categories

LotusGeek Tour 2008

DNUG08-2.png

Proudly Employed By

I am the Vice President of Products for TeamStudio

Our Corporate Blog

I am the Vice President of Products for TeamStudio

Thawte Notary

Thawte Web of Trust Notary

LOTUS GEEK gear

Social Networking


Add to Technorati Favorites

View Rocky Oliver's profile on LinkedIn

Rocky  Oliver

LotusGeek Blog Roll

Why display a blog roll when Planet Lotus does it so much better?

Dilbert

Buy my book!

Blog Buttons

Atheist - Unitarian - Humanist

Atheist Symbol

chalice_150.gif

Happy Humanist

Poker Players Alliance

This Site Designed By

YOU! If you would like to see your name and link here, read more about the Skin the Geek contest!