Mac mail program hacked?

I'm afraid I'm not posting this in the right place - but any advice would be welcome.


I think my mail program/mac.com email account has been hacked. I am recieving around 10 postmaster notifications every day that emails are returned undeliverable - but they are emails I never sent and are not in my sent itmes (or on iCloud). I have changed my password for my mac account, changed it for my computer, and have run a ClamXav scan and found nothing. Yet the emails continue to go out. All my software is up to date.


Here is an example of the email I'm recieving. Note, the email recieptients are not from my contacts - I don't know who they are.


The initial send date is after I changed passwords and scanned the computer. I deleted my email address from the message (replacing with MYEMAILADDRESS).


What should I do? Please help!


Thanks.


___________________________

This report relates to a message you sent with the following header fields:


Message-id: <***>

Date: Wed, 22 Aug 2012 16:53:08 +0200

From: Shdtazsfl <MYEMAILADDRESS>

To: ***

Subject: wesat


Your message has been enqueued and undeliverable for 1 day

to the following recipients:


Recipient address: ***

Reason: unable to deliver this message after 1 day



Delivery attempt history for your mail:


Fri, 24 Aug 2012 00:29:09 -0700 (PDT)



Thu, 23 Aug 2012 16:24:45 -0700 (PDT)



Thu, 23 Aug 2012 08:21:01 -0700 (PDT)



Thu, 23 Aug 2012 00:17:16 -0700 (PDT)



Wed, 22 Aug 2012 20:12:40 -0700 (PDT)



Wed, 22 Aug 2012 16:08:56 -0700 (PDT)



Wed, 22 Aug 2012 12:05:11 -0700 (PDT)



Wed, 22 Aug 2012 10:01:27 -0700 (PDT)



Wed, 22 Aug 2012 07:57:43 -0700 (PDT)



Wed, 22 Aug 2012 06:53:44 -0700 (PDT)



The mail system will continue to try to deliver your message

for an additional 3 days.


Original-envelope-id: ***

Reporting-MTA: dns;st11b01mm-asmtp207.mac.com (tcp-daemon)

Arrival-date: Wed, 22 Aug 2012 06:49:42 -0700 (PDT)


Original-recipient: rfc822;***

Final-recipient: rfc822;***

Action: delayed

Status: 4.4.7 (unable to deliver this message after 1 day)

Return-path: <MYEMAILADDRESS>

Received: from *** by

***

(Oracle Communications Messaging Server 7u4-23.01(7.0.4.23.0) 64bit (built Aug

10 2011)) id <***>; Fri,

24 Aug 2012 00:41:31 -0700 (PDT)

Received: from vrifmgsctsu (unknown [31.192.36.7])

by ***

(Oracle Communications Messaging Server 7u4-23.01(7.0.4.23.0) 64bit (built Aug

10 2011)) with ESMTPA id <***> for

***; Wed, 22 Aug 2012 06:49:42 -0700 (PDT)

Date: Wed, 22 Aug 2012 16:53:08 +0200

From: Shdtazsfl <MYEMAILADDRESS>

Subject: wesat

To:***

Message-id: <***>

MIME-version: 1.0

Content-type: text/plain; CHARSET=US-ASCII

Content-transfer-encoding: 7BIT


vi

gaqin http://aaqdf9jgaam2n.de.tl/ ry na


<Edited By Host>

Mail-OTHER, Mac OS X (10.7.4)

Posted on Aug 24, 2012 6:25 AM

Reply
8 replies

Aug 24, 2012 5:00 PM in response to DrewHyslop

I'm surprised that nobody but one of the hosts has taken the time to answer you. Not my area of expertise, but I'll give you some ideas.


I've never run across any case of the Apple Mail application being used in this way without physical access to your computer over by controlling it remotely over a network. All a spammer really needs is your e-mail address (which I suppose is what the host removed for you) and he can send tons of e-mail out that appears to come from you, some of which doesn't go through and is bounced back to you.


The second biggest way this happens, as you have guessed, is to hack your e-mail account by guessing the password and using that to send spam. Depending on what your preferences are set to, you may be able to tell if this was done if the outgoing messages appear in your "Sent" folder. If you find such messages, you can be assured that they were sent using your e-mail account in some manner. If there you do save sent messages and there is no sign of them, then they are just using your e-mail address.

Oct 19, 2012 4:42 PM in response to MadMacs0

I am having the same problem as the op. beginning two days ago i started getting delay and failure notices for garbage messages, many with .ru addresses. Ordinarily i ignore the odd 'failure notice' but for the last several days that is all i have recieved on my .mac account. Worse, i just learned from a friend that two emails she sent me in the same time were returned to her undelivered. My gmail accounts seem to be unaffected.


There are no outgoing messages in my sent mail folder.


What exactly should i do? Can i save this account or do i have to shut it down and lose the .mac tag?

Oct 19, 2012 4:56 PM in response to xtopad

xtopad wrote:


I am having the same problem as the op.


What exactly should i do?

Nothing you can do. They are simply using your e-mail address in the From: header. As long as there is nothing you did not send in your Sent folder, they are not using your account (or your computer) to send them.


Not sure why your friend was unable to send mail to you. Are you otherwise receiving e-mail to this account OK as near as you can tell?


Have any of the folks in your Contacts reported receiving Spam/Junk from you?

Oct 19, 2012 5:17 PM in response to MadMacs0

I have recieved nothing but failure notices over the last three days. I dont know of any contacts receiving spam, but i am not sure if i would know, since apparently i am not receiving mail through the account. My friend said the bounced emails to me said something about over limit. (i dont have the bounce emails to read myself) i have asked a couple of people who say they havent gotten anything unusual from my address.


Is there something i can request apple do to shut these people down so i can use my own account again?

Oct 19, 2012 5:28 PM in response to DrewHyslop

I agree with MadMacs - someone got your email address by hacking into someone's online account (most likely) to steal email addresses - they are sold to mass marketers. I also get the "can't deliver" messages - they are simply using your stolen email address as a "from" address and sending SPAM to some invalid address. Just as a completely ridiculous example: I have a Yahoo account and that has been hacked into several times. I am now receiving SPAM emails from me to me!!


There isn't much you can do - they will continue to steal email addresses. Change your password often. I've actually reduced my address book entries to a minimum in Yahoo and make sure I do not have any personal info stored there besides the email address.

Oct 19, 2012 11:03 PM in response to MadMacs0

xtopad wrote:


My friend said the bounced emails to me said something about over limit. (i dont have the bounce emails to read myself) i have asked a couple of people who say they havent gotten anything unusual from my address.


Is there something i can request apple do to shut these people down so i can use my own account again?

Apple can't do anything about whoever is sending the messages out because they are not using your account to send anything.


It does sound like they may have locked your account for some reason. Perhaps you have exceeded your storage limits because of all the bounce messages? Make sure your junk/spam and trash folders are completely empty and that you are getting rid of those bounce message. If that doesn't do it you may have to either buy more storage or get rid of messages/attachments you no longer need.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Mac mail program hacked?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.