How to tell if your Gmail account was hacked
Jul 20th
There are two basic signs your e-mail account has been hacked:
- You can’t log in, even with a password you know is valid
- Your account is sending e-mails that you never wrote
Those are obvious, but savvy e-mail hackers don’t often tip their hands with these sorts of blatant clues anymore. They’d much rather hijack your account and use it without your ever knowing it. Serious hackers rarely change your password, and they don’t often resort to sending e-mail to recipients from your address book (who will quickly notice that you’re sending them Viagra ads or porn site signup links). The new breed of email hackers will simply hang out in your account until you get an online bank statement or similar sensitive message, then use that data to steal actual money from you.
That’s why Gmail adds a third method for sniffing out e-mail hackers: the account activity log.
Located at the bottom of your Gmail inbox, just below the “You’re currently using XXXX MB (XX%) of your 7XXX MB” listing, is a line displaying your last account activity. This readout displays the last time someone logged into your Gmail account. If the time and date that follow last account activity don’t match up to a time you were actually using Gmail, that should be a red flag.
In any case, it’s a good idea to regularly click the details link that follows the last account activity timestamp. This will prompt a chart of your last dozen or so Gmail logins, organized by the login method (your web browser, your mobile phone, or a POP3/IMAP connection like that used by Outlook or Thunderbird). Each login will also be timestamped and associated with an IP address.
If you don’t ever log into Gmail from a mobile phone but the activity log says your Gmail has a history of mobile access, that’s a warning sign. The same goes for an IMAP or POP3 link if you don’t use a third-party program or service to sync or access Gmail.
Note that your regular Backupify backups will appear in this activity log as authorized logins, as will some other legitimate services you don’t immediately recognize, which is why checking the IP address of each login is a good idea. Simply copy the IP number and paste it into the lookup service at Domain Tools. You’ll instantly learn who owns the IP address that logged into your Gmail account. Your Backupify backups will typically look like IMAP logins from an IP address owned by Amazon.com; that’s our application backing up your data to our Amazon S3 storage account.
If there’s a sketchy looking IP address on the activity list, now would be a good time to change your Gmail password. Gmail does a good job of noting when a known hacker IP address (or even a suspected one) logs into your account and throwing up an alert. Gmail does the same thing when your account is logged into from two IP addresses simultaneously (like when I have my work VPN laptop and my personal PC on Gmail simultaneously). Follow the instructions in these alerts and change your Gmail password whenever your receive one.
If at any point you suspect your Gmail account has been compromised, notify Google here and follow their instructions. They’ll lock down your account from any further unauthorized access and help undo whatever damage was done — if possible. Whatever Google can’t recover, Backupify is here to replace.
Stay alert, don’t panic and — as always — have a good backup plan.
Some good tips here on keeping your Gmail safe.
Twitter is a funny thing…
Jul 19th
… like last week when I was giving away a free fitness bootcamp, I was the coolest person around. Shit, even GeekMommy was interested and responded to me.
@brandonzeman attend where?
Yet, twice lately I’ve seeked the sage advice and experience of my great followers, only to receive no response. I’m not a self-promoting douche and rarely tax my followers for response, so it’s a bit frustrating.
If you could offer one piece of online advice to a new grad, what would it be?
cricket….cricket….
Bootcamp!
Jul 14th
Wow, the response has been amazing! Because things can get pretty fragmented on Twitter, here’s as much information as I have available:
Bootcamp details:
We’re looking for 10 bloggers (a loose number, willing to take more) to commit to attending the bootcamp for a period of at least two weeks, and up to one month FOR FREE. All they ask for in return is an HONEST take on your experience. If you’d like to blog and tweet the entire bootcamp, that’s wonderful. If you want to write a summary at the end of your training, that works as well.
The bootcamp is run by Brian Feldkamp of Total Results Training. Please check out his website to get some background on him and his program, and to get an idea of what to expect. Brian stresses fun and enjoyment at his bootcamps, so if you’re expecting to get yelled at like you’re in the military, well, you won’t!
Bootcamp schedule:
The bootcamp is offered at a few different locations and times- hopefully you can find one that is convenient for your schedule. Note: The locations below are the ACTUAL parks.
Eckhart Park-6:00am M/T/W/F 8:30am & 9:45am M/W/F
Lincoln Park- 6:15am & 7:15am M/W/F 8:30am & 10:00am Sat
Oz Park- 12:00pm M/W/F
Wicker Park-7:00pm M/W
Still interested?
Contact me directly- either on Twitter @brandonzeman or email brandonzeman@gmail.com and we will get you registered with your preferred times and locations. You can get started right away or wait a week or two to get prepared (although really, can you ever be prepared for one of these?)



