Hacked Email
Problem
Your email has been hacked or compromised.
Solution
The following are our recommendations for handling compromised email accounts and avoid them in the future.
Change password as soon as possible.
Password recommendations
Use a passphrase. A sentence as a password is great, and https://xkcd.com/936/ demonstrates why. Here are the 3 main advantages.
It's easy to make a longer password. We're good at remembering words and phrases.
It's easy to make a more complex password. Just look at punctuation, grammar, and capitalization!
It's easy to make a unique password. Easier to remember means more headspace for more passwords!
Use a password manager. The passphrase recommendation is still important for master passwords, but things like dashlane, logmein, onepassword, etc. are totally amazing and always worth considering. They generate unique, complex, and long passwords for each login, associate them to a site, and save the data for easy and well-organized access for you!
Run anti-malware scans on the computer of the compromised user. Why? It's common to get malware that compromises the most secure of account details. If they can see what is typed on the keyboard, if they have physical access, you're compromised and will continue to get compromised.
Run email addresses attached to your accounts, **especially accounts sharing passwords**, through haveibeenpwned.com to see if/when your passwords may be present in password dumps/mass compromises and change passwords to anything important from around that time, or anything still using that password.
If you ever question the veracity of an email, just open up apps.rackspace.com, export the mail as .zip, and run it through virustotal. Even if virustotal.com doesn't say there's malware, right click on any links and make sure you recognize the website before putting in account details.
Beyond that, if there's malware please report it to us. We need to keep making our filters better to keep everybody on our platform safe.In Web mail, please have the end user review the following sections for any changes not made by him/her. All of these will be accessed by going to the MENU option in the upper-right corner.
Update Phone: Menu > Update Phone
Identities: Menu > Settings > Composing Email > Identities
Forwarding: Menu > Settings > Incoming Email > Forwarding
Filtering: Menu > Settings > Incoming Email > Filtering
Spam Settings: Menu > Settings > Spam Settings
Safelist: Menu > Settings > Spam Settings > Safelist
Blacklist: Menu > Settings > Spam Settings > Blacklist
The last recommendation pertains directly to Rackspace Email mailboxes. here's the exchange settings list
General>Manage Add-ins
General>Mobile Devices
Mail>Automatic Processing>Automatic Replies
Mail>Automatic Processing>Inbox and Sweep rules
Mail>Accounts>Block or Allow
Mail>Layout>Message Format
Mail>Layout>Email Signature
Mail>Layout>Link Preview
Calendar>Automatic Processing>Invitations
Calendar>Shared calendars>Calendar Publishing