Sunday, August 16, 2026
HomeGadgetsAccount Takeover: What an Attack on the Journal Teaches Us About Cyber...

Account Takeover: What an Attack on the Journal Teaches Us About Cyber Crime

Last Friday was just like every Friday in the office, and our publisher, Christine Mallory, was looking forward to an enjoyable, quiet weekend. After closing shop, about 7:30 that night, all hell broke loose. Google notified her that the paper’s email account, northshorejournal@ gmail.com, was suspended because it appeared to have been the victim of what’s known as an account takeover (ATO) attack that sends spam email to every contact in the account. 

“There are so many emotions when this happens,” Christine said. “I was freaking out right away.” 

The attackers/hackers sent an email with a seemingly legitimate, but poisonous, attachment to the paper’s entire email contact list, a list built over two decades. Not content with that, the corrupt actors deleted every contact in the account.

Google restored the account Friday night, and, as of deadline this week, Christine received over 180 emails that failed to be delivered because the address they were sent to was inactive. She thought to send emails to the paper’s list to explain the situation, but since the contacts were all gone, she could only wait and hope that anyone who received the corrupt email deleted them before opening. 

The attackers may have gained access a few weeks earlier when Christine opened a suspect email from a known sender. Once hackers harvest login credentials, they often wait for an opportune moment— like a Friday evening—to spew their spam.

“My contact list goes back like 20+ years, so a lot of the addresses weren’t even valid anymore. I have over 180 email delivery failures,” Christine wrote to contributing writers Monday morning. “I can only imagine how many went through.”

This incident hits on critical internet vulnerabilities that small-to-medium businesses face every day. Cybersecurity experts and email providers point to a few key reasons why long-standing accounts are targeted:

“A Gmail account that has been active for over a decade has a long-standing history and high trust score with email providers. Hackers value these accounts because mass emails sent from them bypass standard spam filters much longer than emails sent from a brand-new account.”

“The account was likely used for phishing (tricking recipients into clicking a link to steal their credentials) or credential harvesting.”

“Hackers often delete contacts, sent items, and incoming filters after an attack to erase their tracks or prevent the business owner from quickly emailing clients to warn them.”

“When Google restores an account after automated fraud suspension, it restores access, but automated security wipes or hacker actions right before the lock-out can leave the contact database empty.”

The scoundrels who commit these cyber crimes target small businesses because they aren’t IT specialists and don’t have corporate-grade security monitoring.

The primary damage from this ATO attack against the North Shore Journal isn’t financial theft from the business, but the erosion of trust when readers and advertisers receive malicious emails from a trusted sender.

Christine recommends that everyone who receives suspect emails check the email address of the sender before opening. 

If you haven’t recently, change your passwords. And make sure to set up multi-factor authentication on your email account(s). Google said that’s the single most effective defense against ATO attacks.

Steve Fernlund
Steve Fernlund
Columnist Steve Fernlund is a retired business owner living in Duluth. He published the Cook County News Herald in Grand Marais at the end of the last century. You may email comments or North Shore news story ideas to him at steve.fernlund@gmail.com. And see more at www.stevefernlund.com.
RELATED ARTICLES
- Advertisment -

Most Popular