Mastodon Mastodon Mastodon Mastodon

Abuse

Updated: · CyberSecureFox Editorial Team

In cybersecurity, abuse means using networks, services or accounts for harmful activity such as spam, phishing, DDoS attacks or fraud.

What counts as abuse

Every hosting provider, e-mail service and cloud platform has an acceptable use policy. Activity that breaks it and harms others is called abuse. Typical examples:

  • sending spam or phishing e-mails;
  • hosting malware, phishing pages or stolen data;
  • scanning, brute-forcing or DDoS attacks launched from rented servers or hijacked zombie computers;
  • copyright infringement and fraud;
  • abusing legitimate features: free trials for crypto mining, API keys for scraping, or built-in admin tools for attacks (“living off the land”).

Abuse contacts and reports

Networks publish an abuse contact so that victims can report problems. By convention (RFC 2142) it is the mailbox abuse@domain; regional internet registries (RIPE NCC, ARIN and others) record an abuse-c contact for every IP range, which you can find with a whois lookup. A good report includes timestamps with time zone, source IP addresses, log excerpts and e-mail headers. Providers that ignore reports end up on blocklists, and their whole IP ranges can be blocked by mail servers and firewalls.

Why it matters for security

Abuse handling is one of the few ways to take down attacker infrastructure quickly. For defenders, it also works the other way round: if your server or cloud account is compromised, the first sign is often an abuse complaint from your provider. Such messages should be treated as a security incident, not as spam.

Best practices

  • Publish and monitor an abuse@ mailbox and your RIR abuse contact.
  • Rate-limit and monitor outgoing mail, API usage and new cloud resources.
  • Report phishing and malware hosting to the provider shown by whois.