ANSI - American National Standards Institute
 Print this article  Previous Next 

ANSI Members Hit With E-Mail Spam

Institute Takes Immediate Action

New York, Sep 30, 2004

The American National Standards Institute (ANSI) and its members were hit with a “spam” attack that generated dozens of bogus e-mail messages for a number of its constituents. The Institute has taken immediate action to eliminate the problem and extends sincere apologies for the inconvenience experienced by its members.

The infiltration of ANSI's electronic mail system affected an e-mail reflector that had been established to facilitate communications to and from all members. The reflector was established during the launch of ANSI Online on January 2, 2003, and followed the two-way dialogue parameters that had been established for several other boards and councils. The reflector was turned off immediately upon ANSI’s notification of the spam problem; some volume of e-mail traffic continued throughout this morning for messages that were already in the pipeline.

"Our investigation of the traffic found that the spam originated from the e-mail server of a member on the distribution list, not from within the Institute’s own e-mail system," explained Bob Feghali, ANSI vice president and chief information officer. "The 'spoof' virus -- one of a relatively new breed of Internet viruses -- infected the address book of the host, generating a message to the contacts in that host’s e-mail address book."

When the first "spoof" message was sent to ANSI’s reflector list, the Institute’s e-mail server rebroadcast the message to all recipients. The servers of some e-mail recipients caught the spam immediately and generated a rejection notice; many of these rejection notices were then bounced back and rebroadcast to the entire list.

"None of the individual e-mail addresses on the reflector list were compromised – this is because the traffic was being continually routed through ANSI's server and not via embedded e-mail addresses," explained Feghali. "Now that the reflector has been turned off for two-way distribution, this e-mail traffic will stop."

ANSI’s customer service and membership support teams are responding to all inquiries received via telephone and e-mail. The Institute is also investigating its Internet usage policies with a view towards enhanced protection for its members while also providing the appropriate vehicle(s) for communication between and among member groups.

Related articles:

Microsoft and the FTC Agree: Standards Would Bolster Anti-spam Legislation
New York July 14, 2003

FTC Forum to Explore Potential Answers to Spam
Standards group looks to technical solutions

New York May 1, 2003