Hackers Spied on Microsoft Email Accounts Via Compromised Admin Login

Hackers Spied on Microsoft Email Accounts Via Compromised Admin Login

It’s possible some unknown group of hackers has been looking at your Microsoft email. Microsoft has cautioned users of Outlook, MSN, and Hotmail email accounts that unidentified individuals gained access to an internal customer support account. That allowed them to view data in a large number of user accounts. The issue has been corrected, but it’s not clear how long the breach went undetected or exactly what the attackers could see.

A source reached out to Motherboard several weeks ago with information about the breach, claiming that they’d accessed customer emails via leaked credentials for the Microsoft customer support portal. Microsoft later confirmed the breach in email warning sent out to users and provided some details to TechCrunch.

There is some disagreement over the severity. Everyone agrees that the support account gave hackers access to the subject lines, email history, and contacts for consumer accounts. Corporate accounts were not affected, but the damage for consumers extended to some Microsoft profile information including birth dates, mailbox folder names and stats, login history, and some calendar data. Microsoft says the hackers had access to the support portal for about three months, from January to March of this year. It says about 6 percent of customer accounts were exposed in the breach, but your password isn’t affected. Still, Microsoft recommends changing it out of an abundance of caution. If you have any doubt, check Have I Been Pwned.

The Microsoft support email, via /u/Keats852 on Reddit.
The Microsoft support email, via /u/Keats852 on Reddit.

According to Motherboard’s source, hackers may have had access to the body of emails as well. The source claims the compromised employee login came from a “high privileged” individual who had access to more data. As proof, they submitted a screen in the support portal with an “Email Body” field and redacted text. In addition, the source claims hackers had access to this account for more than six months, twice as long as Microsoft claims.

Regardless of exactly what data was exposed and for how long, Microsoft email users should take some precautions. At a bare minimum, access to your email history and contacts would make it vastly easier to concoct a convincing phishing email. At worst, the attackers may have gotten email bodies that contain sensitive information. Microsoft says it disabled the offending account, but it didn’t explain how it became compromised in the first place.

Continue reading

Xbox Series X Launch Is Microsoft’s Biggest Ever, Causes ISP Traffic Spike
Xbox Series X Launch Is Microsoft’s Biggest Ever, Causes ISP Traffic Spike

Microsoft claims the Xbox Series X is its most successful debut in history and specifically calls out the Xbox Series S for bringing new players into the fold.

ET Deals: Dell Inspiron 15 5000 Intel Core i7-1165G7 Laptop for $674, iRobot Roomba i7+ 7550 Robot Vacuum for $599
ET Deals: Dell Inspiron 15 5000 Intel Core i7-1165G7 Laptop for $674, iRobot Roomba i7+ 7550 Robot Vacuum for $599

Today you can take advantage of a 10 percent discount to snag a Dell Inspiron 15 5000 laptop with an Intel Core i7-1165G7 processor, 12GB of RAM and a 512GB NVMe SSD for just $674. You can also get iRobot's Roomba i7+ robot vacuum for just $599.00, which is the same price it was on Cyber Monday.

Earth Is Spinning Faster After Decades of Slowing Down
Earth Is Spinning Faster After Decades of Slowing Down

Earth isn't a clock, and the actual length of a day can vary slightly. Scientists now say that the days have started trending shorter because the Earth is spinning faster, which could require potentially confusing adjustments.

Despite Reports, Sony Probably Isn’t Losing Money on Every PlayStation 5
Despite Reports, Sony Probably Isn’t Losing Money on Every PlayStation 5

Sony reported a strong overall quarter this year, with 4.5M PlayStation 5 consoles shipped. Despite some reports, the company is unlikely to be losing money on every PS5 it sells.