Hackers Spied on Microsoft Email Accounts Via Compromised Admin Login

It’s possible some unknown group of hackers has been looking at your Microsoft email. Microsoft has cautioned users of Outlook, MSN, and Hotmail email accounts that unidentified individuals gained access to an internal customer support account. That allowed them to view data in a large number of user accounts. The issue has been corrected, but it’s not clear how long the breach went undetected or exactly what the attackers could see.
A source reached out to Motherboard several weeks ago with information about the breach, claiming that they’d accessed customer emails via leaked credentials for the Microsoft customer support portal. Microsoft later confirmed the breach in email warning sent out to users and provided some details to TechCrunch.
There is some disagreement over the severity. Everyone agrees that the support account gave hackers access to the subject lines, email history, and contacts for consumer accounts. Corporate accounts were not affected, but the damage for consumers extended to some Microsoft profile information including birth dates, mailbox folder names and stats, login history, and some calendar data. Microsoft says the hackers had access to the support portal for about three months, from January to March of this year. It says about 6 percent of customer accounts were exposed in the breach, but your password isn’t affected. Still, Microsoft recommends changing it out of an abundance of caution. If you have any doubt, check Have I Been Pwned.

According to Motherboard’s source, hackers may have had access to the body of emails as well. The source claims the compromised employee login came from a “high privileged” individual who had access to more data. As proof, they submitted a screen in the support portal with an “Email Body” field and redacted text. In addition, the source claims hackers had access to this account for more than six months, twice as long as Microsoft claims.
Regardless of exactly what data was exposed and for how long, Microsoft email users should take some precautions. At a bare minimum, access to your email history and contacts would make it vastly easier to concoct a convincing phishing email. At worst, the attackers may have gotten email bodies that contain sensitive information. Microsoft says it disabled the offending account, but it didn’t explain how it became compromised in the first place.
Continue reading

Star Citizen Developer Unveils New Roadmap, Cancels Squadron 42 Beta
Cloud Imperium Games has canceled the Squadron 42 beta that was supposed to debut before the end of 2020, with no current plan or timeline for launching it.

The Biden Administration Pledges to Address the Semiconductor Shortage
Early on Thursday, a group of US chip designers and manufacturers sent a letter to the White House, asking that the government include “substantial funding for incentives for semiconductor manufacturing” as part of the overall COVID-19 economic recovery plan. The Biden Administration has now pledged to take action to help remedy the situation by “identifying…

The US Air Force Quietly Admits the F-35 Is a Failure
The Air Force has finally admitted that the F-35 is not the aircraft the military hoped it would be, though we doubt Ferrari would appreciate being compared with the F-35.

Microsoft Admits Some Bethesda Games Will Be Xbox Exclusives
Microsoft has admitted that at least some Bethesda games will be Xbox and PC exclusives.