Hackers Spied on Microsoft Email Accounts Via Compromised Admin Login

It’s possible some unknown group of hackers has been looking at your Microsoft email. Microsoft has cautioned users of Outlook, MSN, and Hotmail email accounts that unidentified individuals gained access to an internal customer support account. That allowed them to view data in a large number of user accounts. The issue has been corrected, but it’s not clear how long the breach went undetected or exactly what the attackers could see.
A source reached out to Motherboard several weeks ago with information about the breach, claiming that they’d accessed customer emails via leaked credentials for the Microsoft customer support portal. Microsoft later confirmed the breach in email warning sent out to users and provided some details to TechCrunch.
There is some disagreement over the severity. Everyone agrees that the support account gave hackers access to the subject lines, email history, and contacts for consumer accounts. Corporate accounts were not affected, but the damage for consumers extended to some Microsoft profile information including birth dates, mailbox folder names and stats, login history, and some calendar data. Microsoft says the hackers had access to the support portal for about three months, from January to March of this year. It says about 6 percent of customer accounts were exposed in the breach, but your password isn’t affected. Still, Microsoft recommends changing it out of an abundance of caution. If you have any doubt, check Have I Been Pwned.

According to Motherboard’s source, hackers may have had access to the body of emails as well. The source claims the compromised employee login came from a “high privileged” individual who had access to more data. As proof, they submitted a screen in the support portal with an “Email Body” field and redacted text. In addition, the source claims hackers had access to this account for more than six months, twice as long as Microsoft claims.
Regardless of exactly what data was exposed and for how long, Microsoft email users should take some precautions. At a bare minimum, access to your email history and contacts would make it vastly easier to concoct a convincing phishing email. At worst, the attackers may have gotten email bodies that contain sensitive information. Microsoft says it disabled the offending account, but it didn’t explain how it became compromised in the first place.
Continue reading

VIA Technologies, Zhaoxin Strengthen x86 CPU Development Ties
VIA and Zhaoxin are deepening their strategic partnership with additional IP transfers, intended to accelerate long-term product development.

EKWB Launches Peltier Cooler Powered by Intel Cryo Cooling Technology
Intel and EKWB have jointly announced a new waterblock that integrates a Peltier cooler.

Cyberpunked 2077: CDPR ‘Apologizes’ For Releasing Broken Game, Offers Refunds
Cyberpunk 2077's PS4 and Xbox One S version is so bad, the company is now offering refunds. We recommend last-gen console gamers take them up on it, rather than waiting.

Harvard Astronomer Still Believes Interstellar Object Was Alien Technology
Scientists have classified 'Oumuamua variously as an asteroid or a comet, but Avi Loeb, the chair of Harvard's Department of Astronomy, believes it was really alien — a piece of alien technology we mistook for a naturally occurring space rock.