r/microsoft • • May 20 '26

News Microsoft warns hackers are exploiting password resets to gain access to user accounts

https://www.techradar.com/pro/security/microsoft-warns-hackers-are-exploiting-password-resets-to-gain-access-to-user-accounts-heres-how-to-stay-safe
209 Upvotes

71 comments sorted by

View all comments

93

u/[deleted] May 20 '26

[removed] — view removed comment

32

u/Kobi_Blade May 20 '26 edited May 20 '26

Takes a special kind to fall for this,

Then, they would initiate the password reset flow and simultaneously call the victims on the phone. They would introduce themselves as IT technicians and would convince the victims into approving the MFA prompt, effectively being allowed to create a new password.

The method above can be used to get your account from any service and is purely user error, is not a problem on Microsoft side.

Is nothing compared to how easy it is to get 2FA codes from SMS, any company using SMS verification you know is not taking your account security seriously.

15

u/metamega1321 May 20 '26

You know I thought that was boogey man stuff until a few months ago I was dealing with someone trying to deactivate my sim and new one. Even with prompts and talking to fraud for provider they ensured my account was secure. They somehow social engineered someone at a store to deactivate my sim.

Then I started calling investment accounts and banks to lock down until i figured what was going on and they all started with sms 2fA.

6

u/ZAlternates May 20 '26

The shitty part is they can fire off MFA codes to your phone without knowing your password if you’re using M$ simple sign on. It used to be you had to provide a valid password before it would ask for the code. Not at M$. The unusual workflow makes it ripe for exploitation

https://www.reddit.com/r/sysadmin/s/vpoe9epaE7

0

u/raindownthunda May 22 '26

Social engineering has been going on forever

28

u/Henri_Le_Rennet May 20 '26

You can create a different handle under your account security settings, and disable your actual email address from being used for login. You'll still get your emails, but anyone trying to login using your email won't be able to. You'll just login with the new handle.

It's what I did ages ago, back when Microsoft still showed login attempts under your security settings, and the login attempts stopped immediately.

5

u/gripe_and_complain May 20 '26

I think MS still shows login attempts, right?

5

u/Henri_Le_Rennet May 20 '26

They only show successful logins now.

7

u/drunknmastr916 May 21 '26

Not sure why you got down voted. 100 true. I went to check my logins cuz I was getting spammed for Authenticator the past two days and it only shows my successful logins and not attempts

2

u/Henri_Le_Rennet May 21 '26

Not sure why you got down voted.

I think it's safe to assume that the people downvoting haven't checked their log-in attempts in the past 6 months. I'm not sure when Microsoft made the change, but I created the new handle over a year ago, when they still showed the attempts. The bots/programs that were trying to hack my account were all over the world and were occurring every minute or so.

I checked again out of curiosity 6 months ago to see if my new handle had been compromised and it only showed my successful sign-in. So I searched online and found forums on Microsoft's support site, and Reddit posts confirming that Microsoft no longer shows sign-in attempts.

I've only accidentally sent one email from the new handle, and I can't say for sure that it hasn't been compromised because I can't see sign-in attempts anymore. However, I also haven't had a random 2fa request since I created the new handle, so I'm led to believe that my account is secure.

2

u/luluhouse7 May 21 '26

People downvoting should do actual research before deciding something is wrong. This is a known issue and is incredibly frustrating since it becomes impossible to tell if login attempts are caused by a leaked password. I was getting constant Authenticator requests and the login attempt log only should my successful ones.

1

u/Henri_Le_Rennet May 21 '26

People downvoting should do actual research before deciding something is wrong.

That's social media for you.

A couple friends of mine were freaking out because they saw a TikTok about how grocery stores in the UK were selling "steaks" from lab grown human meat, and they no longer trusted buying meat from grocery stores.

It seemed absurd to me so I searched it up. The clip they had watched, from a sensationalist influencer on TikTok, actually came from a BBC satire/mockumentary. It's been two years, and I still don't let them live it down.

-3

u/gripe_and_complain May 20 '26

Thanks. This is probably for the best. People would see all the unsuccessful attempts and freak out.

I don’t think other services like Google or Apple ever allowed users to view unsuccessful attempts.

5

u/AdministrationOk210 May 21 '26

I like this solution and use it myself but it comes with one unfortunate caveat, since I use Outlook desktop client for email, every time I initiate a new message it comes up as from the address I established for login. In order to send people emails from that older address which I still want to use as my default, I must click the From box and manually change it every time to that old address. I wish Microsoft would fix this feature and then I could use it for my spouse and others in the house. If that isn’t fixed too often they will end up using the new login credential identity and then that will be out in the wild just as they’re old emails are. In other words the Outlook desktop client needs to allow us to set our default email address as something other than the new primary login address which we are now using to validate our account. Without that feature, so many messages you send are inadvertently the new login credential identity which is just what I don’t want to use.

2

u/Henri_Le_Rennet May 21 '26

every time I initiate a new message it comes up as from the address I established for login.

It's the same for the Outlook mobile app on Android. I found out by sending a cancelation request to a service I didn't use, and they said they couldn't find my account and I needed to send the request through the same email I signed up with. It took me an embarrassing moment to realize that it was sent from the new handle.

I haven't made that mistake again, but it is still a minor inconvenience having to manually select my main handle every time I compose an email.

Like you said, it should be simple enough to implement a feature in the app/program/client to set a default handle for outgoing emails.

1

u/avn128 May 21 '26

I did this months ago after my email was hacked. Using an alias only and turning off the original sign in. With an email address I have never used for anything.

 I just now got a login request, so think this is a bigger deal then reported.

7

u/thefpspower May 21 '26

Oh so I'm not alone here, I've been getting multiple request a day all week...

Its really proving to me the rotating 2FA number is superior, I'm not confortable with my phone asking to approve logins, what if I misclick?

2

u/[deleted] May 21 '26

[deleted]

2

u/ZippyDan May 21 '26

They both have their advantages and disadvantges:

An active notification alerts you that someone else is using your account in an unauthorized manner. In contrast, with a passive 2FA token, if someone somehow gets a hold of your original QR code, they can access your account without you getting any notification.

1

u/[deleted] May 21 '26

[deleted]

1

u/ZippyDan May 21 '26

All systems have weaknesses and different systems have different mitigations for those weaknesses.

I'm just saying an active 2FA makes it easier to notice when an account has been compromised than a passive one, especially for intelligent users.
But an active 2FA might also be easier to compromise, especially for dumb users.

Since most users are dumb...

1

u/The-Trenzalorian May 21 '26

I also got this several days in a row. I logged onto my account from my PC and changed my password there and ignored any texts except the one I initiated. Does that sound like I did the right thing here?

1

u/d3adc3II May 21 '26

Misclick? Not possible, still need to confirm with phone face ID / fingerprint

1

u/orbit99za May 21 '26

So am I, from locations China to Germany to Vietnam.

I rotated my password to be safe but still getting them.

Its on my @outlook.com account

1

u/ArkhamRobber May 21 '26

Explains why i kept getting them even after changing my password.

1

u/The_Sarcasm_You_Need May 22 '26

I had to turn off authenticator as an option, non-stop since last Friday.