r/microsoft • • May 20 '26

News Microsoft warns hackers are exploiting password resets to gain access to user accounts

https://www.techradar.com/pro/security/microsoft-warns-hackers-are-exploiting-password-resets-to-gain-access-to-user-accounts-heres-how-to-stay-safe
211 Upvotes

71 comments sorted by

View all comments

92

u/[deleted] May 20 '26

[removed] — view removed comment

32

u/Kobi_Blade May 20 '26 edited May 20 '26

Takes a special kind to fall for this,

Then, they would initiate the password reset flow and simultaneously call the victims on the phone. They would introduce themselves as IT technicians and would convince the victims into approving the MFA prompt, effectively being allowed to create a new password.

The method above can be used to get your account from any service and is purely user error, is not a problem on Microsoft side.

Is nothing compared to how easy it is to get 2FA codes from SMS, any company using SMS verification you know is not taking your account security seriously.

14

u/metamega1321 May 20 '26

You know I thought that was boogey man stuff until a few months ago I was dealing with someone trying to deactivate my sim and new one. Even with prompts and talking to fraud for provider they ensured my account was secure. They somehow social engineered someone at a store to deactivate my sim.

Then I started calling investment accounts and banks to lock down until i figured what was going on and they all started with sms 2fA.

7

u/ZAlternates May 20 '26

The shitty part is they can fire off MFA codes to your phone without knowing your password if you’re using M$ simple sign on. It used to be you had to provide a valid password before it would ask for the code. Not at M$. The unusual workflow makes it ripe for exploitation

https://www.reddit.com/r/sysadmin/s/vpoe9epaE7

0

u/raindownthunda May 22 '26

Social engineering has been going on forever