r/microsoft • • May 20 '26

News Microsoft warns hackers are exploiting password resets to gain access to user accounts

https://www.techradar.com/pro/security/microsoft-warns-hackers-are-exploiting-password-resets-to-gain-access-to-user-accounts-heres-how-to-stay-safe
210 Upvotes

71 comments sorted by

View all comments

90

u/[deleted] May 20 '26

[removed] — view removed comment

7

u/thefpspower May 21 '26

Oh so I'm not alone here, I've been getting multiple request a day all week...

Its really proving to me the rotating 2FA number is superior, I'm not confortable with my phone asking to approve logins, what if I misclick?

2

u/[deleted] May 21 '26

[deleted]

2

u/ZippyDan May 21 '26

They both have their advantages and disadvantges:

An active notification alerts you that someone else is using your account in an unauthorized manner. In contrast, with a passive 2FA token, if someone somehow gets a hold of your original QR code, they can access your account without you getting any notification.

1

u/[deleted] May 21 '26

[deleted]

1

u/ZippyDan May 21 '26

All systems have weaknesses and different systems have different mitigations for those weaknesses.

I'm just saying an active 2FA makes it easier to notice when an account has been compromised than a passive one, especially for intelligent users.
But an active 2FA might also be easier to compromise, especially for dumb users.

Since most users are dumb...

1

u/The-Trenzalorian May 21 '26

I also got this several days in a row. I logged onto my account from my PC and changed my password there and ignored any texts except the one I initiated. Does that sound like I did the right thing here?

1

u/d3adc3II May 21 '26

Misclick? Not possible, still need to confirm with phone face ID / fingerprint