Hackers Access Microsoft Email Accounts

Microsoft has confirmed that hackers targeted an unspecified number of users’ online email accounts across Outlook, Hotmail and MSN services for a period of three months after hacking a customer support account.

The incident took place after hackers compromised the login credentials of a technical support representative, and lasted from 1 January to 28 March of this year, Microsoft said.

The credentials gave the hackers access to some customers email information, including subject lines, identities of email recipients and the names of folders.

“The content of any emails or attachments” were not affected, nor were passwords, Microsoft said in an email sent to users.

Email access

“Upon awareness of this issue, Microsoft immediately disabled the compromised credentials, prohibiting their use for any further unauthorized access,” Microsoft said in the email.

The company said it didn’t know why the hack occurred but warned users that they “may receive phishing emails or other spam mails” as a result.

While login credentials weren’t affected, Microsoft advised users to reset their passwords as a precautionary measure.

However, website Motherboard cited an unnamed source as saying that the hackers were able to access more data on some users, including the contents of emails.

Motherboard’s report said the hackers had been able to access more data on users with free accounts, while access was more limited for those with paid or enterprise accounts.

Microsoft confirmed the report, saying the additional data access affected a subset of those affected, about 6 percent.  It said those users had also been notified.

Compromise

“We addressed this scheme, which affected a limited subset of consumer accounts, by disabling the compromised credentials and blocking the perpetrators’ access,” Microsoft said in a statement.

The company didn’t specify how many users were affected overall.

Microsoft didn’t indicate where the affected users were located, but included contact information for its EU data protection officer in the email to users, suggesting at least some of them were based in Europe.

“Microsoft regrets any inconvenience caused by this issue,” Microsoft said in the email.

The incident follows one of the biggest data breaches ever uncovered, when a security researcher in January uncovered a trove of some 773 million email addresses and passwords from multiple providers.

The credentials had been posted to a popular hacking forum in mid-December.

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Meta Declines On Heavy AI Spending Plans, Despite Strong Q1

Share price hit after Meta admits heavy AI spending plans, after posting strong first quarter…

12 hours ago

Google Delays Removal Of Third-Party Cookies, Again

For third time Google delays phase-out of third-party Chrome cookies after pushback from industry and…

13 hours ago

Tesla Posts Biggest Revenue Drop Since 2012

Elon Musk firm touts cheaper EV models, as profits slump over 50 percent in the…

14 hours ago

Apple iPhone Q1 Sales In China Fall 19 Percent, Says Counterpoint

Bad news for Tim Cook, as Counterpoint records 19 percent fall in iPhone sales in…

17 hours ago

President Biden Signs TikTok Ban Or Divest Bill Into Law

TikTok pledges to challenge 'unconstitutional' US ban in the courts, after President Joe Biden signs…

19 hours ago