Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 PSA: Check your Microsoft account recent activity, My Microsoft account security breached

views
     
TSSycamore
post Dec 9 2024, 01:55 PM, updated 2y ago

Casual
***
Junior Member
334 posts

Joined: Jun 2015
From: underneath the grove of sycamore
Security breached 1 hour ago.
Received email from Microsoft about 'unusual sign-in', went to check 'recent activity'.
Holy moly.

user posted image

user posted image

They have been doing this for one month, on and off.
Account breached on 19th attempt.
Strange Microsoft did not send email to inform me earlier. :x

Changed my password. Turned on 2FA.

Still in after-shock, thinking how big the impact will be.
I think the 'secret' I stored in OneNote is compromised now.
Not sure what is yet to come.
a13solut3
post Dec 9 2024, 02:16 PM

Whiner FTW!
******
Senior Member
1,759 posts

Joined: Mar 2007
From: _|_

very common.

just set another alias and disable your main alias. otherwise you will still get relentless sign in attempt.
Lanchio
post Dec 9 2024, 04:45 PM

Casual
***
Junior Member
487 posts

Joined: Sep 2006
Thanks for the heads up.

arkasi
post Dec 9 2024, 05:05 PM

Getting Started
**
Junior Member
93 posts

Joined: Oct 2010


Always turn on 2FA, doesn't matter if it's Microsoft or Google email. Too many brute force password attempts by hackers nowadays.

I think it started almost bout 3 years ago where i noticed Microsoft account suddenly have a lot of unsuccessful sign ins practically nonstop. Before that, it was once in a while. Decided to turn on 2FA then as don't want to take risk.

Unfortunately, Microsoft won't alert you to unsuccessful sign in as they consider it no harm done.
annoymous1234
post Dec 9 2024, 05:14 PM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

Make password at least 14 characters long, must turn on 2FA, and use alias

This post has been edited by annoymous1234: Dec 9 2024, 05:15 PM
Sichiri
post Dec 9 2024, 05:15 PM

Regular
******
Senior Member
1,192 posts

Joined: Jan 2003
From: Kepong, Kuala Lumpur, Malaysia.


work or personal Msoft account?

My work Microsoft account is secured to the max.
AbbyCom
post Dec 9 2024, 05:19 PM

Casual
***
Junior Member
456 posts

Joined: Mar 2020
I also kena last month, macam breached but that was old work email that I no longer use. Suddenly my MS Mail got notification that unusual account activity.

Another MS account also kena, that was my Windows Login account, turned on 2FA.
failed.hashcheck
post Dec 9 2024, 05:34 PM

Neighborhood plant pathologist
*******
Senior Member
2,096 posts

Joined: Aug 2009
From: Shithole Klang
The uncessful login is normal. It happens to any account by hundreds every day. It just showing your password is working (until it isn't).
Its only alarming because MS account logged the event.
Google didn't do this and only start freaking out on 2fa stage failure.

This post has been edited by failed.hashcheck: Dec 9 2024, 05:34 PM
Chanwsan
post Dec 9 2024, 06:11 PM

सोहम
******
Senior Member
1,406 posts

Joined: Dec 2004
From: Living Hell


Already seeing this brute force shit ages ago. Already got 2FA authenticator so I wouldn't be too worried
Lucas0323
post Dec 9 2024, 07:16 PM

Enthusiast
*****
Junior Member
808 posts

Joined: Aug 2011


Ts ada harom stuff till become target.

Edit: Fuh I got alot attemp too it seems bt microsoft message is this kek.

Thanks for telling us
Don’t worry. This sign-in attempt was unsuccessful, so there is no need to change your password. Learn how to make your account more secure

This post has been edited by Lucas0323: Dec 9 2024, 07:27 PM
ieatchickens
post Dec 9 2024, 08:06 PM

Getting Started
**
Junior Member
111 posts

Joined: Apr 2011
From: kuala lumpur


now open google timeline smile.gif
langstrasse
post Dec 9 2024, 08:19 PM

~ Have a Vice day ~
******
Senior Member
1,589 posts

Joined: Oct 2010
QUOTE(annoymous1234 @ Dec 9 2024, 05:14 PM)
Make password at least 14 characters long, must turn on 2FA, and use alias
*
What does the alias part mean ?

Don’t use “name.surname” type of email format?
knwong
post Dec 9 2024, 08:26 PM

Look at all my stars!!
*******
Senior Member
3,562 posts

Joined: Sep 2005
From: Shenzhen Bahru


What secret you put in OneNote?
annoymous1234
post Dec 9 2024, 08:48 PM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

QUOTE(langstrasse @ Dec 9 2024, 08:19 PM)
What does the alias part mean ?

Don’t use “name.surname” type of email format?
*
No. It means login using an alternate email, for example, ur email is abc@outlook.com, u create another email abcd@outlook.com as an alias, and set this as primary email. Then in the future, every time when u login, u can only use abcd@outlook.com to login, if u try to use ur actual email, u will get email not exist. However, ur actual email is still active, just that when someone use ur email want to login, it will say email doesn't exist.
shadowglow
post Dec 9 2024, 09:24 PM

Casual
***
Junior Member
462 posts

Joined: Aug 2006
From: Ampang


QUOTE(a13solut3 @ Dec 9 2024, 02:16 PM)
very common.

just set another alias and disable your main alias. otherwise you will still get relentless sign in attempt.
*
What u mean disable main alias?
shadowglow
post Dec 9 2024, 09:25 PM

Casual
***
Junior Member
462 posts

Joined: Aug 2006
From: Ampang


QUOTE(annoymous1234 @ Dec 9 2024, 08:48 PM)
No. It means login using an alternate email, for example, ur email is abc@outlook.com, u create another email abcd@outlook.com as an alias, and set this as primary email. Then in the future, every time when u login, u can only use abcd@outlook.com to login, if u try to use ur actual email, u will get email not exist. However, ur actual email is still active, just that when someone use ur email want to login, it will say email doesn't exist.
*
Then.. How u wanna login to check the main email? Everytime switch main email to the initial n switch back before logout?

What's wrong with using authenticator?
smallgiant
post Dec 9 2024, 09:32 PM

New Member
*
Junior Member
49 posts

Joined: Feb 2015
one unsuccessful sign in from Mexico yesterday wtf?
annoymous1234
post Dec 9 2024, 09:36 PM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

QUOTE(shadowglow @ Dec 9 2024, 09:25 PM)
Then.. How u wanna login to check the main email? Everytime switch main email to the initial n switch back before logout?

What's wrong with using authenticator?
*
U use the alias to login, it connects to ur main email.
Think about it this way, when someone wants to login ur email, they will first enter ur email, then guess ur password, correct?

Now with alias, when they enter ur main email, it will say email doesn't exist, which means they can't even proceed to the next step, which is to guess ur password.

Authenticator is another additional security steps.
That's why using alias plus 2FA and u are already well protected.

This post has been edited by annoymous1234: Dec 9 2024, 09:38 PM
Rusty Nail
post Dec 9 2024, 10:02 PM

Why am I still here?
*******
Senior Member
4,883 posts

Joined: Jan 2003
From: Petaling Jaya



yeah here

lucky i had 2FA setup log time ago. but all the breach seems to be wrong passwords. probably from leaked password in haveibeenpwn
a13solut3
post Dec 9 2024, 10:03 PM

Whiner FTW!
******
Senior Member
1,759 posts

Joined: Mar 2007
From: _|_

QUOTE(shadowglow @ Dec 9 2024, 09:25 PM)
Then.. How u wanna login to check the main email? Everytime switch main email to the initial n switch back before logout?

What's wrong with using authenticator?
*
You use 'different' email to sign in, but at a same time, your main email address is still the same.

So like now your main email sign in is abc@outlook.com.

But you sign in with xyz@outlook.my.

Nobody will ever know your xyz@outlook.my as you will still use abc@outlook.com as correspondent email.

Authenticator prevent breach but it doesn't prevent your account getting locked by too much failure attempt.

This post has been edited by a13solut3: Dec 9 2024, 10:03 PM

2 Pages  1 2 >Top
 

Change to:
| Lo-Fi Version
0.0231sec    0.47    5 queries    GZIP Disabled
Time is now: 15th December 2025 - 06:37 PM