Jump to content

Recommended Posts

Posted

This is not a joke! Change your Hotmail Passwords and Security Questions Immediately!

 

Neowin has received information regarding a possible Windows Live Hotmail "hack" or phishing scheme where password details of thousands of Hotmail accounts have been posted online.

 

An anonymous user posted details of the accounts on October 1 at pastebin.com, a site commonly used by developers to share code snippets. The details have since been removed but Neowin has seen part of the list posted and can confirm the accounts are genuine and most appear to be based in Europe. The list details over 10,000 accounts starting from A through to B, suggesting there could be additional lists. Currently it appears only accounts used to access Microsoft's Windows Live Hotmail have been posted, this includes @hotmail.com, @msn.com and @live.com accounts.

 

Neowin has reported this immediately to Microsoft's Security Response Center and to Microsoft's PR teams in the UK and US and we are currently awaiting feedback on the situation. As this is a breaking story please check back frequently as the story will be updated as soon as more information becomes available.

 

If you are a Windows Live Hotmail user Neowin recommends that you change your password and security question immediately.

 

Thanks to Chris for the news tip

 

Update: According to BBC News, Microsoft is currently "investigating the situation and will take appropriate steps as rapidly as possible."

 

More Information:

Thousands of Hotmail passwords leaked online

BBC NEWS | Technology | Hotmail accounts 'posted online'

Hotmail Password Hacking: Microsoft Investigating Claims Details Of Thousands Of Accounts Put Online | Technology | Sky News

Posted
I was under the impression they were phished rather than hacked but I've changed mine as a precaution anyway.
Posted

Since Hotmail doesn't store passwords as clear text even if they were harvested they wouldn't be much use also if they aren't stored as clear text then they can't be leaked.

I suspect it will be a list collected with key loggers or duping users to log into fake hotmail sites or "muppets" who logon to their webmail through proxy anonymizers.

Posted

Hashes can be cracked... :-)

 

Phished through proxy websites is probably the most likely scenario, I doubt MS has any SQLI on that side of things.

 

Had to send an e-mail out to staff, I think we've had one teacher who has been a victim.

Posted (edited)
Hashes can be cracked... :-)

 

Well yes of course but if it was non reversible encryption it would take some time to crack several million passwords assuming they're good passwords of course ;)

 

It would be nice if hotmail would at least force an annual password change.

Edited by cookie_monster
Posted
Hashes can be cracked... :-)

 

Phished through proxy websites is probably the most likely scenario, I doubt MS has any SQLI on that side of things.

 

Yeah cracking the passwords just wouldn't be worth the amount of time it would take :bowl:

Posted

@painejake ... If someone had found a leak it would be TOTALLY worth attempting to crack the hash! In terms of a naughty chappy they could pretty much guarantee a load of access to PayPal accounts, FaceBooks, dim people who save passwords in there mailboxes, potentially several million extra people to spam through address books!

 

... besides the fact you'd get one over on Microsoft, it would be all over the IT news websites and for any 'hacker' this would be the ultimate exposure!

Posted
If you had the hashes it wouldn't take much "cracking" - more like comparing it to a table of known hashes. Of course this wouldn't work for good passwords but most are atrocious.
Posted

I once had my Hotmail hacked, I have no idea how. I had a very random and secure password, never been phished or even used a proxy to access. It was a targetted hack tho as they wanted my old dormant WOW account.

 

Weird.

Posted

I've had the same hotmail account for centuries now. I was one of the originals with a common-ish name without any numbers!

 

I always ignore emails from MSN/Hotmail/Live anyway. I had a spurt of password change requests. As a rule, I only view mail that I know the sender of. The rest are deleted/junked.

Posted
I've just changed my password for my PassPort account............logged into my MSN this morning too find my status name was different!! :lie:
Posted

We have been contacted by Microsoft (well someone from a MS Press office) regarding this and they have asked us to post the following info to you in case its needed by anyone.

We are aware that some Windows Live Hotmail customers’ credentials were acquired illegally by a phishing scheme and exposed on a website. Upon learning of the issue, we immediately requested that the credentials be removed and launched an investigation. As part of that investigation, we determined that this is not a breach of any Microsoft servers. Subsequently we are taking measures to block access to all of the accounts that were exposed and have resources in place to help those users reclaim their accounts.

 

If users believe their information was documented on the illegal list, users should fill out the following form to reclaim access to their account. Phishing is an industry-wide problem and Microsoft is committed to helping consumers have a safe, secure and positive online experience. General information on what to do if you believe you have been victimized via a phishing scam is available on this page at our support community.

 

Additional Points

Phishing is an industry-wide problem and Microsoft is committed to helping consumers have a safe, secure and positive online experience. Our guidance to customers is to exercise extreme caution when opening unsolicited attachments and links from both known and unknown sources, and that they install and regularly update their anti-virus software.

 

Microsoft recommends customers use the following protective security measures:

  • Renew their passwords for Windows Live IDs every 90 days
  • For administrators, make sure you approve and authenticate only users that you know and can verify credentials
  • As phishing sites can also pose additional threats, install and keep anti-virus software up to date

 

I am glad to see Microsoft trying to get the information out there for people not in the know (like a lot of *staff*) so feel free to pass it on to your staff. You could even mention that MS do free av now at http://www.microsoft.com/security_essentials/ (no MS did not ask me to put this in before asking) and its getting good writeups as far as I have seen and anything is better then AVG free ;)

Posted

Scam hits more e-mail accounts

 

More than 20,000 e-mail addresses have been seen by the BBC.

The scale of a phishing attack originally thought to be directed at Hotmail may be larger than previously thought.

BBC News has seen a list of more than 20,000 more names and passwords that have been posted online.

The list contains e-mail addresses and passwords from Hotmail, Yahoo, AOL, Gmail and other service providers.

The list was published on the same website as the original list of 10,000 Hotmail login details.

Some of the accounts appear to be old, unused or fake. However, BBC News has confirmed that many - including Gmail and Hotmail addresses - are genuine.

Other addresses include Comcast and Earthlink accounts.

It is not clear whether the list was part of the same phishing attack that collected the Hotmail addresses or a separate scam.

Phishing involves using fake websites to lure people into revealing details such as bank account details or login names.

A spokesperson for Microsoft said phishing was an "industry-wide problem".

 

Link to full article: BBC NEWS | Technology | Scam hits more e-mail accounts

Posted
We have been contacted by Microsoft (well someone from a MS Press office) regarding this and they have asked us to post the following info to you in case its needed by anyone.

 

If users believe their information was documented on the illegal list, users should fill out the following form to reclaim access to their account. Phishing is an industry-wide problem and Microsoft is committed to helping consumers have a safe, secure and positive online experience. General information on what to do if you believe you have been victimized via a phishing scam is available on this page at our support community.

 

 

 

This paragraph directs you to a form that starts asking for all sorts of personal information, including your credit card number, expiry date and secret answers to your live accounts. Surely this is not the information Microsoft should be asking for, especially when we are always told to never give out your credit card details when someone asks for them. Am I right in ignoring the form or am I being a bit too over protective of my personal financial information?

Posted
I recon this could be a scam, but the domain is the same as hotmail's usual domain. :confused: I doubt there would be any reason what so ever why Hotmail would need your card details. :confused: :confused:
Posted
I recon this could be a scam, but the domain is the same as hotmail's usual domain. :confused: I doubt there would be any reason what so ever why Hotmail would need your card details. :confused: :confused:

 

Did you actually read the message, and the form? ie. the part where the form is for reclaiming accounts you've been locked out of. The subheading saying 'for users with paid services' etc...?

 

It is on an official live.com site, ie. they'd have had to hack the MS website to be able to do that.

  • Thanks 1
Posted
I recon this could be a scam, but the domain is the same as hotmail's usual domain. :confused: I doubt there would be any reason what so ever why Hotmail would need your card details. :confused: :confused:

 

Its not a scam, I had to provide that info and more to recover my account before. If its more comfortable you can also ring MS and provide the info over the phone.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...