Microsoft confirms Hotmail phishing attack
Security experts warn Hotmail users to change their passwords immediately.
Microsoft has confirmed that Hotmail customers were hit by a phishing attack, resulting in the release of thousands of passwords online.
Last Thursday, an anonymous user posted details of over 10,000 accounts - with addresses starting with the letters A or B - on a developer site.
Although the precise cause of the leak is still unclear, Microsoft said that once it had learned of the issue, it requested that the credentials were removed and launched an investigation.
A spokesperson said in a statement: "As part of that investigation, we determined that this is not a breach of any Microsoft servers."
The statement added: "Subsequently we are taking measures to block access to all of the accounts that were exposed and have resources in place to help those users reclaim their accounts."
Microsoft also said that phishing was an industry wide problem, and advised users to keep anti-virus software up to date as well as renew passwords every 90 days.
IT security firm Sophos said that users of Microsoft's online services should change their passwords, and the fact that the accounts began with A or B suggested that it could be the "tip of the iceberg".
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"My recommendation for users of Microsoft's online services is to change your passwords immediately," said Sophos senior security advisor Chester Wisniewski in a statement.
"You are better to be safe than sorry, and password rotation is something we are often to lazy to do," he added.
-
What does modern security success look like for financial services?Sponsored As financial institutions grapple with evolving cyber threats, intensifying regulations, and the limitations of ageing IT infrastructure, the need for a resilient and forward-thinking security strategy has never been greater
-
Yes, legal AI. But what can you actually do with it? Let’s take a look…Sponsored Legal AI is a knowledge multiplier that can accelerate research, sharpen insights, and organize information, provided legal teams have confidence in its transparent and auditable application
-
Ransomware victims are getting better at haggling with hackersNews While nearly half of companies paid a ransom to get their data back last year, victims are taking an increasingly hard line with hackers to strike fair deals.
-
96% of SMBs are missing critical cybersecurity skills – here's whyNews The skills shortage hits SMBs worse as they often suffer from a lack of budget and resources
-
Sophos Firewall Virtual review: Affordable network protection for those that like it virtualizedReviews Extreme network security that's cheaper than a hardware appliance and just as easy to deploy
-
MSPs are struggling with cyber security skills shortagesNews A shortage of tools and difficulties keeping pace with solutions were also ranked as key issues for MSPs
-
Nearly 70 software vendors sign up to CISA’s cyber resilience programNews Major software manufacturers pledge to a voluntary framework aimed at boosting cyber resilience of customers across the US
-
Sophos and Tenable team up to launch new managed risk serviceNews The new fully managed service aims to help organizations manage and protect external attack surfaces
-
Ransomware groups are using media coverage to coerce victims into payingNews Threat actors are starting to see the benefits of a more sophisticated media strategy for extracting ransoms
-
Shrinking cyber attack “dwell times” highlight growing war of attrition with threat actorsNews While teams are becoming more proficient at detecting threats, attackers are augmenting their strategies