Jump to content

Secondary pretty old Microsoft Acc compromised. Primary still holding on

Tech Reprise

Anyone else facing mass sign in attempts being made on their Microsoft Account? 
Recently one of my long forgotten account with a possible weak password was accessed from the Philippines and I got an email. I put that account up for closure after a password change.

I then checked my primary account and there are multiple Unsuccessful attempts at sign-in with the reason being "Incorrect Password" and most of them are from Asian countries with a few of them from European countries.
The successful ones are by me or my PC when I log into my PC or some other shit as they are from India and the IP range is known and from my ISP. 

 

This looks like a bot attack followed by password brute force on my old account. Strange thing is Microsoft didn't notify me that someone tried to access my primary account.

Screenshot_2024-04-02-18-32-12-546_com.android.chrome.jpg

  • AMD Ryzen 7 5700X Stock
  • B550 Aorus Elite V2 Rev1.2
  • G.Skill TridentZ RGB 3600Mhz 32gb (8gb x4)
  • MSI Mech 2X RX6600
  • Deepcool AK620 WH
  • Deepcool CK500 WH
  • Kingston A2000 250gb + WD Blue 1tb HDD, Sn550 1tb + MX500 1000gb
  • Antec EAG Pro 750 80+G
  • Benq Mobiuz EX2510 144Hz
Link to comment
Share on other sites

Link to post
Share on other sites

Likely your email address was exposed in an unrelated breach and now attackers are trying that email and password combination to try and access your account. Hopefully the reason it's unsuccessful is because you're using unique passwords.


For extra protection you should enable MFA (Multi Factor Authentication) to the Microsoft account.

CPU: Intel i7 6700k  | Motherboard: Gigabyte Z170x Gaming 5 | RAM: 2x16GB 3000MHz Corsair Vengeance LPX | GPU: Gigabyte Aorus GTX 1080ti | PSU: Corsair RM750x (2018) | Case: BeQuiet SilentBase 800 | Cooler: Arctic Freezer 34 eSports | SSD: Samsung 970 Evo 500GB + Samsung 840 500GB + Crucial MX500 2TB | Monitor: Acer Predator XB271HU + Samsung BX2450

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, starsmine said:

That just looks like everyone's MS account.
Nothing is compromised, notice the log ins are unsuccessful. 

Yes, saw some people on the web with the same issues. Most likely the email was in a breach and attackers are trying to bruteforce the passwords. 

  • AMD Ryzen 7 5700X Stock
  • B550 Aorus Elite V2 Rev1.2
  • G.Skill TridentZ RGB 3600Mhz 32gb (8gb x4)
  • MSI Mech 2X RX6600
  • Deepcool AK620 WH
  • Deepcool CK500 WH
  • Kingston A2000 250gb + WD Blue 1tb HDD, Sn550 1tb + MX500 1000gb
  • Antec EAG Pro 750 80+G
  • Benq Mobiuz EX2510 144Hz
Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, Spotty said:

Likely your email address was exposed in an unrelated breach and now attackers are trying that email and password combination to try and access your account. Hopefully the reason it's unsuccessful is because you're using unique passwords.


For extra protection you should enable MFA (Multi Factor Authentication) to the Microsoft account.

Yes. And most likely the password for my old email was also leaked as per haveibeenpwned. I have MFA/2FA on my primary account but did not have it on my secondary account. 

Good thing that my current password is holding up. Going to change all my old passwords and store them in a hard paper offline instead of on some password manager. 

  • AMD Ryzen 7 5700X Stock
  • B550 Aorus Elite V2 Rev1.2
  • G.Skill TridentZ RGB 3600Mhz 32gb (8gb x4)
  • MSI Mech 2X RX6600
  • Deepcool AK620 WH
  • Deepcool CK500 WH
  • Kingston A2000 250gb + WD Blue 1tb HDD, Sn550 1tb + MX500 1000gb
  • Antec EAG Pro 750 80+G
  • Benq Mobiuz EX2510 144Hz
Link to comment
Share on other sites

Link to post
Share on other sites

43 minutes ago, starsmine said:

That just looks like everyone's MS account.
Nothing is compromised, notice the log ins are unsuccessful. 

^That TBH because I just checked my own account and found several unsuccessful sign in attempts from France (somehow from some using internet exploder), Germany, Russia and Indonesia all with incorrect password entered.

 

Just move on and don't worry about it.

Link to comment
Share on other sites

Link to post
Share on other sites

5 hours ago, demonix00 said:

^That TBH because I just checked my own account and found several unsuccessful sign in attempts from France (somehow from some using internet exploder), Germany, Russia and Indonesia all with incorrect password entered.

 

Just move on and don't worry about it.

Yes, I got it from all over the world. Most likely bot attacks. Anyways I changed the password to something that even I can't remember lol

  • AMD Ryzen 7 5700X Stock
  • B550 Aorus Elite V2 Rev1.2
  • G.Skill TridentZ RGB 3600Mhz 32gb (8gb x4)
  • MSI Mech 2X RX6600
  • Deepcool AK620 WH
  • Deepcool CK500 WH
  • Kingston A2000 250gb + WD Blue 1tb HDD, Sn550 1tb + MX500 1000gb
  • Antec EAG Pro 750 80+G
  • Benq Mobiuz EX2510 144Hz
Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×