Microsoft Email Breach Exposes User Data Through Compromised Support Agent
Hackers compromise a Microsoft customer support agent's credentials to access a limited number of web-based email accounts. The breach exposes subject lines and folder names, but not email contents or passwords.
Microsoft confirms that a cyberattack exposes a limited number of its web-based email accounts, including those using @msn.com and @hotmail.com addresses. The attackers gain access by compromising the credentials of a Microsoft customer support agent, allowing them to infiltrate the system between January 1 and March 28. Microsoft quickly disables the compromised credentials and blocks the perpetrators from further access.
The exposed data includes email addresses, folder names, subject lines of emails, and the names of communicating contacts. However, Microsoft states that the hackers do not access the actual content of any emails or attachments, nor do they steal login passwords. Despite this limitation, Microsoft actively recommends that all affected users change their passwords as a precautionary measure.
Because the exact scope of the viewed data remains unknown, Microsoft warns affected users to expect a potential increase in phishing and spam emails. The company urges vigilance against misleading domain names and unsolicited requests for personal information. Additionally, Microsoft implements increased detection and monitoring on the impacted accounts to prevent further unauthorized access.