Johanna Taylor @ JULY 23 👻📖's avatar

Johanna Taylor @ JULY 23 👻📖

@johannamation.bsky.social

There must have been a data breach at Microsoft recently, because my Microsoft account has had *15* failed login attempts from 4 different countries since May 25 (previously zero) 🫠 My account is safe and all's okay, but... maybe check your Microsoft account security & set up 2FA just to be safe?

24 replies 60 reposts 224 likes


NutMeg 's avatar NutMeg @casuallychaotic.bsky.social
[ View ]

Or take the opportunity to switch to Linux..?

0 replies 0 reposts 1 likes


Tasmanian Blade Runner's avatar Tasmanian Blade Runner @laminatedballs.bsky.social
[ View ]

haveibeenpwned.com

0 replies 0 reposts 2 likes


Chris Broome's avatar Chris Broome @cabroome.bsky.social
[ View ]

Me too! The crappy thing is that M$ won’t specify which account is getting brute-forced. I’m getting these notifications on my backup gmail account

0 replies 0 reposts 1 likes


Daemonia's avatar Daemonia @daemonia.bsky.social
[ View ]

Yay, Microsoft got hacked big time recently. It's how we learn their new AI tool has no security for all the data they would be collecting. So try to include pass keys if you are able to get one of those

0 replies 0 reposts 5 likes


Ariohn SylvrWolfe 🔞's avatar Ariohn SylvrWolfe 🔞 @ariohn.bsky.social
[ View ]

Huh. 415 attempts since the 29th of last month. Zero penetration, zero requests for 2fa confirmation. Guess the password is secure for now. I might place a call to see if I can change my damn login name then, make em stop dead.

1 replies 1 reposts 6 likes


wi(l)d-screen franken's avatar wi(l)d-screen franken @drunkcrunkfranken.bsky.social
[ View ]

I noticed this happening to me too. It's pretty unnerving how many times they're trying to get in, even if I know nothing is ultimately happening.

0 replies 0 reposts 2 likes


Dunnage Zone 's avatar Dunnage Zone @dunnagez.bsky.social
[ View ]

It's possible an account/password of yours was contained in a data breach of another system. They were then attempted @ Microsoft. It's usually called "credential stuffing".

Go to haveibeenpwned.com to check if any of you accounts have been stolen. Only your email is needed to check known breaches.

0 replies 1 reposts 3 likes


Go Deep, I'll Look for You's avatar Go Deep, I'll Look for You @godeep.bsky.social
[ View ]

What’s a Microsoft account for? Like iTunes?

0 replies 0 reposts 0 likes


🔞Good Girl Elliotte🔞's avatar 🔞Good Girl Elliotte🔞 @elliotte-draws.bsky.social
[ View ]

I had one of those the other day. I got one of those emails with the code to reset your password. Anyway, out of sheer anxiety I reset both the password on my Microsoft account (which I don't use) and my associated email address.

1 replies 0 reposts 3 likes


Sleeplessone's avatar Sleeplessone @sleeplessone.bsky.social
[ View ]

It will be like that forever, once it started on my account I don't think it has ever stopped, all failed. I finally got around to removing the ability to sign in with a password about a year ago. Can only use a FIDO2 token like a Yubikey now, and they still try.

0 replies 0 reposts 3 likes


Josh "Go Drink The Sea" Brown's avatar Josh "Go Drink The Sea" Brown @theotherspeakman.bsky.social
[ View ]

I've got 2FA and they've been trying for over a year. Although not as much as my Epic Games account, yeesh

0 replies 0 reposts 2 likes


Kokoro's avatar Kokoro @livelyprancing.bsky.social
[ View ]

Thank you for the PSA. Just checked and sure enough 5+ different countries locations were listed just from the past few days. I rarely turn on my PC because work is enough screens for me now.

0 replies 0 reposts 1 likes


's avatar @simonball57.bsky.social
[ View ]

Yes they got hacked by china via exchange

1 replies 0 reposts 1 likes


Mara Johnson's avatar Mara Johnson @marajohnson.bsky.social
[ View ]

I just checked and I'm seeing it too. Probably a breech somewhere with my email account and these attackers are trying the account on multiple sites. I try and keep my passwords unique per site with 2-factor on, but its still annoying

0 replies 0 reposts 2 likes


Liz Kramer's avatar Liz Kramer @lizkreates.bsky.social
[ View ]

I had this happen earlier this year, it sucked! I reset my pw and 2FA option. They eventually stopped, but if they didn't, assuming that it's bot - the pwless login option looked very tempting to setup.

1 replies 0 reposts 2 likes


MDK's avatar MDK @mattdkerr.bsky.social
[ View ]

Unique password, I take it? Strange

1 replies 0 reposts 1 likes


Emil 's avatar Emil @emilgson.bsky.social
[ View ]

i get waves of this every few months , usually when gamepass has a new game.

0 replies 0 reposts 0 likes


Dan Davis's avatar Dan Davis @bindlestaff.bsky.social
[ View ]

I get waves of those. Ripples, really. Got 3 or 4 a couple of weeks ago, but never as many as 15!

0 replies 0 reposts 4 likes


nuzzlerat 's avatar nuzzlerat @nuzzlerat.bsky.social
[ View ]

same thing here

0 replies 0 reposts 0 likes


Kara's avatar Kara @karaboo.bsky.social
[ View ]

I've had thousands of attempts at least 20 daily, it's what made me activate 2FA

0 replies 0 reposts 4 likes


chucklefuck's avatar chucklefuck @keegerator.bsky.social
[ View ]

okay yes!! I'm glad it wasn't just me

0 replies 0 reposts 1 likes


Mina Li (she/her)'s avatar Mina Li (she/her) @codenameminali.bsky.social
[ View ]

I got those attempts, and tried to sign in with that address to delete that account, and...Microsoft didn't have an account listed with said address. ::scratches head:: That said, the address username wasn't all that unique and I got a corresponding Microsoft address, so typo maybe?

0 replies 0 reposts 0 likes


Ramith Hettiarachchi's avatar Ramith Hettiarachchi @ramith.fyi
[ View ]

You can select which aliases can be used to sign in to your account.. for example I noticed that one of my addresses has been appeared in breaches a lot, so I added a new alias and disabled login for the previous one. No more login attempts after

Settings page : account.live.com/SignInPrefer...

0 replies 0 reposts 4 likes