MS Authenticator suggests my hotmail account is under attack

MS Authenticator suggests my hotmail account is under attack

Author
Discussion

Aunty Pasty

Original Poster:

782 posts

51 months

Wednesday 20th November 2024
quotequote all
I have a hotmail account that I don't use very much and I have MS Authenticator on my phone for 2FA. Recently I've had a couple of notifications on the app asking for verification which I denied. Looking into the activity history on this account it seems like there are a stream of unsuccessful login attempts every 30 minutes so from throughout the world. It's been going on for a long time.

I've changed the password again just in case but it seems like the account is constantly being probed. Should I be worried or is this typical behaviour and MS is doing its job ok?

Chimune

3,596 posts

236 months

Wednesday 20th November 2024
quotequote all
Its doing its job. Your email and password may have been leaked in a previous data breech and its now being probed. It will prob die off soon.

Check your email - and yr passwords on havibeenpwned.com and change passwords on any other accounts that you may have used them with.

Also be highly suspicious of any emails texts asking you to confirm,login or update anything.

Edited by Chimune on Wednesday 20th November 14:34

Sheepshanks

36,601 posts

132 months

Wednesday 20th November 2024
quotequote all
Mine is the same for dodgy log in attempts and has been for years. Wife’s doesn’t get any - although she gets tons of spam.

eeLee

918 posts

93 months

Wednesday 20th November 2024
quotequote all
Go to accounts.microsoft.com for that Hotmail account and go passwordless. It will make it even harder for whomever it is that is trying to break in, they will get bored quicker.

Aunty Pasty

Original Poster:

782 posts

51 months

Wednesday 20th November 2024
quotequote all
Thanks, sounds like it's ok. I've also turned on the password-less feature which is new to me. Good tip. Sounds a bit counter-intuitive but makes sense.

Road2Ruin

5,830 posts

229 months

Wednesday 20th November 2024
quotequote all
eeLee said:
Go to accounts.microsoft.com for that Hotmail account and go passwordless. It will make it even harder for whomever it is that is trying to break in, they will get bored quicker.
I don't think bored comes into it, it's automated.

Almost everyone will have this, they just don't know about it.

My Hotmail account has an attempted login about every 30 minutes and has done for the last 10 years.

The account has been around for 30+ years, so the address will have been logged in a site somewhere.
They are now using brute force attacks to try and get into it. Unless your password is only 6 digits long and an a word of some sort, I doubt it will be broken.
I do believe there is a site that will tell you how likely and quickly your password can be broken by brute force, with current technology.

Quantum computing though...start crying now.
Mine is a billion years.

Sheepshanks

36,601 posts

132 months

Wednesday 20th November 2024
quotequote all
Road2Ruin said:
Unless your password is only 6 digits long and an a word of some sort, I doubt it will be broken.
If folks are getting the authenticator requests then the hacker has their password.

We get it at work as people use their work password on business related sites that aren't secure. Thankfully the authenticator using number matching stops people letting hackers in - they used to just blindly accept the authenticator requests.

Road2Ruin

5,830 posts

229 months

Thursday 21st November 2024
quotequote all
Sheepshanks said:
Road2Ruin said:
Unless your password is only 6 digits long and an a word of some sort, I doubt it will be broken.
If folks are getting the authenticator requests then the hacker has their password.

We get it at work as people use their work password on business related sites that aren't secure. Thankfully the authenticator using number matching stops people letting hackers in - they used to just blindly accept the authenticator requests.
You're right, missed that bit.

eeLee

918 posts

93 months

Thursday 21st November 2024
quotequote all
Road2Ruin said:
I don't think bored comes into it, it's automated.
Oh I know it's automated, I have a bunch of honeypots each of which getting hundreds of thousands of password stuffing attempts across many protocols.

The point of going passwordless should end up with fewer requests since they are looking to leverage the email address and the password that they believe is useful. Since many use their email address and their same password everywhere, it's low-hanging fruit, I'd hope for compute purposes that they remove unsuccessful combos (but of course they can hope that a dumb user approves the OoB auth request to Authenticator).

Simple thing is to put your webmail email address into www.haveibeenpwned.com and see if any of the datasets that have your email address contained passwords. My Entra ID email has never been used anywhere but to send and receive email......

wyson

3,268 posts

117 months

Thursday 21st November 2024
quotequote all
Sheepshanks said:
If folks are getting the authenticator requests then the hacker has their password.

We get it at work as people use their work password on business related sites that aren't secure. Thankfully the authenticator using number matching stops people letting hackers in - they used to just blindly accept the authenticator requests.
No, you can go straight to authenticator, password-less login. I do this now.

My hotmail accounts are always being probed. Funny it hardly happens on gmail or yahoo accounts.

Derek Smith

47,075 posts

261 months

Thursday 21st November 2024
quotequote all
wyson said:
Sheepshanks said:
If folks are getting the authenticator requests then the hacker has their password.

We get it at work as people use their work password on business related sites that aren't secure. Thankfully the authenticator using number matching stops people letting hackers in - they used to just blindly accept the authenticator requests.
No, you can go straight to authenticator, password-less login. I do this now.

My hotmail accounts are always being probed. Funny it hardly happens on gmail or yahoo accounts.
I use temporary Gmail accounts, and have done for years. I use false persona. When I think it might have been compromised, I dump it and start another.

I used to start a new one at least every year, but I haven't changed any since lockdown. Just realised.

wyson

3,268 posts

117 months

Friday 22nd November 2024
quotequote all
Can use a service that generates burner accounts. My duckduckgo browser has a built in burner email account tool. It sets up random whatever@duck.com email addresses on website sign ups etc and forwards emails to your real email addresses. Can just burn the whatever@duck.com account if you want to disengage.

Best of both worlds I reckon.

Baldchap

9,026 posts

105 months

Friday 22nd November 2024
quotequote all
I go through phases of having loads of these. I reported it to MS the first time but nothing comes of it.

Like others have said, 2FA is doing its job.

Terminator X

17,343 posts

217 months

Friday 22nd November 2024
quotequote all
Sheepshanks said:
If folks are getting the authenticator requests then the hacker has their password.

We get it at work as people use their work password on business related sites that aren't secure. Thankfully the authenticator using number matching stops people letting hackers in - they used to just blindly accept the authenticator requests.
Someone once said that your email account should be a standalone password not repeated anywhere else. I've stuck with that.

TX.

Harpoon

2,146 posts

227 months

Friday 22nd November 2024
quotequote all
Terminator X said:
Someone once said that your email account should be a standalone password not repeated anywhere else. I've stuck with that.

TX.
Just avoid password re-use entirely.

Terminator X

17,343 posts

217 months

Friday 22nd November 2024
quotequote all
Harpoon said:
Terminator X said:
Someone once said that your email account should be a standalone password not repeated anywhere else. I've stuck with that.

TX.
Just avoid password re-use entirely.
Ok but 2FA is also a pain in the ass Vs one password.

TX.

Road2Ruin

5,830 posts

229 months

Friday 22nd November 2024
quotequote all
Terminator X said:
Harpoon said:
Terminator X said:
Someone once said that your email account should be a standalone password not repeated anywhere else. I've stuck with that.

TX.
Just avoid password re-use entirely.
Ok but 2FA is also a pain in the ass Vs one password.

TX.
If you check your emails 18 times a day, I agree. Twice or three times, though.

Lucas Ayde

3,847 posts

181 months

Friday 22nd November 2024
quotequote all
Depends on how you've set up MS services and which ones you have but a lot of people will have their general MS account be tied to the same login as the hotmail account so if it does get hacked and user/password discovered, you could lose control over your Xbox Live, OneNote notes and general Onedrive cloud files.

So anyone who is seeing stuff like this happening needs to be sure to get it sorted. At the least, change the password on the account or better, go passwordless and use trusted authentication only.