MS Authenticator suggests my hotmail account is under attack

MS Authenticator suggests my hotmail account is under attack

Author
Discussion

Aunty Pasty

Original Poster:

724 posts

45 months

Yesterday (08:04)
quotequote all
I have a hotmail account that I don't use very much and I have MS Authenticator on my phone for 2FA. Recently I've had a couple of notifications on the app asking for verification which I denied. Looking into the activity history on this account it seems like there are a stream of unsuccessful login attempts every 30 minutes so from throughout the world. It's been going on for a long time.

I've changed the password again just in case but it seems like the account is constantly being probed. Should I be worried or is this typical behaviour and MS is doing its job ok?

Chimune

3,359 posts

230 months

Yesterday (08:09)
quotequote all
Its doing its job. Your email and password may have been leaked in a previous data breech and its now being probed. It will prob die off soon.

Check your email - and yr passwords on havibeenpwned.com and change passwords on any other accounts that you may have used them with.

Also be highly suspicious of any emails texts asking you to confirm,login or update anything.

Edited by Chimune on Wednesday 20th November 14:34

Sheepshanks

34,997 posts

126 months

Yesterday (09:00)
quotequote all
Mine is the same for dodgy log in attempts and has been for years. Wife’s doesn’t get any - although she gets tons of spam.

eeLee

855 posts

87 months

Yesterday (09:46)
quotequote all
Go to accounts.microsoft.com for that Hotmail account and go passwordless. It will make it even harder for whomever it is that is trying to break in, they will get bored quicker.

Aunty Pasty

Original Poster:

724 posts

45 months

Yesterday (10:51)
quotequote all
Thanks, sounds like it's ok. I've also turned on the password-less feature which is new to me. Good tip. Sounds a bit counter-intuitive but makes sense.

Road2Ruin

5,476 posts

223 months

Yesterday (11:27)
quotequote all
eeLee said:
Go to accounts.microsoft.com for that Hotmail account and go passwordless. It will make it even harder for whomever it is that is trying to break in, they will get bored quicker.
I don't think bored comes into it, it's automated.

Almost everyone will have this, they just don't know about it.

My Hotmail account has an attempted login about every 30 minutes and has done for the last 10 years.

The account has been around for 30+ years, so the address will have been logged in a site somewhere.
They are now using brute force attacks to try and get into it. Unless your password is only 6 digits long and an a word of some sort, I doubt it will be broken.
I do believe there is a site that will tell you how likely and quickly your password can be broken by brute force, with current technology.

Quantum computing though...start crying now.
Mine is a billion years.

Sheepshanks

34,997 posts

126 months

Yesterday (17:17)
quotequote all
Road2Ruin said:
Unless your password is only 6 digits long and an a word of some sort, I doubt it will be broken.
If folks are getting the authenticator requests then the hacker has their password.

We get it at work as people use their work password on business related sites that aren't secure. Thankfully the authenticator using number matching stops people letting hackers in - they used to just blindly accept the authenticator requests.

Road2Ruin

5,476 posts

223 months

Sheepshanks said:
Road2Ruin said:
Unless your password is only 6 digits long and an a word of some sort, I doubt it will be broken.
If folks are getting the authenticator requests then the hacker has their password.

We get it at work as people use their work password on business related sites that aren't secure. Thankfully the authenticator using number matching stops people letting hackers in - they used to just blindly accept the authenticator requests.
You're right, missed that bit.

eeLee

855 posts

87 months

Road2Ruin said:
I don't think bored comes into it, it's automated.
Oh I know it's automated, I have a bunch of honeypots each of which getting hundreds of thousands of password stuffing attempts across many protocols.

The point of going passwordless should end up with fewer requests since they are looking to leverage the email address and the password that they believe is useful. Since many use their email address and their same password everywhere, it's low-hanging fruit, I'd hope for compute purposes that they remove unsuccessful combos (but of course they can hope that a dumb user approves the OoB auth request to Authenticator).

Simple thing is to put your webmail email address into www.haveibeenpwned.com and see if any of the datasets that have your email address contained passwords. My Entra ID email has never been used anywhere but to send and receive email......

wyson

2,691 posts

111 months

Sheepshanks said:
If folks are getting the authenticator requests then the hacker has their password.

We get it at work as people use their work password on business related sites that aren't secure. Thankfully the authenticator using number matching stops people letting hackers in - they used to just blindly accept the authenticator requests.
No, you can go straight to authenticator, password-less login. I do this now.

My hotmail accounts are always being probed. Funny it hardly happens on gmail or yahoo accounts.

Derek Smith

46,486 posts

255 months

wyson said:
Sheepshanks said:
If folks are getting the authenticator requests then the hacker has their password.

We get it at work as people use their work password on business related sites that aren't secure. Thankfully the authenticator using number matching stops people letting hackers in - they used to just blindly accept the authenticator requests.
No, you can go straight to authenticator, password-less login. I do this now.

My hotmail accounts are always being probed. Funny it hardly happens on gmail or yahoo accounts.
I use temporary Gmail accounts, and have done for years. I use false persona. When I think it might have been compromised, I dump it and start another.

I used to start a new one at least every year, but I haven't changed any since lockdown. Just realised.