Site icon WinCert

Microsoft discovered 44 Million Accounts using leaked passwords

<p>Between January and March this year Microsoft&&num;8217&semi;s threat research team performed a scan on all of the Microsoft account passwords&period;  These passwords were then compared with the database that holds more than three billion leaked credentials&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone wp-image-3464 size-full" title&equals;"leaked passwords" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2019&sol;12&sol;password-2781614&lowbar;640&period;jpg" alt&equals;"" width&equals;"640" height&equals;"448" &sol;><&sol;p>&NewLine;<p>The result was devastating as 44 million account passwords matched the database including regular user accounts&comma; Microsoft services accounts&comma; and even Azure AD accounts&period;<&sol;p>&NewLine;<p>Microsoft has immediately forced a password reset for accounts they&&num;8217&semi;ve found a match for&period; Additionally&comma; for Enterprise environments&comma; Microsoft will elevate the user risk by alerting Administrators to enforce password resets&period;<&sol;p>&NewLine;<p>Even though Microsoft initiated password resets it won&&num;8217&semi;t stop users to choose new passwords that have also been exposed as a part of a security breach&period;<&sol;p>&NewLine;<p>A <a href&equals;"https&colon;&sol;&sol;people&period;cs&period;vt&period;edu&sol;gangwang&sol;pass" target&equals;"&lowbar;blank" rel&equals;"noopener noreferrer">research study performed on 28 million user accounts<&sol;a> showed that 52&percnt; of users tend to reuse passwords or make small modifications to the original password&period; The same study also showed that 30&percnt; of those passwords along with its small modifications could be easily cracked with only 10 attempts&period;<&sol;p>&NewLine;<p>The company also advises the use of Multi-Factor Authentication or MFA which is a proven security mechanism that can dramatically improve security bearing&period; According to Microsoft&comma; 99&period;9&percnt; of identity attacks were prevented when the MFA authentication mechanism was used&period;<&sol;p>&NewLine;

Exit mobile version