Microsoft Found 44M Accounts Using Breached Passwords

From PC Mag: Microsoft has discovered 44 million user accounts are using usernames and passwords that have been leaked through security breaches.

As ZDNet reports, the vulnerable account logins were discovered when Microsoft's threat research team carried out a scan of all Microsoft accounts between January and March this year. The accounts were compared to a database of over three billion sets of leaked credentials and resulted in 44 million matches.

These accounts were spread between regular user accounts used by consumers (Microsoft Services Accounts) and enterprise accounts in the form of Microsoft Azure AD logins. In response, Microsoft explained, "For the leaked credentials for which we found a match, we force a password reset. No additional action is required on the consumer side ... On the enterprise side, Microsoft will elevate the user risk and alert the administrator so that a credential reset can be enforced."

Microsoft goes on to recommend that, "Given the frequency of passwords being reused by multiple individuals, it is critical to back your password with some form of strong credential. Multi-Factor Authentication (MFA) is an important security mechanism that can dramatically improve your security posture. Our numbers show that 99.9% of identity attacks have been thwarted by turning on MFA."

View: Article @ Source Site