Hackers Used Microsoft Email Accounts to Steal Users’ Cryptocurrency, Report

Published at: April 30, 2019

In worsening news for users of Microsoft’s email services like Outlook, Hotmail and MSN, several cryptocurrency holders affected by a recent hack allege that the hackers responsible stole their crypto, as reported by Vice’s Motherboard on April 29.  

One victim claimed on a Dutch tech forum to have lost just over 1 bitcoin (BTC), or almost $5,400 at press time, when hackers used his email account to reset his password and gain access to his Kraken account on March 31st.  Several Reddit users attested to similar experiences.  

According to Microsoft, the initial breach took place between January 1st and March 28th of this year, though according to others it may have extended for six months. Hackers initially reached consumer emails via a Microsoft support agent account.  

Microsoft’s initial email statement to affected users assured them that hackers may have accessed email metadata like contacts, “but not the content of any e-mails or attachments.”  

Two days later, however, reports surfaced that hackers had indeed been able to read email content.  

Microsoft has yet to respond to the latest escalation of this security breach.  

This comes just a week after an Independent Security Evaluators report on a “blockchain thief” who has stolen millions in ether by guessing weak private keys, as well as Coinbene’s continued denial of losing over $100 million to a hack in March.

Tags
Related Posts
California Man Sues AT&T Over Loss of $1.8M and Crypto Accounts
California resident Seth Shapiro has filed a lawsuit against wireless service giant AT&T alleging that its employees helped to perpetrate a SIM-swap which resulted in the theft of over $1.8 million in total, including cryptocurrencies. The complaint filed on Oct. 17 claims that Shapiro is “a two-time Emmy Award-winning media and technology expert, author, and adjunct professor at the University of Southern California School of Cinematic Arts.” The lawsuit alleges that between May 16 and May 18 AT&T employees transferred access to Shapiro’s mobile phone to outside hackers: “AT&T employees obtained unauthorized access to Mr. Shapiro’s AT&T wireless account, viewed …
Cryptocurrencies / Oct. 20, 2019
Recent Firefox Zero-Day Flaw Was Used in Attacks Against Coinbase’s Employees
The recent Firefox’s zero-day security flaw was used in attacks against major crypto exchange and wallet service Coinbase, according to a tweet from Coinbase security researcher Philip Martin posted on June 20. As Martin found, the reported critical zero-day vulnerability in Mozilla’s Firefox web browser, which was announced on June 18, has actually emerged along with another zero-day flaw that targeted Coinbase employees, meaning that there were two separate Firefox zero-day attacks. The Coinbase security expert tweeted: “On Monday, Coinbase detected & blocked an attempt by an attacker to leverage the reported 0-day, along with a separate 0-day firefox sandbox …
Cryptocurrency Exchange / June 20, 2019
Bilaxy exchange suspends website after ERC-20 hot wallet hack
Bilaxy, a lesser-known cryptocurrency exchange, has confirmed a major hacking incident, reporting the losses of funds due to an exploit of the platform’s ERC-20 hot wallet. Bilaxy announced on its Telegram channel that the crypto exchange suffered a “serious hack” on Saturday between 6 pm and 7 pm UTC, resulting in the transfer of 295 different ERC-20 tokens. According to the exchange, the affected tokens were transferred by the hacker to a single address. At the time of writing, the tokens are valued at $170,600, with the most recent transaction sending out 50 Ether (ETH), or about $159,000, on Monday. …
Bitcoin / Aug. 30, 2021
Coin Bureau Youtube channel hacked despite 2FA protection
Coin Bureau, a popular information portal for cryptocurrency developments with over 600,000 followers on Twitter, experienced a security breach on its Youtube channel on Monday. Hackers allegedly uploaded a video with links to scam fiat/cryptocurrency addresses soliciting a token sale before being taken down by Youtube. According to Coin Bureau staff, they were baffled by the incident as its accounts were "secured with ultra-strong passwords and Google security keys." So our YouTube channel was just hacked. Have absolutely no idea how this happened. All accounts are secured with ultra strong passwords and Google security keys. @YouTubeCreators this is a serious …
Technology / Jan. 24, 2022
Developers need to stop crypto hackers — or face regulation in 2023
Third-party data breaches have exploded. The problem? Companies, including cryptocurrency exchanges, don’t know how to protect against them. When exchanges sign new vendors, most just innately expect that their vendors employ the same level of scrutiny as they do. Others don’t consider it at all. In today’s age, it isn’t just a good practice to test for vulnerabilities down the supply chain — it is absolutely necessary. Many exchanges are backed by international financiers and those new to financial technologies. Many are even new to technology altogether, instead backed by venture capitalists looking to get their feet wet in a …
Bitcoin Regulation / Nov. 3, 2022