
Once the attack was brought to Microsoft's attention, they shut it down quickly. Microsoft hasn’t revealed how many users in total were affected during the attack, which took place between January 1 and March 28, but actual email content accessed is a significant step up in severity from subject lines and contacts. While Microsoft stated that no email content was pilfered, a little while after their initial reveal, they had to update their warnings to state that about 6 percent of the total affected users had, in fact, had email body content accessed. This unauthorised access could have allowed unauthorised parties to access and / or view information related to your email account (such as your email address, folder names, the subject lines of emails, and the names of other email addresses you communicate with), but not the content of any emails or attachments, between January 1st 2019 and March 28th 2019. We have identified that a Microsoft support agent’s credentials were compromised, enabling individuals outside Microsoft to access information without your Microsoft email account. As per the notification email from Microsoft, which appears to have gone out over the weekend:

If it was a free personal account, however, it might have been affected. If your account was for business, you’re safe. This is where our tale of compromise woe begins.Ī customer support agent was compromised by hackers and used to gain access to certain pieces of email data. No matter your angle, and regardless of your stance on whether a Hotmail account is even a good idea anymore, people still make use of them. It could be you just appreciate the novelty of having a legacy email address, which is becoming rarer with each passing moment. Maybe your old Microsoft-supplied email address is tied into large portions of the MS ecosystem, and you’d rather not start trying to reinvent the wheel. Perhaps it’s an email you’ve pretty much grown up with and don’t want to let go. While most have long since moved on from MSN and Hotmail to Live and Outlook, all of these email accounts are still chugging away in one form or another. Yet, many users still have a few Hotmail accounts rattling around.

Microsoft email services have been around forever in Internet time. Long-time users of certain Microsoft products, such as Hotmail, MSN, and Outlook found they may be wrapped up in a hack grabbing snippets of email information, and in some cases, a little bit more.
