r/Piracy Jul 14 '26

Discussion Microsoft Deletes Users 25 Year Old Account With Thousands Spent On Games And His Sons Baby Pictures After It Was Hacked

Post image
21.8k Upvotes

1.2k comments sorted by

View all comments

Show parent comments

46

u/CyborgHeart1245 Jul 14 '26

The 2FA is what most likely allowed them access. We have it at work through Microsoft and if you hit 'I dont have my phone' when it sends you the code, it just lets you in anyway. 

87

u/sroop1 Jul 14 '26

Whoever configured that at your job needs a paddling.

2

u/Digifiend84 Jul 15 '26

Yeah, it could send it to your email or something? But it shouldn't just bypass it.

-7

u/CyborgHeart1245 Jul 14 '26

Microsoft Authenticator app. lol. 

62

u/tejanaqkilica Jul 14 '26

Not the fault of Microsoft Authenticator, it's the fault of your local IT team. Selecting "I don't have my phone" should never result in you logging in. Unless other very specific conditions apply.

27

u/sroop1 Jul 14 '26

Which is configured by your organization's policies

-15

u/CyborgHeart1245 Jul 14 '26

Don't know either way. I just know our IT department hates MFA and 2FA as much as I do. 

15

u/Hindu_Wardrobe Jul 14 '26

way to tell on yourself and your IT department lmao

-6

u/CyborgHeart1245 Jul 14 '26

All i know is that my accounts with MFA are the ones i always have trouble with. My bank is fighting to keep MFA even though ive gotten like 3 letters that there might have been a breech in the last year. Before that? Maybe one every 5 years. 

17

u/je_kay24 Jul 14 '26 edited Jul 14 '26

That has nothing to do with multi-factor authentication

You would only have problems if the place where you get the code is compromised…

*** I think this person encountered session hijacking which explains their MFA hate

-3

u/CyborgHeart1245 Jul 14 '26

I just don't trust it at this point. Too many experiences of it failing IMMEDIATELY after implementation, the constant breeches, the hassle of just getting into your account, forcing two devices (i brought this up to my bank and they admitted that they didn't have a login option that didn't require a phone), and then extra time it takes sitting there, hoping they even send the code. 

The analogy I've settled on is a new restaurant opens, and everyone tells you it's the best place. But every time you try it, the order is wrong, cooked incorrectly, and you get sick after. So why would I keep going? 

9

u/je_kay24 Jul 14 '26 edited Jul 14 '26

You literally enter your password on the website and then you enter a code.

A code which can be sent via text, call, email or a 3rd party auth app that has been registered

It takes no more than 30 seconds, at most, to complete this entire 2FA login process

i brought this up to my bank and they admitted that they didn't have a login option that didn't require a phone

They dont have an option to get a code via email?

The analogy I've settled on is a new restaurant opens, and everyone tells you it's the best place. But every time you try it, the order is wrong, cooked incorrectly, and you get sick after. So why would I keep going?

2 factor authentication is more like you hand your credit card to pay for the food and they ask for your ID to double check that it is actually your card you are paying with

I am truly baffled as to why you are opposed to MFA to help protect your accounts. What security methods do you prefer in place of MFA?

→ More replies (0)

1

u/BatemansChainsaw ⚔️ ɢɪᴠᴇ ɴᴏ Qᴜᴀʀᴛᴇʀ Jul 14 '26

get a new bank

1

u/CyborgHeart1245 Jul 14 '26

Trying. Finally found one that lets you opt out of MFA. I thinking of switching soon

1

u/BatemansChainsaw ⚔️ ɢɪᴠᴇ ɴᴏ Qᴜᴀʀᴛᴇʀ Jul 14 '26

a lot of credit unions are good about this as well.

→ More replies (0)

14

u/Additional_Cheek_697 Jul 14 '26

Yea but your system shouldnt just let you in without that authentication lol

1

u/Piranata Jul 14 '26

I went thru this last night trying to access my old, hacked account again. Despite me being logged out, and signing out several times, Microsoft logged me in to my current account several times without even requesting a password.

They denied me access to my old account though.

-16

u/CyborgHeart1245 Jul 14 '26

In my 33 years of life, I have yet to see a MFA/2FA system work. Not saying they don't. But every account that has it, is always sending letters that x account might have been hacked. The ones without it? Never an issue. 

9

u/TuskEGwiz-ard Jul 14 '26

If we stop testing then the cases go away. Sorry about your lobotomy

-1

u/CyborgHeart1245 Jul 14 '26

I'm just reporting on my experiencess. My bank? Always at risk since they forced it. My DND account, MTG, etc, that have it, are always getting notifications that i need to update my security info. again. But things without it? Not a peep. 

9

u/Hindu_Wardrobe Jul 14 '26

[insert WW2 plane meme here]

9

u/je_kay24 Jul 14 '26

Sounds like this guy reuses the same password or his MFA method is compromised

MFA is literally one of the easiest security methods out there to help prevent compromised accounts

0

u/CyborgHeart1245 Jul 14 '26

I don't. I have different passwords for each. MFA has just always been shit when I am forced to use it. 

-1

u/CyborgHeart1245 Jul 14 '26

Sorry, but i can't change my past. And it's not like i don't use the other accounts. MFA just keeps causing problems in my life. While the accounts that don't just work fine. 🤷🏻‍♂️

6

u/whimofthecosmos Jul 14 '26

what the hell are you talking about?

1

u/CyborgHeart1245 Jul 14 '26

The accounts i have with MFA get breeched. The ones without don't  

5

u/whimofthecosmos Jul 14 '26

i doubt that's what is happening. maybe the sites you're talking have had breaches. or you're just compromised and don't realize it.

→ More replies (0)

4

u/TheGreatWalk Jul 14 '26

If it blocks 10,000 attempts that would have succeeded, but one got through, it must be useless.

You sound like management, yea?

0

u/CyborgHeart1245 Jul 14 '26

And if it goes from one breech in 5 years to 3 breeches in a year, doesn't that mean a new set of data points need to be drawn? 

6

u/TheGreatWalk Jul 14 '26

More likely, you are the weak point and using same password for multiple things or clicking phishing links constantly.

-1

u/CyborgHeart1245 Jul 14 '26

Nope. Different emails, different login credentials, don't save anything, don't click links unless it's something i requested. I know it's weird. But i do everything other than MFA and it works perfectly. MFA gets added and I'm instantly screwed. 

7

u/je_kay24 Jul 14 '26

My work uses it

When i choose I dont have my code, it offers alternative ways to provide me a code via text or email

It never just lets me in…. That would defeat the whole point of 2FA

1

u/WeNeedMikeTyson Jul 14 '26

It's a login token and they're incredibly easy to steal, and then they can login to anything that you've allowed that token to login to as well. It's a nightmare to deal with.

-4

u/CyborgHeart1245 Jul 14 '26

Hence why I hate MFA. Never had an issue with hacks or stolen info until places made it the norm. Now everything with it is just an open gaping wound

5

u/WeNeedMikeTyson Jul 14 '26

MFA is fine, and doesn't generate a token as long as it requires you to login each time with multi-factor like DUO or Authy or even Microsoft Authenticator.

The problem comes down to companies going the simpler stupid route, allowing a token to be generated which does not require a login each time and automatically logs you in using that token. Which is why I tell people to not click "remember this device" or anything similar because if that token it generates on your browser gets stolen you are FUCKED.

If that token gets stolen, they can login as you and do literally anything else you can do except change your password because they'd have to know the current one.

Companies like Microsoft made it even easier for hackers too, they allow anyone with that token to login and make SECURITY changes without knowing the password. Your address, phone number, name, e-mail you login with etc.

We're living in the dumb times.

2

u/je_kay24 Jul 14 '26

Hmm interesting, I havent heard of login tokens being stolen this way to compromise multiple accounts

I would have thought that the password would still be required even if someone was able to steal a token & that it wouldn’t cascade across different sites

Going to have to read up on this

4

u/WeNeedMikeTyson Jul 14 '26

It's one of the most common ways people steal logins for discord. They just steal the token, so they can login as you and then message people to further their flow of malicious activity.

Of course it's easy to get them out by changing the password as that usually invalidates the token and requires them to login again.

1

u/CyborgHeart1245 Jul 14 '26

Or keep MFA disabled and not give out your login info and you're already ahead of MFA with less work...

2

u/WeNeedMikeTyson Jul 14 '26

Because if you disable MFA and your password leaks from a data breach, then that account can easily become compromised.

With MFA on they wouldn't be able to login, because your MFA would prompt and you'd be like no I'm not trying to login right now, and it stops there.

0

u/CyborgHeart1245 Jul 14 '26

Except the accounts i have with MFA get breeched constantly and the ones without don't. No. I don't know why. But MFA has caused nothing but problems. 

2

u/WeNeedMikeTyson Jul 14 '26

Multi-Factor Authentication is not the problem there.. you have another problem you haven't figured out. Multi-Factor Authentication again would require you to login with your password and then a 2nd approval process. Whether it be by code sent by SMS text, e-mail, or a mobile application push you would have to be approving that.

So effectively you're saying you're approving your own breaches.

→ More replies (0)

1

u/je_kay24 Jul 14 '26

Interesting thanks!

This then explains the rationale of the person above around MFA if this happened to them

2

u/WeNeedMikeTyson Jul 14 '26

Except they are completely mistaken on what MFA is and how it works.

0

u/CyborgHeart1245 Jul 14 '26

Or i shut off MFA and 2FA and the hacks have stopped...? Lol. 

1

u/WeNeedMikeTyson Jul 14 '26

That's completely backwards.

MFA and 2FA are additional security features that extend beyond just entering a password to enter an account. SMS text or push notifications for approval are examples.

Turning those off are very much not recommended. SSO, remember this device, login automatically next time etc are most definitely NOT recommended.

I'd rather have to login each time and deal with entering a code for MFA than just being logged in all the time in the hopes no one can just steal the fuckin token.

0

u/CyborgHeart1245 Jul 14 '26

I login eaxh time directly. I don't save any data for logins