This is a split board - You can return to the Split List for other boards.

Microsoft confirms 'high-profile' employees Xbox Live accounts hacked...

#1SolnotPosted 3/20/2013 11:54:13 AM

As more of the story about the simultaneous cyber attack and real-world "Swatting" carried out against security researcher Brian Krebs comes to light, one of the significant details has the reported targeting of Microsoft employees for hacking. Allegedly, the hackers who targeted Krebs did so because he helped to reveal the method by which they have been compromising the accounts of "Microsoft employees who work on the Xbox Live gaming platform," Krebs writes. The method apparently involves acquiring and then utilizing the employees' social security numbers along with some social engineering to obtain (and apparently then sell) access to those accounts.

"Attackers are targeting high-profile Microsoft employees by social engineering other companies."

In a statement given to The Verge, Microsoft confirmed that "a handful of high-profile Xbox LIVE accounts held by current and former Microsoft employees" have in fact been compromised. However, Microsoft denies that it in any way collects or utilizes SSNs in conjunction with Xbox Live accounts. Instead, the SSNs are apparently used by a third party in some way, and it was actually information garnered from that company which allowed the hackers to gain access to Microsoft employee accounts.

We are aware that a group of attackers are using several stringed social engineering techniques to compromise the accounts of a handful of high-profile Xbox LIVE accounts held by current and former Microsoft employees. We are actively working with law enforcement and other affected companies to disable this current method of attack and prevent its further use. Security is of critical importance to us and we are working every day to bring new forms of protection to our members.

As you can see in Microsoft's statement above, the company is working with both "law enforcement and other affected companies" to close off the loophole this hack has uncovered. It's a "stringed social engineering technique," as Microsoft describes it, that sounds remarkably similar to the multiple steps involved in the famous hack Mat Honan suffered last year. The very same hacker, who goes by "Phobia," may have been involved in both cases.

Chaining together security loopholes from multiple companies seems to be an increasingly common tactic. It lines up with the description Krebs published about the method as well, which allegedly involved "phone companies" in some way.

Microsoft does not collect or use Social Security numbers in its services, including Xbox LIVE Gamertags or Microsoft accounts. Attackers are targeting high-profile Microsoft employees by social engineering other companies that do use this data to intercept security proofs from Microsoft to compromise the accounts.

Krebs may not have been the only person targeted recently, as Ars Technica also said it had suffered a denial-of-service attack that could be linked to Phobia. For its part, Microsoft is directing Xbox Live users to its standard security recommendations at However, for now the strongest line of defense offered there appears to be those self-same "security proofs," at least one of which was compromised thanks to a third party.
#2Dragon NexusPosted 3/20/2013 12:12:20 PM
Social engineering =/= hacking.
Brute forcing =/= hacking.
"The problem with quotes on the internet is that you can never be sure if they're true" - Abraham Lincoln
#3djwagonPosted 3/20/2013 12:28:33 PM
Dragon Nexus posted...
Social engineering =/= hacking.
Brute forcing =/= hacking.


I donít know how much they got access to, but getting access to a credit card, address, and a few other things can do as much damage (if not more) than a SSN.

Plus, they might ruin your street cred in Halo 4.

Mar 19, 2013 | 11:04 PM

lol I beat you in b4djwagon comes out of your back to the qoute i that guy really that dumb.ssn theft is way worst then credit card thief
when I was here before I went by the screen name IMPORTER1..
#4dark_shardPosted 3/20/2013 12:38:16 PM
If I'm reading this correctly, they just got access to the employees' Xbox LIVE accounts. Why would this be a security concern to anyone BUT those having their accounts stolen?
--- - Games and Beer
GT: darkshardx
#5velvet_hammerPosted 3/20/2013 12:39:39 PM
Sony is the only company ever to be hacked stop with the lies TC
"F*** weed, I'm smoking Bob Marley's ashes."