Outlook email users alerted to suspicious activity from Microsoft-owned IP address
- Reference: 1658399229
- News link: https://www.theregister.co.uk/2022/07/21/outlook_sign_ins/
- Source link:
While [1]an unusual sign-in activity email should always be treated with suspicion , the twist here is that the IP address at the root of the issue appears to originate within Microsoft itself.
The messages, [2]according to users , also appear in the unusual activity section of the company's email website, ruling out a phishing attack. Some confirm that an automatic sync has occurred.
[3]
Microsoft's [4]support forums are full of customers confused and a little concerned about the notifications, which look for all the world like either Microsoft or a miscreant with access to one of the company's endpoints is seeking to access their mailbox. Users have wisely changed passwords, but still occasionally see a successful sync among the failed login attempts.
[5]
[6]
Even switching to two-factor authentication appears not to stop the "Unusual Activity."
As with many email vendors, Microsoft fires off an Unusual Activity email or text message when it spots a sign-in attempt from a new location or device. Sometimes they can be completely legitimate; for example, logging into webmail from abroad, or adding a new mobile phone. Other times they can be an indicator of nefarious activity.
[7]
Sometimes Microsoft will up the ante and block the user's sign-in to keep an account safe.
Register readers got in touch to complain about the situation, with one saying: "This has been ongoing for a couple of days now with both myself and my wife affected."
Our reader went on to speculate that perhaps there were some bad actors using Azure (hence the Redmond IP addresses) to break into accounts or perhaps it was all just a blunder by one of Microsoft's administrators. We asked the company to clarify, but days later it has yet to respond.
[8]Microsoft lures SMBs to Cloudy PCs by connecting them to Xbox accounts
[9]Microsoft's latest security patch troubles Windows 11 users
[10]Microsoft tests CD ripping for Media Player in Windows 11
[11]Microsoft resorts to Registry hack to keep Outlook from using Windows 11 search
In the absence of an explanation from the Windows giant, The Register asked a tame IT specialist for his thoughts on what the problem might be. He joked: "Let's start with observing that Microsoft deems ITSELF suspicious. I call that progress!"
He went on to suggest that, other than something being severely wrong in the single sign-on department, perhaps miscreants were reusing passwords from various disclosure lists "and possess a sufficiently deep streak of irony to use Azure for the breaches."
[12]
Microsoft has been equally reticent on its own support forums with a smattering of comments from its employees sprinkled among the complaints suggesting a change of password, switching on two-factor authentication or simply signing out of one's account on all devices.
Perhaps a solution if only one or two users were struggling, but the issue appears to be hitting a large number of Outlook.com customers.
[13]One user noted : "Microsoft really needs to address this issue, at the very least to confirm that this 'unusual sign-in activity' (as they have detected themselves & urgently alerted their account users to) is either NOT an 'Account intrusion/compromise' situation and possibly just an MS internal system issue OR, if something more serious, what steps will need to be taken to resolve."
We'd have to agree. The company's relative silence on the matter is perhaps more worrying than the incident itself. If Microsoft responds with an explanation, we will update this piece accordingly.
Another user said: "I would like to know why a Microsoft-owned IP is syncing to my Microsoft account, why it is flagged as "suspicious", and why was it able to successfully sync at least once before." ®
Get our [14]Tech Resources
[1] https://blog.malwarebytes.com/scams/2022/03/unusual-sign-in-activity-mail-goes-phishing-for-microsoft-account-holders/
[2] https://answers.microsoft.com/en-us/outlook_com/forum/all/suspicious-activity-allegedly-coming-from-a/82c1495a-a1b2-4dc1-998d-57e898210b4d
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ytl4Isgue-GxOvx4FBhbMAAAAFc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://docs.microsoft.com/en-us/answers/questions/927298/unusual-imap-activity-from-ip-belonging-to-microso.html
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ytl4Isgue-GxOvx4FBhbMAAAAFc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ytl4Isgue-GxOvx4FBhbMAAAAFc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ytl4Isgue-GxOvx4FBhbMAAAAFc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2022/07/20/windows_365_cloud_pc_upgrades/
[9] https://www.theregister.com/2022/07/18/windows_11_patch_problems/
[10] https://www.theregister.com/2022/07/14/insider_build/
[11] https://www.theregister.com/2022/07/11/outlook_search/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ytl4Isgue-GxOvx4FBhbMAAAAFc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://answers.microsoft.com/en-us/outlook_com/forum/all/outlook-mail-account-unusual-activity/6cfb226f-8cd7-41ae-bd0a-a80d100af543
[14] https://whitepapers.theregister.com/
VPN == Virtual Private Network.
Seems to me nowadays that this term is more abused than it is used.
I fail to see your point, and I'm sure you understood mine. But I'll explain it again in case it wasnt clear.
By using a VPN, I mean that the miscreant would create a tunnel from their actual location to a location in my country of residence in order to trick, in this case, Microsoft into thinking that the access attempts were originating from my country. Yes, there are other ways that this could be done, but the use of VPN's to avoid location locking/identification is very common and widely understood. So I thought that would be quite clear...
> I dont know why it isnt the default.
No money in doing it, not to mention potential customer support issues from people who have left on a trip and forgotten they had this feature?
> simply block all attempts originating from outside of your registered country
Appreciate this advice is not much use for free outlook.com users, but you can do this with Office 365/Azure/business Outlook accounts.
Create a conditional access policy. Grant = Block. Conditions: Include = "Any location" Exclude = "UK".
(be very careful, obviously!)
While I agree simple country filtering can block most miscreant attempts, there is a danger of locking some people out of their accounts permanently. I've recently relocated to a different country, and while I tried to update my address for the most important services before leaving, there are others I didn't get round to. Then there's the accounts where I need to receive an SMS on the old number before I can login to update the details... even with roaming, the message might take longer than the 10-minute window to arrive.
So, make the default safe for most people, but have a fallback mechanism for the edge cases.
Can such people not use a VPN to their former country? As the owner of the account, you know the country to which it is currently restricted and so can establish a VPN connection to that country.
Azure or O365 Shells do this
I've had this on my account; the root cause was my authenticating on an Azure/O365 web shell in order to run some admin Powershell commands against Teams. This showed up as an apparent login from an IP in Singapore that was MS-owned.
So the root cause may be people using their personal IDs rather than a Service Principal to run scripts in Azure
[quote]
He joked: "Let's start with observing that Microsoft deems ITSELF suspicious. I call that progress!"
[/quote]
Correction: He wasn't joking.
"Many a true word is spoken in jest"
Some possible explanations
- In their ongoing attempt to be the one and only stop for everything IT, MS has decided to become a threats provider
- There is money to be made in hacking, and MS is all about making money
- Intelligent hackers have decided it was easier to infiltrate the company which controls and spies upon 90% of the world's personal computer estate instead of going after each victim piecemeal
- It's a feature. Won't fix
Relative silence...
They might think it's a rogue employee and actually admitting to that would kill their cloudy aspirations stone dead?
Dumbf***ery abound
I’ve been working / playing with computers since being 4 years old, since 1984
Forget about the nonsense that the gubbermint get up over the same timeline, ie false flags, and other assorted stupidity. Just on this site, I am reading, or should I say, “trying to read” the content, and because it is littered with adverts, the screen will suddenly jump about, because the advert server somewhere else is slow AF
FFS get a f***ing grip morons
“I Like Money” - Frito
Re: Dumbf***ery abound
I don't see adverts - I'm using uBlock Origin. Why aren't you?
Re: Dumbf***ery abound
"False flags" hahahaha
And what ads..?
Re: Dumbf***ery abound
Dunno what you're on about regarding false flags, but yes, inline adverts are shit and cause the page to jump about erratically and frequently seem to grab clicks/taps that were intended to do something else, not to mention more than a few take any form of interaction as being permission to throw away what you were reading and go to a different site for even more adverts....
...so the painfully obvious question is why are you reading a tech oriented site and not using a blocker to block, well, everything .
Governments of all persuasions spout the bullshit they want you to hear, just ignore it. Don't get hung up on so-called false flags, instead worry about what you're letting have access to your device. That's a much more insidious problem.
I mentioned it here
-> https://www.theregister.com/2022/06/13/open_source_office_suites/
If you use MS Outlook with third party IMAP servers (presumably POP3 too, and Outlook), your login details are passed to Microsoft.
When I recently tried Office 365 for Mac, I set up Outlook. I was expecting to see logins from my IP address. What I saw was logins from Microsoft. There is only one conclusion from this, for my circumstances but probably in general: Microsoft is storing the log in details in plain text. They have to be, as the server I use only has plain text logins over TLS. This cannot be hashed in any way. Perhaps Microsoft is hashing the details when it stores them, but it has to have a way to retrieve the plain text version.
I contacted MS about this. They said they do this to "enable server side search". This is not necessary, as IMAP servers support server side search - there is no requirement for Microsoft or anyone else to have a login to do this.
If you use Outlook with an IMAP server, consider it to be unsafe unless you can prove otherwise. Naturally, I do not use Outlook and changed my passwords.
It is worth mentioning that I saw the same behaviour with Outlook on Android.
Microsoft forgot to disable reporting when the NSA logs in?
I got this as well, and had not realised it was a Microsoft IP address. I just updated my password, noted that someone in America seemed to have successfully sync'd my account, and again regretted the fact there was no way to, for instance, simply block all attempts originating from outside of your registered country by selecting a specific setting within Outlook.
I do not know why this seems so hard for firms to implement. Yes it wont stop a dedicated attack against me by someone using a VPN, but first the miscreants would need to know which country I'm in, to know which VPN to set up, before they could try to access my account. And that is not how the vast majority of attacks come in. They are usually simply lists of email addresses, with lists of previously leaked passwords, and try your luck. Add in location blocking and I'd be willing to bet 99% of intrusions are stopped at source. Make it a simple on-off setting, so when people want to travel they can turn it off, and access there device from anywhere, and then turn it back on again when they're home.
This is not rocket science... I dont know why it isnt the default.