Microsoft Says Someone Changed My Profile Information

Anonymous
2014-03-09T09:44:08+00:00

I just received the following email (I have asterisked-out my email address):

From: Microsoft account team (*****@account.microsoft.com)*

Sent: Sun 3/09/14 4:45 AM

To: ****@hotmail.com

Microsoft account

Your profile info changed

Profile info such as your name, birth date, or country/region was changed on the Microsoft account ****@hotmail.com.

If this was you, then you can safely ignore this email.

If this wasn't you, a malicious user has your password. Please review your recent activity and we'll help you take corrective action.

Review recent activity

To opt out or change where you receive security notifications, click here.

Thanks,

The Microsoft account team

Is this a legit email? from Microsoft or Phishing?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

46 answers

Sort by: Most helpful
  1. Anonymous
    2014-08-26T19:21:30+00:00

    Weirdly, looks like Microsoft removed the offending IP address, which points to Microsoft BingBot of Microsoft Hosting in Redmond Washington.

    So here it is again....  It is an IPV4 address

    IP information '(Removed PII)'

    In text, the number is (Removed PII).

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2014-08-26T16:48:24+00:00

    Amazing lack of recognition and apparently some inability to communicate effectively by the Microsoft teams.

    I have been following Steve's comments and agree with the conclusions.  However in my case, the errant messages are coming via text message and for I too, there has been no apparent profile data changed.  My guess is that the profile information being changed is some field that does not appear on the UI like "date last update by Bingbot".

    I chased down the perpetrating IP address Removed PII and it is listed as Microsoft Bingbot from the organization = Microsoft Hosting.

    Sadly, I still get these after setting up two-factor authentication and using the Request Approval app.  My conclusion is that using the best and most comprehensive account protection methods will not prevent these messages.

    So, Steve, it is like the "little boy that cried wolf" wherein there is no actual threat from these sorts of conditions.  Yet they mask real profile attacks which ultimately makes the security less effective.

    I would expect more of Microsoft.  In  terms of both interest in their customers and in terms of protection of their brand.  I guess Microsoft doesn't what we think of them.  And right now, I think they have security issues they don't care about.  

    Not quite Ivy League.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2014-08-20T09:59:40+00:00

    It seems clear we are not going to get any assistance here in this forum.

    I think with everything that is going on, it's now more important than ever to keep an eye on these notifications to check where they are coming from.

    If you get one, don't ignore it.

    First, check that it is a legitimate email.  It should contain a button / link "Review recent activity" that should link to https://account.live.com/activity (if it goes somewhere else don't click the link!).  If you're not sure, just go to the above link directly.

    Sign in to your account and check the recent activity.  I'm in the UK, so what I see that is immediately odd is logins from the United States.  If you open any of these records it will show the IP address of the request along with other details.  If it was you, then it show your external IP address (which may be static or one that belongs to your ISP depending on how you are connected).  You can see your current external IP address easily by going to a site like http://whatsmyipaddress.org/

    If the IP address isn't one you recognise then open up a Google search page and paste the IP address into the search box and search for it.  You will see a bunch of results that are mostly IP address information databases or lookup tools.

    In my case, all of those USA ones are from Redmond, Washington - you know who's there, right?  All of the activity that is not mine belongs here, which are Microsoft servers.

    HOWEVER, don't start ignoring these emails, because you could end up in a "boy who cried wolf" situation and may well miss one that actually IS a real breach and not one of these false alarms (as confirmed in my case by Microsoft).

    DO turn on two-step / multifactor authentication on your account.  Go to https://account.live.com, login, go to Security & password, tap Turn on two-step verification.

    I do hope Microsoft will address this issue.  I have tried contacting them directly as suggested.  The first response was basically "everything is fine - don't worry about it".  I pursued them for more detail but so far have been ignored with no further response.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2014-08-19T22:58:56+00:00

    Hi Graham,

    We are sorry for this inconvenience.

    Again, we would love to assist to here in Community Forum however questions/issues regarding your Microsoft account are not best handled in a public forum due to the personal information involved. I suggest that this be addressed through a secured environment for your privacy and ease of access to our moderator's reply.

    Please go to this link. We have experts who can check and make thorough investigation of your account.

    Thank you.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2014-08-19T22:04:56+00:00

    Hi Graham,

    I understand your frustration with regards to the message you are receiving on your account regarding your profile information. 

    Clearly you did NOT understand my post, and you certainly did not respond to it.  Your response pretty much fails the Turing test.

    -- Graham

    Was this answer helpful?

    0 comments No comments