My outlook account notices some unusual IMAP Login from Microsoft at Redmond

Anonymous
2022-07-12T08:27:40+00:00

I'm noticed from Microsoft Account Service that my outlook account has been exposed some IMAP Logins from each of the IPv4 addresses at 13.101.0.0-13.101.255.255 since 2022-07-11 JST informed as "unusual activity".

And I found with using whois service that these IP may be managed by Microsoft and placed at Redmond city in US.

Yeah I changed PW in usual way but these access can't stop anyway, so I'm guessing this is a specification for Outlook service.

But at the same time I am afraid of some attacks to Outlook service or Microsoft's collection of users data.

Does Anyone know some information about these kinds of access?

I already used technical help service of online chats in Japan, but he said that he doesn't have some clear idea.

Notification

Thanks to any users to read this thread and report the same issue.

I guess you all are as anxious as I am, but I'd like you to just keep focus on the topic of "unusual activity" from 13.101.0.0/16 here.

While many attacks on login to some system will happen all the time around the world, Thus this case is unique in that it's coming from IPv4 addresses inside Microsoft.

And here we hope to solve this strange problem.

Thank you for your cooperation.

S.E.

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2022-07-19T22:42:18+00:00

User @Chezlong Just placed this on my forum post

https://answers.microsoft.com/en-us/outlook_com/forum/all/unusual-account-activity-from-ms-ip-addresses/974cc1c1-232f-44a2-b0eb-0f378fd2c801?page=5:

Finally got to talk to someone at MS- this was their reply:

Thank you for the information. Please be advise that Microsoft is aware of this known issue already. This started to happen even last week and we are already working with this matter. We even have created a ticket number for this issue while it is still happening.

The ticket number for the emerging issue is INC31680156.

So they are on it, but no idea when it will be fixed.

[EDIT] They also confirmed that the account was secure, no need to change passwords, etc

AND

Found the following on thread https://answers.microsoft.com/en-us/outlook\_com/forum/all/outlook-mail-account-unusual-activity/6cfb226f-8cd7-41ae-bd0a-a80d100af543?page=9

posted by user @Pierre-LucMorais:

I have looked for other means to communicate to MS and I found an “official” thread to post this problem. Your mile may vary but i’ve had a reply on my thread and encourage ppl to try using them as well ?

https://www.reddit.com/r/microsoft/comments/o22lfc/microsoft\_official\_support\_thread/

They’ve responded that it is a backend accessing the service and a known issue.

Hoping this helps

Was this answer helpful?

10 people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2022-07-22T15:39:05+00:00

Outlook email users alerted to suspicious activity from Microsoft-owned IP address—
People turn amateur sleuths to discover that the source of all those sign-ins seems to be in Redmond
https://www.theregister.com/2022/07/21/outlook_sign_ins/
Article has an update at the end:

Updated at 09.33 UTC on 22 July 2022 to add:
Following publication of this article, Microsoft sent us a statement:
"We're working to resolve a configuration issue causing some customers to receive these notifications in error," said a Microsoft spokesperson via email.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

56 additional answers

Sort by: Newest
  1. Anonymous
    2022-07-15T21:25:22+00:00

    some reddit threads about this:

    https://www.reddit.com/r/Outlook/comments/vy2gej/unusual_sign_in_activity_reported_for_my/?sort=new https://www.reddit.com/r/Outlook/comments/vz04yd/i_am_not_sure_if_i_got_hacked_some_microsoft_ip/?sort=new

    You're right, people are already becoming desensitized to the logins and assuming it is just microsoft doing maintenance in a nonsensical way. And the account activity page stops flagging logins as unusual after it gets flooded with so many.

    This is much worse than the phishing campaign, it doesn't seem to require any user interaction except to open an email client once. It doesn't care about app-passwords or 2fa. Changing passwords barely slows it down because a user is likely to keep using their email client after. Having a strong password clearly doesn't matter because the attackers are syncing on the first attempt regardless. I can't think of anything that might mitigate how bad this is.

    Was this answer helpful?

    7 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2022-07-15T20:19:15+00:00

    Overall, attacks on our email accounts appears to be part of a larger scheme of attacks.

    Microsoft has been reporting to the media MFA skipping attacks on email systems at over 10000 companies so far -

    https://arstechnica.com/information-technology/2022/07/microsoft-details-phishing-campaign-that-can-hijack-mfa-protected-accounts/ https://www.zdnet.com/article/microsoft-warning-this-phishing-attack-can-skip-your-defenses-and-has-hit-10000-firms-already/

    "In the days following the theft of an authenticated session cookie, attackers were observed scanning Outlook online inboxes every few hours for email chains to exploit for payment fraud. They also set inbox rules to hide replies from the fraud target from the victim.

    Attackers also deployed tactics to hide their access, such as deleting the original phishing email from the victim’s inbox. This was a manual operation and differed from the initial attack which was automated."

    Replay attacks exploiting some loophole in Microsoft's email servers appear to be part of the story. However, the point of these repeated attacks may also be to desensitize Microsoft's unusual activity sensing systems. If your email account is being constantly accessed by 13.101.x.x, then over time, it is no longer an unusual activity. The intruders can then access your emails, and you wouldn't even know, because they'll get to your emails before you do, and they'll approve financial transactions on your behalf, and you wouldn't even know. Using Azure cloud services is part of this story so that Microsoft won't suspect it's own IP addresses. Some of these Azure services may be used on behalf of some of us too, because we'll never know that they are being used.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2022-07-15T19:50:56+00:00

    Hello everyone.

    I've had a similar problem.

    Successful sync attempts too.

    Here is a miscorosft forum post i've made about it:

    https://answers.microsoft.com/en-us/outlook_com/forum/all/suspicious-activity-allegedly-coming-from-a/82c1495a-a1b2-4dc1-998d-57e898210b4d

    Was this answer helpful?

    0 comments No comments