A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Hey there, Venkatesh Muppidi
I keep receiving malicious sign-in requests on my Authenticator from random places across the world - Germany, Venezuela, Mauritius, etc,.
If you keep getting requests continuously, this could mean you are a victim of a credential stuffing attack. A credential stuffing attack is is where attackers will generally use sign in information such as email addresses and passwords that have been obtained online. They generally place the email address in a bot that will constantly inject the username and passwords into the login box to try and gain access to the account.
This is why you are receiving multiple requests to sign into your account. While this doesn't mean your account has been compromised, the attacker is hoping you will accidently click yes to sign in on their request. Especially if you are trying to sign in too and are expecting a request to come through on the authenticator app.
I have reviewed and removed unwanted devices, used sign-out everywhere option, and have even updated my password.
This is a good first step to ensure your Microsoft account is kept secure. However, please be aware that changing your password doesn't stop these attempts because the bot that is behind this isn't reacting to your password change. All it is doing is running through a list of leaked passwords automatically, putting each one into the password box.
The first thing I would check is whether your email address has appeared in a known data breach using a service like “Have I Been Pwned" found here: https://haveibeenpwned.com/
If your email address, or personal information, has been in a known data breach, this can mean you are more likely to be subjected to a credential stuffing attack. However, these attacks generate countless MFA notifications constantly, so if this isn't happening, then it could be someone manually trying to gain access to your account or someone accidently trying to sign into the wrong account.
If it is a credential stuffing attack, to reduce or stop these attempts please make sure you’re using a strong unique password and keep MFA enabled as this prevents the attacker from getting in.
On a personal Microsoft account, you have the option to generate a recovery code to use for your account to use if you no longer have access to your security information and recovery methods. Please sign into your Microsoft account security page here: https://account.live.com/proofs/manage/additional
Once you have signed in, please scroll down to the bottom of the security page until you come to an option to generate a new code.
Once at the bottom, please select “Generate a new code”
You will want to keep this in a safe place. If you do get hacked, you can use this code to recover your Microsoft account. Once you generate a new code, the previous code will no longer work.
If the constant MFA prompts are disruptive, one effective option is to change your Microsoft account’s primary alias (your sign‑in email). But do not delete the old account alias. This prevents bots from continuing to trigger MFA prompts using the old sign‑in address. Changing your primary alias doesn’t delete your mailbox or emails, it only changes the address you use to sign in.
To change this on Microsoft personal accounts, please sign into your Microsoft account here: https://account.live.com/names/manage
Once you have signed into your account, you can add an email address to use when signing into your Microsoft account. You can then click onto the link to change sign in preferences and select the new email you have added and de-select the previous email.
I hope this helps,
Nathan