A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Hey there, Egor Bova
I've checked my existing sessions and MFA methods, and everything looks fine.
Microsoft only logs a sign‑in attempt once the attacker successfully submits the correct username and password. In your case, the attacker is failing at the password step, so the attempt never reaches the point where Microsoft records it as an actual sign‑in.
At this point, I'm just tired of receiving login attempt notifications around the clock.
From what you have posted, it sounds as though you are experiencing a credential stuffing attack. A credential stuffing attack is is where attackers will generally use sign in information such as email addresses and passwords that have been obtained online. They generally place the email address in a bot that will constantly inject the username and passwords into the login box to try and gain access to the account.
This is why you are receiving multiple requests to sign into your account. While this doesn't mean your account has been compromised, the attacker is hoping you will accidently click yes to sign in on their request. Especially if you are trying to sign in too and are expecting a request to come through on the authenticator app.
I have already changed my password several times, but this hasn't helped – I continue to receive these login requests.
While changing your password is a good first step, it doesn't stop these attacks.
This is because the bot is not reacting to your password being changed. It is using another way to sign into your account, using the Microsoft Authenticator app. This is why you are getting the notifications coming through to the Microsoft Authenticator app.
The first thing I would check is whether your email address has appeared in a known data breach using a service like “Have I Been Pwned" found here: https://haveibeenpwned.com/
If your email address, or personal information, has been in a known data breach, this is where your personal information has been leaked from. The website tells you when the data breach occurred and what information was obtained in the data breach. Me personally, I sign up for the alerts on all of my Microsoft accounts, so I know if my data has been compromised and when.
After you have checked this, I would recommend signing into your Microsoft account security page here: https://account.live.com/proofs/manage/additional
Please check that all of your information is correct and up to date. If there is anything that is not up to date, please update it.
As this is a Microsoft account, you have the option to generate a recovery code to use for your account to use if you no longer have access to your security information and recovery methods.
please scroll down to the bottom of the security page until you come to an option to generate a new code.
Once at the bottom, please select “Generate a new code”
You will want to keep this in a safe place. If you do get hacked, you can use this code to recover your Microsoft account. Once you generate a new code, the previous code will no longer work.
As you have said these prompts are becoming disruptive, please can you sign into your Microsoft account alias page here: https://account.live.com/names/manage
Please add a new Microsoft account username to your profile by clicking onto the blue hyperlink "Add email"
You will then be able to create a new account alias you can use to sign into your Microsoft account with. Once you have created one, please click onto "Change sign-in preferences"
On this page, please untick the primary alias. This doesn't delete the primary alias and people can still email you using it. However, it prevents you from using that email address to sign into your account with.
Once you have done this, please click save. Now when the bot tries to sign into your account, it will get a message telling it that the Microsoft account doesn't exist. Thus, will drop your email address and move onto the next one in it's list.
It is important to note, please do not change the primary alias. Please keep it. Otherwise you would have to update everyone and every service on your new email address.
Hope this helps,
Nathan