Xbox live accounts being hacked?


Recommended Posts

Did you guys even read the article? Do you seriously think that being able to reset the CAPTCHA so you will have unlimited attempts to find the password isn't a security problem?

If Sony had something like this you all would be letting them have it. Also my password did contain uppercase, lowercase, and numbers in it so it's not just simple password being exploited.

Brute forcing a password is not a 'hack'. If this is it, then it's just these guys using weak passwords.

I agree. Just because they have found a way to brute force it without a CAPCHA doesn't mean its been hacked!

I would hardly call it a serious security flaw.......

I agree. Just because they have found a way to brute force it without a CAPCHA doesn't mean its been hacked!

I would hardly call it a serious security flaw.......

And if your account had been taken over? Of course it's serious, it's not working as it should.

Did you guys even read the article? Do you seriously think that being able to reset the CAPTCHA so you will have unlimited attempts to find the password isn't a security problem?

If Sony had something like this you all would be letting them have it. Also my password did contain uppercase, lowercase, and numbers in it so it's not just simple password being exploited.

Yes... being able to reset the CAPTCHA is a flaw Microsoft should fix asap. However, if your password contained uppercase/lowercase/numbers, wasn't a dictionary word, and wasn't short (<= 6 characters) it would have taken years to brute force your password so it's highly unlikely this flaw has anything to do with it.

Also, since you brought up Sony, does PSN even have any sort of brute force security? I just tried an invalid password 25 times for my PSN account and it didn't lock or display any captcha.

3 failed attempts and the account should simply lock and email recovery is needed. Simple really, throw in a drop down on logon for x, x and x of another password adds another layer of security.

Doh..

Is being able to avoid the CAPTCHA a security flaw? Yes

Is it the reason why your account is being hacked? No. A CAPTCHA is not a replacement for a secure password, if your password is being bruteforced over a network, it is FAR too simple.

This is absolutely NOT the reason why the accounts are being hacked. As others have said, a brute force hack would take years to crack most passwords. Yes, the CAPTCHA method is a flaw on Microsoft's part, but hardly has anything to do with accounts being hacked.

Yup, a security flaw with Live. Not EA. Some people have some back pedaling to do after the recent threads.

Well, at this point this is a "private investigator's" opinion. As far as I'm concerned, it still has not been proven, and if it were that simple, I still think we would be seeing FAR more people getting their accounts "hacked". I still think this is more of a social engineering scam than anything.

3 failed attempts and the account should simply lock and email recovery is needed. Simple really, throw in a drop down on logon for x, x and x of another password adds another layer of security.

Doh..

Agreed. I think that would certainly be wise.

Also, since you brought up Sony, does PSN even have any sort of brute force security? I just tried an invalid password 25 times for my PSN account and it didn't lock or display any captcha.

Wow. THAT is really scary... I guess they haven't learned anything about security whatsoever...

Yup, a security flaw with Live. Not EA. Some people have some back pedaling to do after the recent threads.
The "security flaw" is limited to being able to bypass captcha and then continue brute force. As someone has said already, Sony doesn't even have a captcha. So all those PSN accounts where you "only lost your ID" but no money was lost? They are in equal danger. ;-) (I wouldn't know better, I am not going to play with my WLID and don't have a PSN account to verify one way or the other).

This also shows that all who got hacked had weak passwords and all "I have never used it anywhere but my xbox" were simply stupid. If your password could be brute-forced, then it's not a good password.

If this is really an issue with WLID, which I still doubt it - then MS has bigger things to worry about than Xbox.

This should be merged with this thread: https://www.neowin.net/forum/topic/1036915-xbox-live-accounts-being-hacked/ No need for another one.

This is audio and shakey's day. let them enjoy it. :-D Microsoft is now "hacked" same as Sony. Kind of morale booster, ain't it?

"the email address or password is incorrect" - or not - "That Windows Live ID doesn't exist."

Terrible. That's security 123 students learn in school. Never ever give too much information to hackers.

The message should always be something like "Account informations invalid".

OK, this is absurd for a number of reasons.

First of all, it assumes that the passwords people use are so utterly stupid that they can be brute force hacked in a relatively fast fashion. That's patently stupid, for one. Secondly, most of the phishing or hacking victims have said they had strong passwords (including the couple of people on Neowin who were hacked). So unless they've been attempting to brute force crack someone's password since the original Xbox came out and they got incredibly lucky, then that's no dice. Third, I'm more than willing to bet that many of the hacking victims didn't have their e-mails searchable on Facebook or social networking sites.

It's not even a good theory. The CAPTCHA thing needs to be fixed, absolutely, but that's not even much of a security flaw in the grand scheme of things. You'd have to have good knowledge of what someone would use as a password (or have someone who has an insanely simple password) to have any value in that issue. I'm sure there's some way people are getting this information (and it's more likely they're not even finding out passwords, but using some sort of social engineering to get into someone's account -- like calling customer service and exploiting a flaw in the human system), but this doesn't seem even remotely likely.

Also: can we stop creating a billion topics about this? We only need one, just like all the posts when Sony was hacked were kept in the same place.

I wonder if the same CAPTCHA loophole affects Hotmail.com as well. In any case, I hope Microsoft fixes it soon.

CAPTCHAs are not that much secure.

I would hardly call it a serious security flaw.......

wow glad you are not working for my bank web site.

OK, this is absurd for a number of reasons.

First of all, it assumes that the passwords people use are so utterly stupid that they can be brute force hacked in a relatively fast fashion. That's patently stupid, for one. Secondly, most of the phishing or hacking victims have said they had strong passwords (including the couple of people on Neowin who were hacked). So unless they've been attempting to brute force crack someone's password since the original Xbox came out and they got incredibly lucky, then that's no dice. Third, I'm more than willing to bet that many of the hacking victims didn't have their e-mails searchable on Facebook or social networking sites.

It's not even a good theory. The CAPTCHA thing needs to be fixed, absolutely, but that's not even much of a security flaw in the grand scheme of things. You'd have to have good knowledge of what someone would use as a password (or have someone who has an insanely simple password) to have any value in that issue. I'm sure there's some way people are getting this information (and it's more likely they're not even finding out passwords, but using some sort of social engineering to get into someone's account -- like calling customer service and exploiting a flaw in the human system), but this doesn't seem even remotely likely.

Also: can we stop creating a billion topics about this? We only need one, just like all the posts when Sony was hacked were kept in the same place.

Yeah, I don't believe this either. It just doesn't seem like it would be possible as people have said, their password wasn't an easy guess. It's a flaw that should be fixed though.

Is it possible Microsoft doesn't know how they are accessing accounts ?

Social engineering, inside job or something. Surely an actual hack will lead to something more than Xbox Live which seems small fish if you have someones details.

Even if this isn't the flaw that got hackers into the accounts, it's definitely a good way to learn what accounts exist, and at least attempt common passwords. Knowing the first is a good part of the battle, and of the second even if the success is low (1% maybe, depending how many passwords you try, but not bruteforce) it's still a chance.

Yeah, I don't believe this either. It just doesn't seem like it would be possible as people have said, their password wasn't an easy guess. It's a flaw that should be fixed though.

Is it possible Microsoft doesn't know how they are accessing accounts ?

Social engineering, inside job or something. Surely an actual hack will lead to something more than Xbox Live which seems small fish if you have someones details.

Absolutely. I agree 100%. If they "hacked" all of these people's details, they'd be out to do much more damage than buying a few things on XBox Live... I mean, come on... The fact that that is their focus, leads me to the conclusion that it is not Live, as that would give them access to their e-mail and as a result a TON of other stuff... So, I still chalk this up to social engineering.

hmm claiming this is like the PSN hack is kinda like how lighting candles is like forest fires...

yeah...

I'd bet MS and EA will find some way to stop this, since it's obviously hurting both of them. I'd still guess crappy passwords that are never changed have something to do with it, too. So many people are clueless when it comes to online security and just assume it won't be an issue...until it is.

And i guess some people like you are clueless about server side security. because from what i'm reading it's very weak for xbox live. You never ever say why a login failed. That's gold information for hackers. Live loging does.

You Freeze an account when too much login attempts failed and send a mail to the user to recover the account. Live doesn't not freeze the account but use a weak captcha protection.

Come one that's security 123 students learn in college. Seriously ...

Funny that, im a web designer and have all sorts of I.T knowledge. Yet I still got hacked/phished. Sadly because you know something exists, doesnt mean you wont fall prey.

Don't lose your time. I went thru all this when my wow account got hacked (and i mean it). All people told me it was phishing and such. I am a web dev and knew i did not fall for a scam. I lost a complete night checking my email account log used for my wow account, checking my router log, scanning my HD and memory for a keylogger (even though i play games on my work computer while i surf the web on my secondary computer).

After this night i was 99.99% sure the account was not compromised from my side. Yet people was still telling me it was phishing.

You also always have this guy blaimg your PW strength too saying you need a 50 digits password with asian and russian caracters in (while in fact any good web service will freeze an account before it's even remotely possible to brute force a 8 digits random letters/numbers/symbols/caps PW).

It's a waste of time. They think they are better than anyone ... until the day they'll like me get hacked for the first time.

I don't play wow anymore but i can assure you my SWTOR account is protected using the authenticator app ;).

Interesting. A poster knows more about Microsoft security than Microsoft's multimillion dollar security team? Ok then. Um..no.

I don't. Everyone know about that. Seriously you can't be serious. I simply can't believe it. That's something you learn in the most basic class about security. Carefully word the error messages you show to the end users so you do not tell too much informations to hackers. What hackers get from error messages is gold to them.

Sorry but when you have 2 different error messages, one for when the account doesn't exist and one for when the account login information is wrong this is just bad.

As for the account not being frozen that's hilarious to see some people defending that.

I don't. Everyone know about that. Seriously you can't be serious. I simply can't believe it. That's something you learn in the most basic class about security. Carefully word the error messages you show to the end users so you do not tell too much informations to hackers. What hackers get from error messages is gold to them.

Sorry but when you have 2 different error messages, one for when the account doesn't exist and one for when the account login information is wrong this is just bad.

As for the account not being frozen that's hilarious to see some people defending that.

You still fail to realize that having a valid email or Gamertag really isn't that useful. Unless the password is guessable, then a password shouldn't ever be cracked. Every hacker out there knows that brute force is the worst way of cracking into an account. It's simply not plausible in a short amount of time.

Is it bad that Microsoft confirms if the username is valid? Yes. Is it allowing people to hack into accounts? Absolutely not.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • @Sayan...I have defended you at various points as I hope you know. This headline however is utter trash...shame on you sir!
    • An actual cosmic "Eye of Sauron" had been looking straight at us all along by Sayan Sen Image by Kovin P. Vasquez via Pexels | Not representative An international team of researchers has solved a long-standing mystery surrounding a distant blazar known as PKS 1424+240, helping explain why it produces some of the brightest high-energy gamma rays and cosmic neutrinos ever observed despite appearing to have a relatively slow-moving jet. The findings were published on June 6 in Astronomy & Astrophysics Letters. The study addresses a broader challenge in astrophysics: understanding how extreme cosmic objects accelerate particles to very high energies and produce very high-energy (VHE) photons and neutrinos. PKS 1424+240 is located billions of light-years from Earth. It has attracted attention for years because it is both a powerful source of VHE gamma rays and the brightest known neutrino-emitting blazar in the sky, according to observations by the IceCube Neutrino Observatory. It is also associated with one of the strongest peaks in IceCube's nine-year neutrino sky map A blazar is a type of active galactic nucleus powered by a supermassive black hole that pulls in surrounding matter and launches jets of plasma moving close to the speed of light. What makes blazars unique is their orientation. One of their jets points almost directly toward Earth, making them appear exceptionally bright across the electromagnetic spectrum and allowing scientists to study some of the most extreme physical processes in the Universe. The scientists exclaimed it's like the 'Eye of Sauron' in deep space. Usually, the brightest gamma-ray-emitting blazars are expected to have jets that appear to move very quickly. However, radio observations of PKS 1424+240 suggested that its jet was moving much more slowly, creating a contradiction that became part of a long-running problem known as the "Doppler factor crisis." To investigate, researchers analyzed 15 years of observations from the Very Long Baseline Array (VLBA), a network of 10 radio antennas spread across the continental United States, Hawaii and St. Croix. Using a technique called Very Long Baseline Interferometry (VLBI), astronomers combine signals from widely separated radio telescopes to create a virtual Earth-sized telescope capable of revealing extremely fine details. The team combined 42 polarization-sensitive radio images collected between 2009 and 2025, creating a much deeper and more detailed view of the jet than had previously been possible. The observations were carried out as part of MOJAVE (Monitoring Of Jets in Active galactic nuclei with VLBA Experiments), a long-running program that studies the brightness, polarization and magnetic field structures of jets produced by active galaxies. The project aims to better understand how activity near supermassive black holes is linked to high-energy radiation and neutrino emission. “When we reconstructed the image, it looked absolutely stunning,” said Yuri Kovalev, lead author of the study and Principal Investigator of the European Research Council-funded MuSES project at the Max Planck Institute for Radio Astronomy. “We have never seen anything quite like it — a near-perfect toroidal magnetic field with a jet, pointing straight at us.” The image revealed an unusual geometry. The researchers found that Earth lies almost directly in line with the jet, with a viewing angle of less than 0.6 degrees. In simple terms, astronomers are looking almost straight down the jet. This turned out to be the key to the mystery. Because the jet is aimed almost directly at Earth, a relativistic effect called Doppler boosting dramatically increases its apparent brightness. The study found that this effect boosts the emission by a factor of about 30 while also making the jet appear slower than it actually is. “This alignment causes a boost in brightness by a factor of 30 or more,” said Jack Livingston, a co-author at the Max Planck Institute for Radio Astronomy. “At the same time, the jet appears to move slowly due to projection effects — a classic optical illusion.” The nearly head-on view also gave scientists a rare look at the jet's magnetic field. Using polarized radio signals, they detected a clear toroidal, or doughnut-shaped, magnetic field component. The observations suggest the jet carries an electric current and that its magnetic field helps launch, shape and stabilize the flow of plasma. Researchers believe this magnetic structure may also play a key role in accelerating particles to energies high enough to produce both gamma rays and neutrinos. “Solving this puzzle confirms that active galactic nuclei with supermassive black holes are not only powerful accelerators of electrons, but also of protons — the origin of the observed high-energy neutrinos,” Kovalev said. The research was conducted under the MuSES (Multi-messenger Studies of Energetic Sources) project, which investigates how active galactic nuclei accelerate particles and generate different cosmic signals, including light and neutrinos. Scientists say understanding how protons are accelerated and linked to neutrino production remains one of the major unanswered questions in astrophysics. The findings help explain why some blazars can appear to have slow jets while still producing extremely bright high-energy emissions. More broadly, the study strengthens the link between relativistic jets, magnetic fields, gamma rays and high-energy neutrinos. Researchers say the results provide new clues about how some of the Universe's most powerful natural particle accelerators work and offer important insights for multimessenger astronomy, which combines different types of cosmic signals to study extreme events in space. Source: European Research Council, EDP Sciences This article was generated with some help from AI and reviewed by an editor. Under Section 107 of the Copyright Act 1976, this material is used for the purpose of news reporting. Fair use is a use permitted by copyright statute that might otherwise be infringing.
    • Gotenks98 is right... Outlook (new) is absolute trash. Doesn't Mozilla have an Enterprise Version of Firebird?
    • Microsoft Weekly: Surface Laptop Ultra, Windows 11 context menus, Build 2026 recap, and more by Taras Buria This week's news recap is here, with Microsoft announcing the new Surface Laptop Ultra, fresh chips from NVIDIA for Windows on ARM, a no-build week, fixes for Windows 11's context menus, gaming news, reviews, and more. Quick links: Windows 10 and 11 Windows Insider Program Updates are available Reviews are in Gaming news Great deals to check Windows 11 and Windows 10 Here, we talk about everything happening around Microsoft's latest operating system in the Stable channel and preview builds: new features, removed features, controversies, bugs, interesting findings, and more. And, of course, you may find a word or two about older versions. At Computex 2026, together with NVIDIA, Microsoft announced the Surface Laptop Ultra, its most powerful laptop to date, powered by NVIDIA's RTX Spark processor. Details about this computer are currently scarce, as Microsoft has only revealed certain parts of its specs. So far, we know that the computer has a 15-inch mini-LED display, a rich set of ports, a powerful processor, and all-day battery life. It also comes with a new wallpaper, which you can already download here in full resolution. The Surface Laptop Studio is not the only NVIDIA-powered Surface, which Microsoft unveiled this week. At Build 2026, the company also debuted the Surface RTX Spark Dev Box, an odd-shaped desktop with a 20-core NVIDIA Grace CPU and an NVIDIA Blackwell RTX GPU with 6,144 CUDA cores and fifth-generation Tensor Cores with FP4 precision, connected via the NVIDIA NVLink-C2C chip-to-chip interconnect for high performance. According to Microsoft, it can run models with up to 120 billion parameters locally without relying on cloud GPU infrastructure. These two new Surface devices are likely to cost quite a lot, and for those who need a more affordable device, Microsoft is preparing the next-gen Qualcomm-powered Surface Pro and Surface Laptop. This week, details about these two devices leaked in plenty of detail. Other announcements at Build 2026 include the following: Microsoft unveils new security tools for IT admins and developers building AI products Microsoft announces Scout, an OpenClaw-powered personal agent for enterprise customers Microsoft unveils MAI-Thinking-1 reasoning and MAI-Code-1 coding models Microsoft announced a new Windows 11 native command-line utility Microsoft unveils Majorana 2 quantum chip, accelerating commercial timeline to 2029 Microsoft believes that AI agents will eventually replace apps through Project Solara Microsoft introduces Web IQ, a Bing-powered search system built for AI agents Last week, Microsoft released a new Experimental build, which introduced a major Start menu upgrade. It now lets you toggle off specific parts of the menu without affecting other features, resize the menu, and hide additional UI elements. We published a closer look here, so if you want to know what Microsoft is cooking without enrolling in the Insider program and installing unstable builds, check it out. Speaking of new features, many users are very annoyed about the way Microsoft delivers them. Recently, a frustrated user shared their experience with gradual rollouts, and even Microsoft engineers admitted there is a flaw in the system that prevents new features from applying properly. One of those new features includes the ability to uninstall AI models in Windows 11 with a single click. Windows 11 is finally getting fixes for its slow context menus. Marcus Ash from Microsoft confirmed that the company is working on fixing Windows 11's context menus. Reworked context menus are going to be faster, simpler by default, and "configurable to what you use most." According to Marcus, Microsoft will share more details soon. Windows Insider Program Windows 11 preview builds, released last week, are now available for download as standalone ISO files. These days, Microsoft regularly pushes new images, allowing users to clean-install its recent Windows 11 preview builds faster and easier. If you want to try the latest Windows 11 features without jumping through the Windows Update hoops, get those new images here. Sadly, Microsoft did not release new Windows 11 preview builds this week. Come back next time. Updates are available This section covers software, firmware, and other notable updates (released and coming soon) delivering new features, security fixes, improvements, patches, and more from Microsoft and third parties. Microsoft is preparing new features for Teams. Later this month, the messenger will receive a new download manager with auto-dismissing notifications, reducing clutter and making the overall experience less annoying when dealing with downloads. Mozilla released Firefox 151.0.3, a new bug-fixing update for the browser. It is a small release, which fixes problems with pasting into text fields and the oversized VPN button on the toolbar. The update is now available for all users in the Release channel. Here are other updates and releases you may find interesting: VS Code 1.123 introduces massive upgrades for persistent AI developer workflows Microsoft OneDrive is getting a simple yet much-needed feature Microsoft faces heat after quietly blocking promised Office features on Apple systems Microsoft resumes forced Copilot app installation on some Windows PCs Browser vendors pen an open letter to Microsoft, saying "enough is enough" Here are the latest drivers and firmware updates released this week: AMD Radeon Software 26.6.1 with optimizations for F1 25: 2026 Season, World of Tanks: HEAT, and various bug fixes. Reviews are in Here is the hardware and software we reviewed this week Steven Parker dropped more mini PC reviews this week. GEEKOM Air12 2026 Edition is a low-power, affordable computer with an Intel Tiger Lake Pentium Gold processor, up to 16GB of memory, and 512GB of storage, costing just $349. It is light, quiet, energy efficient, and has modern ports on the front. However, the front-facing USB Type-C is data-only, and there are some quirks with the computer's memory, so check out the full review. The AMD RX 9070 GRE has been released worldwide, and we published a benchmark review comparing this powerful graphics card to the RX 9070 XT, 7800 XT, the NVIDIA RTX 5070, and RTX 4070. It has solid, balanced performance, plenty of RAM, and low temperatures, but watch out for mediocre ray tracing performance and not the best efficiency. Also, we reviewed the Cuktech 10 Ultra, a compact, high-power charger with four ports and a big display full of various stats. This tiny charger can pull nearly 120W and spread that power according to each connected device's needs. It also comes with a high-quality 240W cable, three power modes, and retractable prongs. The best part? It is quite affordable, just make sure you have an outlet placed in the right spot to benefit from the built-in display. On the gaming side Learn about upcoming game releases, Xbox rumors, new hardware, software updates, freebies, deals, discounts, and more. Do you remember the ASUS ROG Xbox Ally, Microsoft's first handheld console designed in partnership with ASUS? This week, ASUS revealed a new version of the device to celebrate twenty years of its Republic of Gamers brand. The new ROG Xbox Ally X20 features an OLED display, a transforming D-Pad, TMR sticks, and other changes. However, the chip inside the console is still the same. Forza Horizon 6 launched last month to critical acclaim, but the game will soon have a new rival made by those who used to work on Forza Horizon titles. Mike Brown from Maverick Games announced Clutch, an upcoming racing game with a story-driven campaign, deep car customization, and rich multiplayer. The game is coming to PC, Xbox Series X|S, and PlayStation 5 in Spring 2027. The next update for Minecraft now has a release date. This week, Mojang announced that Chaos Cubed will be available on June 16, 2026. In addition, Mojang published a teaser of the next Minecraft movie. A Minecraft Movie Squared has now been confirmed for a release somewhere in 2027. NVIDIA GeForce Now is getting 18 new games in June. Those include Jurassic World Evolution 3, Fatekeeper, GOALS, Gothic 1 Remake, NTE: Neverness to Everness, and more. If you are a Game Pass subscriber, you can also get new games soon: Persona 5 Royal, Starseeker: Astroneer Expeditions, and more are coming to the service this month. Sumer Game Fest 2026 happened this week, where we saw plenty of new games, including Alien Isolation 2, Final Fantasy VII Remake Part 3, Gen Atlas from the Shadow of the Colossus creator, a new Cuphead game in 8-bit style, a new expansion for Mafia: The Old Country, and more. Finally, here are this week's Weekend PC Game Deals, full of discounts and the latest freebies from the Epic Games Store. Other gaming news includes the following: God of War Laufey announced, introducing Kratos' wife as the new protagonist Ori studio's No Rest for the Wicked 1.0 release and console plans announced Microsoft launches Godot Sample to streamline Xbox PC game development on the engine Great deals to check Every week, we cover many deals on different hardware and software. The following discounts are still available, so check them out. You might find something you want or need. Samsung 990 PRO SSD 2TB NVMe - $389.99 | 39% off Sonos Sub 4 - Wireless Subwoofer - $759 | 16% off Logitech MX Creative Console - $159.99 | 20% off This link will take you to other issues of the Microsoft Weekly series. You can also support Neowin by registering for a free member account or subscribing for extra member benefits, along with an ad-free tier option.
  • Recent Achievements

    • Reacting Well
      X-No-file earned a badge
      Reacting Well
    • One Month Later
      pestcontrol46 earned a badge
      One Month Later
    • Week One Done
      pestcontrol46 earned a badge
      Week One Done
    • Week One Done
      JKR earned a badge
      Week One Done
    • Rookie
      moog19 went up a rank
      Rookie
  • Popular Contributors

    1. 1
      +primortal
      510
    2. 2
      PsYcHoKiLLa
      276
    3. 3
      Skyfrog
      75
    4. 4
      +Edouard
      71
    5. 5
      FloatingFatMan
      68
  • Tell a friend

    Love Neowin? Tell a friend!