Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Microsoft Confirms Breach at its Online Store in India

Late Sunday reports emerged that Microsoft’s online store in India had been hacked, defaced and user information exposed including unencrypted passwords. It turns out these claims are true and while Microsoft isn’t saying much on the subject, they did comment on the issue.

Late Sunday reports emerged that Microsoft’s online store in India had been hacked, defaced and user information exposed including unencrypted passwords. It turns out these claims are true and while Microsoft isn’t saying much on the subject, they did comment on the issue.

“Microsoft is investigating the limited compromise of the company’s online store in India,” a Microsoft spokesperson told SecurityWeek. “Customers have been notified and provided with guidance to reset their passwords. We are diligently working to remedy the incident and keep our customers protected.”

Taking credit for the hack is “7z1&Ancker,” claiming to be part of “EvilShadow Team”. After the site was defaced with several images and pages showing that were created by the attacker, Microsoft quickly took the site offline and it currently remains unavailable. At the time of publishing the site displays the following error message: “The Microsoft Store India is currently unavailable. Microsoft is
working to restore access as quickly as possible. We apologize for any inconvenience this may have caused.”

The hacker also posted several images, some of which are included below.

SecurityWeek will follow-up if additional details emerge.

Microsoft Online Store India Passwords Exposed

Microsoftstore.Co.in Hacked

Advertisement. Scroll to continue reading.
Written By

For more than 15 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is founder and director of several leading cybersecurity industry conferences around the world.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Assaf Keren, who previously served as CSO/CISO at Qualtrics and PayPal, is Meta's new CISO.

Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.

AJ Shipley has been appointed Chief Product Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.