Hackers Launch Sneak Attacks on Microsoft's Live ID - eCommerce Times
eCommerce Times, by Richard Adhikari
Hackers have been infiltrating Microsoft services by sending emails to targets saying their Live IDs have been used to distribute unsolicited email, and their accounts will be blocked unless they click on an embedded link and fulfill new security requirements, Kaspersky researcher Andrey Kostin reported last week.
Clicking on the link takes victims to the real Live ID site.
Instead of then stealing the user's login and password, this new attack triggers a pop-up message stating that an app requests permission to automatically log into victims' accounts, view their profile information, and access the list of email addresses in their contacts file.
Agreeing to the request lets the hackers vacuum up personal information stored in victims' user profiles on services such as Xbox Live, Hotmail, Outlook, MSN, Messenger and OneDrive. Read more.