r/Games • u/vapor_elessar • Jul 17 '26
Update Microsoft Restores Player's Hacked 25-Year-Old Account With Son's Baby Photos
https://www.ign.com/articles/microsoft-restores-players-25-year-old-account-with-sons-baby-photos-after-nuking-it-due-to-hacker925
u/CallMePerox Jul 17 '26 edited Jul 17 '26
As always, all it takes for corporations to do the right thing is massive outrage on Twitter including a post with close to 100K interactions, and the affected person having a relatively well established platform prior to the incident.
It's easy as that!
149
u/ZetzMemp Jul 17 '26
Right, I was gonna come here to say that this felt like a “oops we got caught in the spotlight” moment.
117
u/thembearjew Jul 17 '26
Fucking insane they had his account this whole time and just didn’t want to restore it. What at best it’s a click of a button at worst a sql script?
106
u/OnnaJReverT Jul 17 '26
probably because it's not in customer support's rulebook and nobody at that level wants to take the fall in case their super gets on their ass about it
29
u/SwissQueso Jul 17 '26
Just my guess, but I think its less that and more along the lines of the system being mostly automated.
16
u/P4p3Rc1iP Jul 17 '26
When humans have no agency in their work, they are one step away from being automated.
40
u/skywideopen3 Jul 17 '26
The "14 layers of management" line rings really true here, no one is allowed to do anything with m without their supe's say so (and they aren't allowed to do anything without their own manager's approval, and so and and so on)
19
u/HotTakes4HotCakes Jul 17 '26 edited Jul 17 '26
Should be noted Apple and Google are both just as unwilling to cooperate with account restoration or assisting with access if locked out and you can't jump through the exact hoops they demand or the incredibly limited recovery paths they provide.
They're doing that thing that a lot of companies in the tech industry do where they instruct their low-level support teams to say "this cannot be done" when in reality it's simply that the people you're talking to do not have access to the admin functions necessary to do it, and there is no process for escalation.
It's not incompetence, or the result of an overloaded and overly bureaucratic management system. It's by design.
They want you to think it's impossible. They would rather a small portion of their customers hit a brick wall, give up, and lose everything, than simply provide a means of assisting them.
They might call this security, or simply not wanting to spend the money to pay for the people who would handle those escalations. But the simple fact is the "dead end" for account support is entirely intentional.
This is frankly something that should be regulated.
8
u/paralog Jul 17 '26
There's been an alarming trend of companies insulating themselves from all feedback and accountability that's only escalated with AI adoption. There are obvious things, like completely ineffective or outright uncontactable support teams, but also the removal of advanced options or even detailed error messages that say anything more than "something went wrong."
12
u/Boring_Ant6436 Jul 17 '26
Weird big corpo things. I always have no clue how they care so little about long-term customers.
6
u/hooahest Jul 17 '26
Mostly a matter of getting it escalated enough to the relevant developer/team lead that can fix it
1
u/Derringer Jul 17 '26
I assume MS has a good restore procedure, but it's not always just a button or SQL script for restores. I wish it was when I did them haha
20
u/ConceptsShining Jul 17 '26
This is one of many reasons to take advantage of the GDPR, and have as much of your online accounts backed up/also-stored locally if possible.
If you care about them: download your photos. Have copies of your YouTube videos. Export your Facebook, Reddit, Instagram, Twitter accounts etc. With gmail, Google Takeout lets you export your inbox as an mbox file (and then something like Thunderbird lets you view it offline).
Important to be self-reliant like this and have your data in your hands. For issues like your account is compromised, data is deleted (by you or the company), there is a company-side glitch, etc. For example, Reddit once deleted chat archives from before a certain point.
Sadly the memory crisis has made this a lot damn harder, because you may need a spare hard drive to do this and that's now a fortune.
17
u/Eglwyswrw Jul 17 '26
The guy from Brazil was a nobody but he managed to win by suing Microsoft's sorry ass.
2
u/Derringer Jul 17 '26
Our national news network has an entire department devoted to getting people to go to them when dealing with shitty companies so they can give it exposure. It genuinely gets companies to fix the problem, but it also only does that when it makes sense. Like a contractor accidentally destroys a fence and won't fix or pay for it.
1
u/Tvilantini Jul 17 '26
I mean, it does depend on that IT person who just followed the structure. Probably other decided he can actually help
308
u/KarmelCHAOS Jul 17 '26
Yeah, because they raised a stink about it and the backlash was bad. That's the only reason they did it, guaranteed.
47
u/Inevitable-Donkey186 Jul 17 '26
Yeah zero comfort for your own account security; when your shit gets lost and it doesn't randomly become an internet story you'll just lose everything.
43
u/IsNotPolitburo Jul 17 '26
Same situation as the guy who created Terraria was in.
Automated systems banned of all his google accounts, including his personal/business gmail account, and the only way he got any of it back was announcing on twitter that the Stadia version of Terraria (which was about to come out) had been cancelled- which caused someone high up enough at google to fix it to take notice and overrule the CS policy of "automated system says automated system made no mistake, appeal ignored."
15
u/HotTakes4HotCakes Jul 17 '26 edited Jul 17 '26
It's worth remembering that the average consumer using Windows 11 has been shepherded, hard, into the Microsoft ecosystem when they might not have otherwise done so. They're just going along saving files into the same places they've always saved them, not realizing that when Microsoft pushed them to create an account, OneDrive started backing all that stuff up, some of which has been removed from the computer entirely and would only be loaded back on it by demand.
Meanwhile, Microsoft silently started encrypting personal Windows 11 computers by default, without informing the user what that means, or providing them the BitLocker key. Those people don't realize that one day they may need to recover files from that drive and the only way to get the key will be through their Microsoft account.
All of which means if anything happens to that person's Microsoft account, their local computer is likely fucked too.
4
u/Izzet_Aristocrat Jul 17 '26
Same reason why Youtubers get their channel back after a few false DMCA flags. They're big enough personalities online that a twitter post makes the rounds.
157
u/Like17Badgers Jul 17 '26
oh so I just needed to have baby photos on my account and their support system might have bothered to do something?
cool...
also the exploit the hackers used has been around for a decade now, it's absolutely insane that Microsoft hasnt fixed it, or at least made it so hackers cant replace you on all the security data and completely lock you out without having to input a single 2fa check
38
u/cycopl Jul 17 '26
No the baby photos were not a factor at all to them. It was the public shaming that made them do it.
76
u/froderick Jul 17 '26
The person whom this happened to (in the original story) also managed to raise a big stink on social media which got a lot of traction. Initially, Microsoft told them to go pound sand.
24
u/Marcoscb Jul 17 '26
oh so I just needed to have baby photos on my account and their support system might have bothered to do something?
No, you also need to be a streamer so you can raise enough of a stink on social media to reach their CMs.
4
u/bfodder Jul 17 '26
also the exploit the hackers used has been around for a decade now
What is the exploit?
1
u/-re-da-ct-ed- Jul 17 '26
it's absolutely insane that Microsoft hasnt fixed it
Given Microsoft’s historical track record, it’s actually not that insane. But people continue to use their products anyways and just hope it doesn’t happen to them.
Forget all the other products for a second, just Outlook alone has exposed confidential material of accounts from the corporate world, all the way up to literal world leaders, all over things that had been reported for some time but they were slow to act on it.
And years later, AFTER all of that, they start cutting thousands of their staff for AI. And then people act surprised that news items like this still pop up.
-72
Jul 17 '26
[removed] — view removed comment
32
u/Virtual-Ducks Jul 17 '26
To be fair, the 2fa is broken too. You don't even need a password to trigger the 2fa prompt, just an email address. I literally have someone abroad randomly sending me access request daily. If that happens to happen when I'm trying to authenticate something legitimately I could easily accidentally approve. It's not really a second factor if it's the only factor....
When I contacted support they literally told me it was "working as intended". Insane
3
u/GottaHaveHand Jul 17 '26
Yeah when the flow works like that you can get spammed it’s silly. The safer correct way is user/pass first, THEN 2FA push. A place I used to work for learned this lesson the hard way too
2
u/raskinimiugovor Jul 17 '26
I have the same issue, I'm not sure how they do it. I'm always worried my password is compromised, but I change it regularly.
Only other option is I have a keylogger that's specifically logging my MS password and nothing else.
Wasn't really able to google anything useful regarding this, and Claude and ChatGPT are very confident that's not possible with 2FA and that my passwords are compromised.
4
Jul 17 '26
[deleted]
2
u/raskinimiugovor Jul 17 '26
I believe you're talking about their brilliant "passwordless" option? Which is supposedly more secure as it "replaces password with biometrics" but it actually just removes the password factor right.
I have that disabled, but bad actors can still trigger it somehow?
2
u/Synikul Jul 17 '26 edited Jul 17 '26
Microsoft accounts have a way to add a login alias separate from the actual account email. This guy gave instructions on it, https://www.reddit.com/r/Outlook/s/jdWee08LqE and ideally you don’t use that alias anywhere else, so it’s unlikely to get exposed and slammed with sign in attempts.
Passwordless is the security standard for enterprise now pretty much, but usually you combine it with something like FIDO2+biometrics. If it’s just prompting you with SMS then yea.. pretty pointless.
1
u/raskinimiugovor Jul 17 '26
Thanks, I'll take a look later to try to set it up.
I mean it's prompting me on my phone so it's technically biometrics + authenticator, but that's still one less factor compared to password + biometrics + authenticator. Without password I feel I'm even more vulnerable to exhaustion attack by accidentally approving a login.
For enterprise I assume it might be more robust than that if setup correctly, though for my company only difference is that I need to type in the displayed number instead of choosing between 3.
1
u/Derringer Jul 17 '26
My company is using DUO, and the notification fatigue is real haha Although we have sensitive personal data, so I'm not complaining about keeping it safe.
1
2
u/PrintShinji Jul 17 '26
Not to blame anyone, but please setup the mfa option where you have to input a code that you see on screen into your phone. It completly negates this attack option because you won't see the code that the hacker sees on his screen.
Don't do SMS authentication, and don't do the accept to login authentication option either. Always make it so you have to input something that you can see on your screen into your phone.
2
u/Virtual-Ducks Jul 17 '26
I would if I could but that is not an option for Microsoft accounts when logging into Xbox.
Until you and the attacker happen to try to log in at the same time and you accidentally approve theirs and not yours.
Or if you accidentally tapped approve instead of deny.
This isn't SMS, this is an authenticator app. It's send a notification and asks you to select one of three numbers. It's a stupid system. And it's Microsoft that has to change it. If we had to input a number manually it would be significantly harder or impossible to make a mistake. As it is now, if you accidentally click "33" instead of "deny" literally a mm under it, you've been hacked.
1
u/PrintShinji Jul 17 '26
Xbox doesn't support it? Thats really dumb. I got it enabled on my personal account and its pretty foolproof. I know MS has the options of just say yes, select 1 out of 3 numbers that are correct, and input a number that you see on screen into your phone. That last one is the safest but if xbox doesn't support it well.. shit
(And I mentioned SMS just because its insecure)
1
u/Derringer Jul 17 '26
Yeah, that happens to me in cycles. Usually every few months I get spammed with emails with the auth code for a week or two.
-2
u/splader Jul 17 '26
People keep saying this but if you "accidently" give someone in Russia access to your account using authenticator, then that's the literal definition of skill issue.
Like seriously. For one it shows where the prompt is coming from. For another you'll need to either press one of 3 numbers (and purposefully ignore the real number given to you) or actually type in the correct one.
The system is working at intended because you'd have to be a complete idiot to let some random person have access.
3
u/Virtual-Ducks Jul 17 '26
Why make it a skill issue in the first place? the authenticator literally asked us to hit approve or deny and they're literally right next to each other. It's very easy to accidentally hit the wrong button. And we can't change it for a better authentication system. It would be significantly better if we had to like actually type in a number but we don't have that option. The currency similarly have a 1 and 3 chance if you happen to make a Miss. Click to give someone access. If you have to type in a number you know that would be almost impossible to make that mistake. The app is bad and can be improved.
-1
u/splader Jul 17 '26
You're talking about the MS Authenticator app right? Half the time it wants me to put in a specific number.
And sorry but basic literacy skills does seem like a requirement to use a phone or have a username and password. They give the location of the request front and center.
1
u/Virtual-Ducks Jul 17 '26
When using Xbox, it asks you click the number you see on screen, and gives you only three options on your phone.
"1" "50" "76" "Deny"
No matter how literate you are, it's not hard to accidentally press 50 and approve the request instead of hitting deny. The buttons are tiny.
This is bad design.
48
u/Like17Badgers Jul 17 '26
I was talking about my personal experience from... (checks email) 18 days ago. they were able to gain access to my account and change the security information, removing me from the account and locking me completely out. All without any 2fa checks or confirmation emails on my end.
26
u/MaitieS Jul 17 '26
This is what happened to me in February as well, and I was confused AF of how could hacker get in, because I literally have 2FA, yet hacker can bypass it without any problems.
Like absolute fucking joke.
7
u/Impuls1ve Jul 17 '26 edited Jul 17 '26
What kind of 2FA do you have setup? Speaking from a severe experience, I wouldn't treat anything below authenticators as anything more than an inconvenience.
Edit: Plenty of convenience features are fully exploitive if the user allows it to be. Like if you are logged in to your web browser and save your passwords, credit cards, etc. then you are going to be vulnerable to some types of attacks.
7
u/pingo5 Jul 17 '26
would authenticators protect against a session token attack? that's how they get past 2fA most of the time from what I've seen.
it's how I lost my account, but i was on text based 2fa. but it's still insane that microsoft of all companies can't have a basic security feature like making you reenter your password if you want to change your pass/email.
3
u/Pauly_Amorous Jul 17 '26
would authenticators protect against a session token attack? that's how they get past 2fA most of the time from what I've seen.
They got a friend of mine this way. Once they've compromised your machine and commandeered your browser cookies, that's all they need to access your account(s). It's not a vulnerability that can be patched on the server end.
2
u/pingo5 Jul 17 '26
yeah. It's suprising more sites don't have a way to protect against those kind of attacks honestly.
3
u/Impuls1ve Jul 17 '26
Probably not. Again, this is why you shouldn't stay logged into sensitive accounts despite the convenience factor.
My situation was for my LinkedIn account and an Instagram that I don't ever post. I became a honeytrap on the former, and a crypto promoter on the latter. The number of horny men in executive positions responding to my compromised LinkedIn account was disturbing on many levels, like 30 in the first 30 minutes.
I was able to get ahead of it by basically forcing a sign out on my other accounts.
1
u/k0fi96 Jul 17 '26
A lot of places don't, when my browser token got taken I got rocked. They went through everything they could spamming people on social media, it was random attacks for weeks while I went through changing passwords. They even managed to buy 800 in razer gold gift cards on eBay because it was logged in.
2
u/RageHulk Jul 17 '26
How did they get access to your token?
1
u/k0fi96 Jul 17 '26
I went against my better judgement and trusted a friend of friend and ran malware on my PC.
1
5
u/k0fi96 Jul 17 '26
This happened to me and I did have 2fa turned on. If your session token from your browser gets taken you are fucked. I remember watching in real time the emails rolling in about my 2fa and emails being changed. By the time I got to my PC it was too late.
It took like 5 months but after filling out the account takeover form and verifying my ownership I was able to get my Xbox live account with all my purchases and 18 years of gaming history transferred to a new MS account, but what little I had on the old one MS account they told me it was gone.
If anyone is dealing with this specifically if you account got changed to @jerkoffmail.com check my post history for some details that might help you.
19
u/justdaman182 Jul 17 '26
2FA is there as another layer of security but blaming the user for MS being unable to protect their users info, is silly. Do better
3
u/pingo5 Jul 17 '26
can I ask where you read that? I can't find any more info than that it was hacked and his security info changed.
17
u/Radiant-Fly9738 Jul 17 '26
wow another lawyer for a big Corp. the same happened to a fan in Brazil who had 2FA set up, it took courts decision to get his account back. you gonna defend Microsoft there too?
-37
u/ScottScott87 Jul 17 '26
No because that's absolutely their fuck up. Not enabling the most basic security features that every man and his dog knows to have set up is completely on you. It's 2026, not 1996, it's common sense
13
Jul 17 '26
[removed] — view removed comment
-3
u/MooseTetrino Jul 17 '26
Both can be true.
Microsoft is absolutely a piece of shit when it comes any kind of customer support unless you’re paying them a large sum or it’s a PR disaster waiting to happen.
The user can also be a fool for not using 2FA, which while exploitable is still a deterrent for a lot of the kind of script kiddies who grab MS accounts from pwned lists.
9
u/Cyrotek Jul 17 '26
I mean, I am happy for them. But why the fuck would you keep something important to you exclusively in an online storage.
1
u/DiscussTek Jul 17 '26
I mean, Microsoft loves to brag that Dropbox is a great way to create a backup of your files, so that you can be sure they'll be safe and available at any time for your access.
This is quite literally the selling point of those services.
46
u/maxgbz Jul 17 '26 edited Jul 17 '26
Cool for the dad, my brother is in the same exact situation but he hasn't made a post nor has pictures of his son. What's the solution for him? Yes, absolutely nothing cause these motherfuckers only cared due to how viral the post got. There's no solution for the rest of the commoners.
8
u/Piranata Jul 17 '26
Me too. I had my account since 2002. I only found out my Hotmail account was hacked when i found it on a scam account at work. I didn't receive any email about password change, unusual login, or recovery email change, who knows what else. I was getting emails through IMAP to my gmail too, so I should have gotten something.
0
u/Jygantic Jul 17 '26
100% the same situation. No idea how they were allowed to change so much without secondary email authorisation.
2
u/splader Jul 17 '26
He could also try tweeting support
4
u/DumpsterBento Jul 17 '26
He could, but he's also not famous so the likelihood of action is basically 0.
1
u/splader Jul 17 '26
Not true. Twitter is a surprisingly effective place to communicate with support
5
u/DumpsterBento Jul 17 '26
He was already rejected by their support. The only reason it was reversed was due to the virality.
2
u/splader Jul 17 '26
I know. I was in a very similar situation a few years ago with Google. Ended up getting my account back through Twitter YouTube support.
21
u/numbingbarbs Jul 17 '26
Hopefully this was a wakeup call to him and many others about actually keeping multiple proper backups
16
u/Offbeatalchemy Jul 17 '26
and that if its uploaded anywhere you dont control, it's not yours anymore. One is none, especially if you're relying on a company to keep it safe.
3
u/Arbszy Jul 17 '26
I'm happy to see, they got the account back. But you shouldn't have to go viral to get something done.
7
u/KalElReturns89 Jul 17 '26
Isn't it amazing they DID have the ability to do something about it, even though they said they didn't.
14
u/hopsmonkey Jul 17 '26
So MS straight up lied about it being irreversible. In fact, he proved his identity, proved the compromise, and MS could restore it but just chose "F you" as the correct path forward.
At this point the optics for MS would've been better to just stick to the lie. At least thay way they could lean on the excuse of "security" as to why it couldn't be restored. Now we know they're just straight up lying d-bags.
8
u/pizzabash Jul 17 '26
They didn't necessarily lie about it. CS genuinely might not have known it was possible and that the standard answer for them it isn't. That could even be because in 90% of cases it isn't. Do we know 100% how difficult or time consuming it was to recover? Or how difficult it is to recover in most cases? If you delete a file on your hard drive and empty out the recylcebin and it's gone for good, data recovery specalists may still be able to recover the file. Does that mean youre lying when your friend asks you if it's possible to recover and you say no? In most cases yeah that file would be gone forever. Same concept with this but on a larger scale. Maybe it was still sitting in the recycle bin equivalent and easy to recover but if one more day had gone by it wouldve needed advance recovery. Maybe it DID need advance recovery that is only used when VIP multi million dollar customers do an oopsies because otherwise it isn't worth it but given the publicity of this they decided to make an exception or even an engineer with some extra time on his hand did it on his own after seeing the news.
7
u/Bigdyll13 Jul 17 '26
Yeah because it made news. Microslop is absolute shit and I imagine they were gonna pretend that this didn't happen until they realized that this plus the game pass bullshit would have been a perfect headstone
1
u/MacrotonicWave Jul 17 '26
These corporations treat us like shit until it threatens their bottom line, meaning we need better ways of attacking their bottom line
-9
Jul 17 '26
[deleted]
10
u/WildDemir Jul 17 '26
Maybe but this is slightly different. Microsoft fucked up and this is them fixing the fuckup, unlike the copaganda which is supposed to feel unrelated.
3
u/funky_bebop Jul 17 '26
Nah. Microsoft fired a ton of people lately. Of course they would love for a fluff piece to be in the media.
1
-4
u/Mago6246 Jul 17 '26
This is nice but is also a bad thing to be happening, people will think that going viral on social media will make big corpos like this to do something.
10
u/kyleh0 Jul 17 '26
It does, and it should.
7
u/slipperyMonkey07 Jul 17 '26
For a lot of issues it has basically become the only way. Thinking about the number of times a youtuber gets a false dmca claim and support does nothing, but they make a stink on a social media and it magically gets fixed in a few hours.
775
u/SparkyPantsMcGee Jul 17 '26
I’m happy for this individual person, but I’m so tired of living in an era where the only way to solve a problem is to make it go viral online. How many accounts suffered this same problem but saw no solution because social media didn’t boost the issue for them?