Microsoft may have been hacked — what this means for you

Microsoft logo on black background
(Image credit: Josep Lago/AFP via Getty Images)

Updated March 23: Microsoft has confirmed that it was indeed breached, and we have more details.

Microsoft may have been hacked, with 37 GB of source code for Bing, Bing Maps and Cortana stolen. Or maybe not — Microsoft has yet to confirm the data theft, which was claimed over the weekend by a purportedly Brazilian group of hackers calling themselves Lapsus$.

The group seems amateurish, but its previous claims of hacking into the company networks of Nvidia, Samsung and Ubisoft have proven to be true. Today, enterprise single-sign-on provider Okta confirmed that Lapsus$ had indeed broken into its systems by stealing an employee password.

On Sunday (March 20), Lapsus$ put up what appeared to be screenshots of a Microsoft Azure DevOps cloud server containing the aforementioned items. Because the screenshot showed just part of an alphabetized list of projects, it's possible many other Microsoft assets were compromised.

On Monday (March 21), according to Bleeping Computer, the Lapsus$ group posted a torrent link for a 9-GB compressed archive, which when unpacked seems to be 37 GB of web-based features and mobile apps. There didn't seem to be any desktop software, such as Windows or Microsoft Office, involved, but Bleeping Computer said the files sure looked real.

Whether Microsoft did indeed have several gigabytes of source code stolen, it's not clear exactly how that could affect the end user. 

A French security researcher named Soufiane Tahiri claimed that valid Microsoft digital-signature certificates had been part of the Lapsus$ leak, which might let criminals and other attackers create malware that could get past Microsoft's defenses. 

However, Will Dormann of the U.S. government's CERT Coordination Center wasn't so sure.

For the moment, we're going to have to wait and see whether Microsoft confirms the data theft, or criminals really do start exploiting secrets disclosed by the apparently stolen data. We've reached out to Microsoft for comment and will update this story when we receive a reply.

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Read more
How to disable the Windows key
Microsoft patches over 160 security flaws including 3 active zero days — update your PC right now
Malware
New macOS malware uses Apple's own code to quietly steal credentials and personal data — how to stay safe
Discord on a phone and a laptop
Reported Discord data leak disputed by third-party service RestoreCard
Hooded cybercriminal sitting with laptop surround by hooks
New report details the brands that scammers like to impersonate most — and you'll definitely guess who's at the top
A hacker typing quickly on a keyboard
Thousands of WordPress sites hijacked to spread Windows and Mac malware - how to stay safe
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Latest in News
A mosquito resting on a plant
Experts predict a spring surge in these 9 pest populations — here's what's forecast for your area
Apple Watch SE (2022) shown on wrist
Apple Watch SE 3 reportedly in ’serious jeopardy’ — here’s why
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
Claude AI on phone sitting on keyboard
Claude 3.7 Sonnet now supports real-time web searching — but there's a catch
Nintendo Switch 2
Nintendo Switch 2 pre-order date just tipped — here's when you might be able to buy
Apple iPhone 16 & 16 Plus hands-on.
iPhone 17 just tipped for this long overdue Pro feature in new report