Microsoft found 44 million accounts using breached passwords

Microsoft has now forced a password reset on all these user accounts.
 By  Matthew Humphries  for PCMag  on 
Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

PCMag.com is a leading authority on technology, delivering Labs-based, independent reviews of the latest products and services. Our expert industry analysis and practical solutions help you make better buying decisions and get more from technology.

Microsoft has discovered 44 million user accounts are using usernames and passwords that have been leaked through security breaches.

As ZDNet reports, the vulnerable account logins were discovered when Microsoft's threat research team carried out a scan of all Microsoft accounts between January and March this year. The accounts were compared to a database of over three billion sets of leaked credentials and resulted in 44 million matches.

These accounts were spread between regular user accounts used by consumers (Microsoft Services Accounts) and enterprise accounts in the form of Microsoft Azure AD logins. In response, Microsoft explained, "For the leaked credentials for which we found a match, we force a password reset. No additional action is required on the consumer side ... On the enterprise side, Microsoft will elevate the user risk and alert the administrator so that a credential reset can be enforced."


You May Also Like

Microsoft goes on to recommend that, "Given the frequency of passwords being reused by multiple individuals, it is critical to back your password with some form of strong credential. Multi-Factor Authentication (MFA) is an important security mechanism that can dramatically improve your security posture. Our numbers show that 99.9% of identity attacks have been thwarted by turning on MFA."

Picking a password is always a trade-off between what's memorable and what's strong, which is why using a password manager makes so much sense. But we have another problem: security breaches expose passwords and they shouldn't be used by anyone.

While Microsoft did the right thing resetting the passwords on these account, it currently can't stop a user selecting a new password that's also been exposed as part of a past security breach. A positive next move would be to perform a check when a password is entered to see if it appears on a breach list, and if it is, to reject it and request the user pick something else.

Mashable Potato

Recommended For You

Microsoft 365 Outlook down: Microsoft breaks silence on outage
Microsoft logo

Microsoft says Copilot was summarizing confidential emails without permission
the copilot logo appears on a phone screen

Get the best of both worlds with this Microsoft Office license for Mac
MacBook on desk

Bring Microsoft Office staples to your Mac for less than $9 each
MacBook keyboard

More in Tech

The DJI Mini 5 Pro drone is down to its best-ever price at Amazon — save $500 this weekend
DJI Mini 5 Pro Fly More Combo

California just launched the country's largest public broadband network
Newsom stands behind a teen on a computer. A group of people cheer and clap behind them.

The Shark FlexStyle is our favorite Dyson Airwrap dupe, and it's $160 off at Amazon right now
The Shark FlexStyle Air Styling & Drying System against a colorful background.

Amazon's sister site is having a one-day sale, and this Bissell TurboClean deal is too good to skip
A woman using the Bissell TurboClean Cordless Hard Floor Cleaner Mop and Lightweight Wet/Dry Vacuum.

Trending on Mashable
NYT Connections hints today: Clues, answers for April 4, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 4, 2026
Wordle game on a smartphone

NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone


Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!