News

Microsoft warns hackers are exploiting password resets to gain access to user accounts - here's how to stay safe

  • Sead Fadilpašić--TechRadar
  • published date: 2026-05-20 18:05:00 UTC

Storm-2949 is engaged in a "methodical, sophisticated, and multi-layered" campaign against Microsoft 365 accounts.

<ul><li>Microsoft researchers warn Storm‑2949 is abusing the Self‑Service Password Reset flow to hijack accounts</li><li>Attackers trick victims into approving MFA prompts via phone calls, then reset… [+2703 chars]