A Chinese hackers called Evil Shadow Team has hacked Microsoft India’s web store(www.microsoftstore.co.in), Similar to Sony’s PlayStation Network, Microsoft also stored users passwords were stored in plain text without any encryption and this makes easy for the hackers to obtain them.
On Sunday Night (10:00 PM IST) Microsoft’s India store displayed images posted by hackers as shown in above screenshot, where users will be greeted with the suspicious visage of a Guy Fawkes mask and a link to the hacker site (HackTeach) also posted on the homepage.
The Chinese site HackTeach shows images that illustrate the extent of the damage and the hacked page warned that an “unsafe system will be baptized”. Although hackers motivations is unknown, but there will be huge damage when hackers release all the Web sites users’ account details,including passwords on Internet.
At the time of writing this post Microsoft Store India was down and displays a message that Microsoft is working to restore access as quickly as possible. To make a note Microsoft store India official site was not run by Microsoft, but by Quasar Media, which has been appointed to operate & maintain Microsoft’s online store.
Today Microsoft conformied this attack and sent an alert email to all it’s users which says “Alert: Microsoft Store India Compromise – Please Update User Name & Password Information”.
Dear Ramakanth Reddy,
Microsoft Store Customer Update
We are writing to inform you that there may have been unauthorized access to some of your customer account information on Microsoft Store India (http://www.microsoftstore.co.in/). We have confirmed that databases storing credit card details and payment information were not affected during this compromise. However, exposed account details may include non-financial related information including e-mail address, password, order details and shipping address.
Microsoft Store takes this situation very seriously, and the company is diligently working to remedy the issue and keep our customers protected. We need your help in this regard and we ask that you please take the following steps to prohibit any further unauthorized access to your information.
Precautions You Should Take
In order to secure your account information, Microsoft Store will take the action to re-set your password. Please follow these steps to ensure your privacy is protected:
1. If you use the same e-mail and password combination on any other sites, including non-Microsoft websites or services, you should proactively change the password immediately to ensure your personal information is protected.
2. You will receive an e-mail with a temporary password and a prompt to create a new password. Please note, the password reset relates only to Microsoft Store India.
3. Once you receive the e-mail you should immediately create a new password, one that is both secure and familiar to you.
Microsoft Store is Here to Help
We understand that you may have additional questions and Microsoft Store is here to help. If you have specific questions about your Microsoft Store account or want more information about computing and personal security please contact us at 1800-102-1100.
We apologize for any inconvenience this incident might cause.
Microsoft Store India