How Did Hackers Breach Microsoft’s Security, Create Millions of Fake Accounts?

This file photo from April 12, 2016, shows the Microsoft logo in Issy-les-Moulineaux, outside Paris, France. (AP Photo/Michel Euler, File)
This file photo from April 12, 2016, shows the Microsoft logo in Issy-les-Moulineaux, outside Paris, France. (AP Photo/Michel Euler, File)
TT

How Did Hackers Breach Microsoft’s Security, Create Millions of Fake Accounts?

This file photo from April 12, 2016, shows the Microsoft logo in Issy-les-Moulineaux, outside Paris, France. (AP Photo/Michel Euler, File)
This file photo from April 12, 2016, shows the Microsoft logo in Issy-les-Moulineaux, outside Paris, France. (AP Photo/Michel Euler, File)

The trustworthiness of the online authentication systems used to verify whether the user is human is currently under scrutiny. Microsoft recently uncovered a group of cyber criminals in a major development that exposed the widely-used authentication technique known as “Captcha”.

Microsoft uncovered a group of hackers, "Storm-1152", that sold 750 million fake Microsoft accounts that enable cyber criminals to execute their online attacks.

- The beginning

Storm-1152 is a group of cyber hackers that operates from Vietnam. It managed to overcome all the authentication terms required to create a Microsoft account.

The group initially targets the Captcha technique, a widely-used window that requests a user to type a series of letters or numbers, or click on parts of a picture depicting buses of stairs, to verify that they are human, not robots.

But this authentication method is becoming less efficient, as Storm-1152 found a way to deceive it and create millions of fake accounts.

The hackers used “machine learning” to train their special hacking tool on clicking in the right place on the verification pictures, explained François Deruty, expert at a cybersecurity firm, Sekoia.

Then, the Storm-1152 hackers sold these fake accounts on a website for actors planning attacks, such as phishing emails and ransomware, according to Deruty.

- Famous group

The Vietnamese group is well-known. While other countries like China, Iran, Russia and North Korea make headlines in most cybersecurity attacks news, Vietnam, like India and Türkiye, has many hacking groups that make progress every year, added Deruty.

Microsoft has blocked a part of its websites on the US territories following a federal ruling that approved the closure of the servers that the group breached. “They definitely have other websites somewhere else and an international collaboration is needed to shut them down,” the expert noted.

Defenses against techniques used by cybercriminals

There are novel techniques such as the multifactor authentication, which uses codes sent via SMSs for example, but it’s a matter of time before the hackers figure out its vulnerabilities.

Other methods include security keys provided by banks for better security, but expanding these novel methods require more time and money, while Microsoft still keeps the old versions of its different programs.



KAUST Scientists Develop AI-Generated Data to Improve Environmental Disaster Tracking

King Abdullah University of Science and Technology (KAUST) logo
King Abdullah University of Science and Technology (KAUST) logo
TT

KAUST Scientists Develop AI-Generated Data to Improve Environmental Disaster Tracking

King Abdullah University of Science and Technology (KAUST) logo
King Abdullah University of Science and Technology (KAUST) logo

King Abdullah University of Science and Technology (KAUST) and SARsatX, a Saudi company specializing in Earth observation technologies, have developed computer-generated data to train deep learning models to predict oil spills.

According to KAUST, validating the use of synthetic data is crucial for monitoring environmental disasters, as early detection and rapid response can significantly reduce the risks of environmental damage.

Dean of the Biological and Environmental Science and Engineering Division at KAUST Dr. Matthew McCabe noted that one of the biggest challenges in environmental applications of artificial intelligence is the shortage of high-quality training data.

He explained that this challenge can be addressed by using deep learning to generate synthetic data from a very small sample of real data and then training predictive AI models on it.

This approach can significantly enhance efforts to protect the marine environment by enabling faster and more reliable monitoring of oil spills while reducing the logistical and environmental challenges associated with data collection.


Uber, Lyft to Test Baidu Robotaxis in UK from Next Year 

A sign of Baidu is pictured at the company's headquarters in Beijing, China March 16, 2023. (Reuters)
A sign of Baidu is pictured at the company's headquarters in Beijing, China March 16, 2023. (Reuters)
TT

Uber, Lyft to Test Baidu Robotaxis in UK from Next Year 

A sign of Baidu is pictured at the company's headquarters in Beijing, China March 16, 2023. (Reuters)
A sign of Baidu is pictured at the company's headquarters in Beijing, China March 16, 2023. (Reuters)

Uber Technologies and Lyft are teaming up with Chinese tech giant Baidu to try out driverless taxis in the UK next year, marking a major step in the global race to commercialize robotaxis.

It highlights how ride-hailing platforms are accelerating autonomous rollout through partnerships, positioning London as an early proving ground for large-scale robotaxi services ‌in Europe.

Lyft, meanwhile, plans ‌to deploy Baidu's ‌autonomous ⁠vehicles in Germany ‌and the UK under its platform, pending regulatory approval. Both companies have abandoned in-house development of autonomous vehicles and now rely on alliances to accelerate adoption.

The partnerships underscore how global robotaxi rollouts are gaining momentum. ⁠Alphabet's Waymo said in October it would start ‌tests in London this ‍month, while Baidu ‍and WeRide have launched operations in the ‍Middle East and Switzerland.

Robotaxis promise safer, greener and more cost-efficient rides, but profitability remains uncertain. Public companies like Pony.ai and WeRide are still loss-making, and analysts warn the economics of expensive fleets could pressure margins ⁠for platforms such as Uber and Lyft.

Analysts have said hybrid networks, mixing robotaxis with human drivers, may be the most viable model to manage demand peaks and pricing.

Lyft completed its $200 million acquisition of European taxi app FreeNow from BMW and Mercedes-Benz in July, marking its first major expansion beyond North America and ‌giving the US ride-hailing firm access to nine countries across Europe.


Italy Fines Apple Nearly 100m Euros over App Privacy Feature

An Apple logo hangs above the entrance to the Apple store on 5th Avenue in the Manhattan borough of New York City, July 21, 2015. REUTERS/Mike Segar/File Photo Purchase Licensing Rights
An Apple logo hangs above the entrance to the Apple store on 5th Avenue in the Manhattan borough of New York City, July 21, 2015. REUTERS/Mike Segar/File Photo Purchase Licensing Rights
TT

Italy Fines Apple Nearly 100m Euros over App Privacy Feature

An Apple logo hangs above the entrance to the Apple store on 5th Avenue in the Manhattan borough of New York City, July 21, 2015. REUTERS/Mike Segar/File Photo Purchase Licensing Rights
An Apple logo hangs above the entrance to the Apple store on 5th Avenue in the Manhattan borough of New York City, July 21, 2015. REUTERS/Mike Segar/File Photo Purchase Licensing Rights

Italy's competition authority said Monday it had fined US tech giant Apple 98 million euros ($115 million) for allegedly abusing its dominant position in the mobile app market.

According to AFP, the AGCM said in a statement that Apple had violated privacy regulations for third-party developers in a market where it "holds a super-dominant position through its App Store".

The body said its investigation had established the "restrictive nature" of the "privacy rules imposed by Apple... on third-party developers of apps distributed through the App Store".

The rules of Apple's App Tracking Transparency (ATT) "are imposed unilaterally and harm the interests of Apple's commercial partners", according to the AGCM statement.

French antitrust authorities earlier this year handed Apple a 150-million euro fine over its app tracking privacy feature.

Authorities elsewhere in Europe have also opened similar probes over ATT, which Apple promotes as a privacy safeguard.

The feature, introduced by Apple in 2021, requires apps to obtain user consent through a pop-up window before tracking their activity across other apps and websites.

If they decline, the app loses access to information on that user which enables ad targeting.

Critics have accused Apple of using the system to promote its own advertising services while restricting competitors.