TL;DR: someone managed to add a stolen credit card and shipping information to my account, ordered $160 worth of digital xbox gift cards, and redeemed those cards this morning.

There are no suspicious logins on my account, and I have verification and 2FA turned on.

Microsoft not only does not care, they also claim that any unauthorized activity on a user's account is the user's responsibility.

So that's fun.

transportation.social/@DrTComb

@DrTCombs I'm very interested in how they were able to add a credit card and billing address to your account without (apparently) being able to sign in.

My main worry for you is if/when the likely stolen credit card is reported your account will be the one that gets suspended. If you have anything important through that account I'd be sure to take some backups if you can.

@DrTCombs Did you get an email with an order number?

I'm wondering if they did a checkout as guest. I can't figure out what conditions allow you to checkout as guest, but they I saw they have this separate lookup for guest orders

microsoft.com/en-us/store/gues

Follow

@wesley
Yep, I found out about the purchase due to an email confirmation, with order number.
I logged into my Microsoft account through a different browser and sure enough, the order was there

Sign in to participate in the conversation
transportation.social

A Mastodon instance for transportation professionals!