
Microsoft
Data Breach on July 27, 2026
| Data Breach Report | |||
|---|---|---|---|
| Victim | microsoft.com | ||
| Threat Actor | ExfilSquad | ||
| Date Discovered | Jul 27, 2026 | ||
| Description | Microsoft Corporation is a technology company based in the USA (Washington), specializing in software, cloud computing, consumer electronics, personal computers, and digital services. | ||
| Leak Size | 130GB |
Credential Exposure for microsoft.com
We've indexed 177,830 @microsoft.com accounts from external breaches, plus 434,780 credentials for microsoft.com itself.
Last checked Aug 16, 2026
| @microsoft.com addresses from external breaches | |
|---|---|
| Third-party breaches | 157,606 accounts · across 3828 breaches · 133,580 with a plaintext password · most recent Aug 8, 2026 |
| Combo lists | 93,731 accounts · most recent Aug 15, 2026 |
| Phishing pages | 63 accounts · most recent Aug 15, 2026 |
| Passwords for microsoft.com accounts | |
|---|---|
| Combo lists | 374,986 logins · most recent Aug 15, 2026 |
| Infostealer logs | 159,408 logins · 131,341 infected devices · most recent Aug 8, 2026 |
Logins may belong to customers or to staff, and the data doesn't say which. None of this is necessarily connected to the ransomware attack above.
Is your organization next?
Microsoft was breached. Check if your company's credentials have been exposed in this or other data breaches.
Check your exposure →Continuous dark web monitoring alerts you when we find leaked credentials or session tokens for your company.