Login

Microsoft patches bug that left Skype accounts open to attack (update)

Skype Windows 8 stock

Russian hackers have discovered a security hole in Skype's password recovery tool that allows a third party to take control of your account. All the hackers require is your Skype username and the email address that Skype account is registered to. With those details, they'll be able to access your account and change the password in a matter of minutes. The Next Web has tested out the five-step hack and reports that the process worked across several accounts, something which we've independently confirmed. The site says it contacted Skype several hours before going public with the story.

It's worth noting that your account is only vulnerable if the would-be hacker knows your email address. If you're worried that your address may be common knowledge, the simplest way to protect yourself from any attack would be to change the address your account is registered with. We've spoken to Skype, which says that it is currently looking into the issue.

Update: After temporarily removing the ability to reset passwords while it worked on a solution, Skype has now issued a fix for the security bug. The company also issued the following statement:

"Early this morning we were notified of user concerns surrounding the security of the password reset feature on our website. This issue affected some users where multiple Skype accounts were registered to the same email address. We suspended the password reset feature temporarily this morning as a precaution and have made updates to the password reset process today so that it is now working properly. We are reaching out to a small number of users who may have been impacted to assist as necessary. Skype is committed to providing a safe and secure communications experience to our users and we apologize for the inconvenience."

The Verge
X
Log In Sign Up

forgot?
Log In Sign Up

Please choose a new Verge username and password

As part of the new Verge launch, prior users will need to choose a permanent username, along with a new password.

Your username will be used to login to Verge going forward.

I already have a Vox Media account!

Verify Vox Media account

Please login to your Vox Media account. This account will be linked to your previously existing Eater account.

Please choose a new Verge username and password

As part of the new Verge launch, prior MT authors will need to choose a new username and password.

Your username will be used to login to Verge going forward.

Forgot password?

We'll email you a reset link.

If you signed up using a 3rd party account like Facebook or Twitter, please login with it instead.

Forgot password?

Try another email?

Almost done,

By becoming a registered user, you are also agreeing to our Terms and confirming that you have read our Privacy Policy.
Spinner.vc97ec6e

Authenticating

Great!

Choose an available username to complete sign up.

In order to provide our users with a better overall experience, we ask for more information from Facebook when using it to login so that we can learn more about our audience and provide you with the best possible experience. We do not store specific user data and the sharing of it is not required to login with Facebook.