Skype patches account hijack that affected “a small number of users”

Skype has fixed the loophole allowing accounts to be compromised with little more than an email address, claiming that only “a small number of users” may have been impacted by the flaw. In a new statement, the Microsoft-owned VoIP company said that it had “made updates to the password reset process” after temporarily blocking the feature in response to the alert.

According to initial reports, the hack was facilitated by Skype’s handling of new account setups which, paired with the way account recovery was managed, created a way for third-parties to change the passwords of existing users. By attempting to create a new account using an email address already used by an existing user, Skype would give a reminder of that existing username.

A second stage to the exploit allowed the password to be reset by the interloper. If the targeted user was not paying attention to their account, they could find they were locked out and their Skype credit – as well as the cloud-hosted chat logs from the past few months, which Skype offers no way to delete – were accessible by a third party.

“Early this morning we were notified of user concerns surrounding the security of the password reset feature on our website. This issue affected some users where multiple Skype accounts were registered to the same email address. We suspended the password reset feature temporarily this morning as a precaution and have made updates to the password reset process today so that it is now working properly. We are reaching out to a small number of users who may have been impacted to assist as necessary. Skype is committed to providing a safe and secure communications experience to our users and we apologise for the inconvenience” Skype

However, Skype is yet to comment on suggestions that the Russian hackers who initially identified the flaw alerted the company several months ago, but received no acknowledgement of the issue. We’ve reached out to Skype for further comment on the allegations.

 

Skype patches account hijack that affected “a small number of users” is written by SlashGear.
© 2005 – 2012, SlashGear. All right reserved.


Related posts

Latest posts

ChatGPT’s latest image tools are stirring up another viral and creepy trend

ChatGPT's new image tools pose a risk of being misused for stalking.

TORRAS Ostand Air Case deal: save 15% for Earth Day

is almost here, and TORRAS is making it even easier to celebrate sustainably without sacrificing style. From April 18 to April 25, you can score 15% off the TORRAS Ostand Air Case (available for , , and ) when you use code ostand321 at checkout. It’s the perfect time to refresh your phone case with […]

The HP Victus gaming PC with RTX 4060 is under $1,000 with this deal

The HP Victus 15L gaming desktop with the Nvidia GeForce RTX 4060 graphics card is on sale from HP for only $850 following a $350 discount.

Amazon’s Marvel-themed ‘Pro’ kids tablet is marked down to just $95 today

This deal on an Amazon Fire HD 8 Kids Pro tablet gets you a Marvel-themed tablet for just $95, not $150.

Order a Retroid Pocket Mini? We’ve got bad news

Did you pre-order the Retroid Pocket Classic? You might want to check your emails as there's some bad news.

Synology brings severe hard drive limitations to DiskStation models, and I’m pissed

Synology is launching its 2025 DiskStation portfolio shortly, but before that, the brand's controversial decision to enforce its own hard

The Galaxy A56 is the worst mid-range phone I used in 2025

I used a lot of great phones in 2025 — the Galaxy A56 isn't one of them.

Meta updates Ray-Ban smart glasses with ‘natural’ AI voices and expands apps

Meta started rolling out an update for its Ray-Ban smart glasses.

Outdated network tech in Chinese state-owned telecom providers are claimed to be putting global data at risk

The report says unencrypted mobile interconnect providers in China are said to be putting everyone's data at risk.

Google Chrome finally brings the long-awaited bottom address bar for Android

The new bottom address bar allows users to navigate and open tabs in the browser quite easily and is useful