Lockouts – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sun, 20 Apr 2025 04:17:39 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.8 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Lockouts – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Widespread Microsoft Entra lockouts tied to new security feature rollout https://earlybirdsinvest.com/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/ https://earlybirdsinvest.com/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/#respond Sun, 20 Apr 2025 04:17:39 +0000 https://earlybirdsinvest.com/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/

Microsoft with a red background

Windows administrators from numerous organizations report widespread account lockouts triggered by false positives in the rollout of a new Microsoft Entra ID’s “leaked credentials” detection app called MACE.

These alerts and lockouts began last night, with some admins believing they were false positives as the accounts have unique passwords that are not used on any other sites or applications.

Microsoft Entra ID, formerly Azure Active Directory, is a cloud-based identity and access management service that helps organizations manage user identities and secure access to resources.

In a Reddit thread posted early this morning, Windows admins reported receiving multiple alerts from Entra indicating that some of their user accounts had been found with credentials leaked on the dark web or other locations.

These accounts were automatically locked out of the tenant, with numerous users impacted per organization.

“Us as well… about 1/3rd of our accounts got locked out about ~1 hour ago. We’re a MSP so I’m assuming this is happening to our clients as well,” posted an admin on Reddit.

The locked-out accounts showed no signs of compromise, such as suspicious sign-ins, and were protected with MFA. Furthermore, breach notification services like Have I Been Pwned (HIBP) had no matches for these accounts.​

Another report on Reddit further corroborated that this was widespread, with an MDR provider stating they received over 20,000 notifications from Microsoft overnight regarding leaked credentials from different customers 

While Microsoft has not publicly confirmed the cause of these lockouts, Microsoft told one of the affected organizations it was caused by an issue with the rollout of a new Enterprise application called “MACE Credential Revocation.”

“Just got off with engineer. It is Tenant Lockout due to this MACE ninja rollout they did. no signs of compromise. He needs an hour to convert the ticket from compromise to lockout but can breathe a sigh of relief. It was Error Code: 53003 for conditional access policy,” an admin reported on Reddit.

Multiple people confirmed this application was added to tenants right before they began receiving the alerts.

MACE Credential Revocation app is a Microsoft Entra feature used to detect leaked credentials and lockout potentially compromised accounts.

While all alerts of leaked credentials should be investigated to confirm that an account was not compromised, if you received a flurry of alerts at once this rollout likely caused it.

BleepingComputer contacted Microsoft with questions about this incident but has not received a response at this time.

]]>
https://earlybirdsinvest.com/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/feed/ 0 31795
ZachXBT Slams Coinbase for Account Lockouts, Undisclosed Breach Leading to User Losses https://earlybirdsinvest.com/zachxbt-slams-coinbase-for-account-lockouts-undisclosed-breach-leading-to-user-losses/ https://earlybirdsinvest.com/zachxbt-slams-coinbase-for-account-lockouts-undisclosed-breach-leading-to-user-losses/#respond Mon, 07 Apr 2025 22:36:07 +0000 https://earlybirdsinvest.com/zachxbt-slams-coinbase-for-account-lockouts-undisclosed-breach-leading-to-user-losses/

Crypto investigator ZachXBT has publicly criticized Coinbase, calling out the popular crypto exchange for repeated account lockouts and an undisclosed data breach, which he claims led to thefts.

In the latest tweet, the on-chain sleuth expressed his dissatisfaction and stated that Coinbase had locked him out of his account twice in the past month without providing an explanation. He also highlighted the company’s failure to transparently disclose a recent breach that exposed customer data, which allegedly led to financial losses for some users.

While acknowledging that Coinbase offers competitive annual percentage returns on stablecoins, ZachXBT concluded that he could not recommend the platform to others due to these unresolved issues.

Data Breach, Account Lockouts, and Lack of Transparency

ZachXBT’s comments come amid growing concerns about Coinbase’s handling of user security and support. Despite marketing itself as a secure, transparent, and regulated platform, the exchange has faced a series of challenges.

Coinbase, which went public in 2021, has long positioned itself as a gateway to the crypto world for both institutional investors and newcomers. However, incidents like the one ZachXBT described paint a different picture for more experienced users.

This isn’t the first time ZachXBT slammed Coinbase. He had previously lashed out at the exchange’s leadership for failing to report theft addresses, provide responsive support, or react swiftly to threats. His findings revealed that at least $65 million was stolen through these scams between December 2024 and January 2025.

The scammers allegedly impersonated Coinbase support using spoofed communications to trick users into transferring funds to compromised addresses. ZachXBT attributed the scams to Indian groups and low-level cybercriminals while criticizing Coinbase’s inadequate response.

Coinbase Controversies

This latest comment adds to a history of security-related concerns for the platform. In 2021, Coinbase users reported being locked out of their accounts for extended periods, often during times of high volatility in the market. Many of these users struggled to get timely support, leading to significant financial losses.

Coinbase faced accusations of account restrictions last October as well. During the same period, several users of the platform also reported security threats, with attackers impersonating Coinbase support. A researcher under the pseudonym ‘pcaversaccio’ lashed out at Coinbase’s position on VPNs, which was defended by the platform.

The exchange’s Senior Director of Product Management, Scott Shapiro, later clarified that VPNs alone don’t raise flags, but combined with suspicious activity, such as unfamiliar logins, they may prompt security checks.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

]]>
https://earlybirdsinvest.com/zachxbt-slams-coinbase-for-account-lockouts-undisclosed-breach-leading-to-user-losses/feed/ 0 29583