AntiMalwareJuly 15, 2026🇷🇺Translated from Russian

Microsoft Permanently Locks Hacked Account After Security Changes, Erasing 25 Years of OneDrive Data and Purchases

A streamer named Joshua Kane has permanently lost access to 25 years of personal digital content after his Microsoft account was compromised. The attacker changed the account’s security details, allowing them to take full control and lock out the original owner.

Along with the account itself, Kane lost all files stored in OneDrive, including family photographs of his son as an infant, as well as years of purchased games, applications, and other digital services. Microsoft acknowledged that the profile had indeed been hacked and belonged to Kane, yet support staff refused to restore access.

According to the company, once an attacker modifies security settings, internal policies prohibit employees from manually returning control to the original owner. The lock has been declared permanent, and the associated files are now inaccessible even to Microsoft engineers.

The corporation further explained that content stored in OneDrive cannot be extracted because of the service’s encryption architecture and strict privacy protections. Kane was told to purchase his games and services again on a newly created account.

The story rapidly spread across social media, with Kane’s post receiving more than two million views within 11 hours. Numerous other users began sharing comparable cases of permanent account loss following similar takeovers.

While Microsoft’s formal rules allow account suspension when fraudulent activity is suspected, the temporary measure can easily become a lifetime ban once an attacker updates recovery information. Kane himself admitted that he had not adequately protected the account.

The incident serves as a stark reminder that two-factor authentication is essential and that storing the only copy of important files in the cloud does not constitute a true backup strategy. Unlike a physical device, cloud storage cannot be stolen with a flash drive, yet a single successful compromise can permanently sever the owner’s access.

Related articles

AntiMalwareFraud & Social Engineering

Positive Technologies Uncovers Disinformation Factory Linking 45 Domains and 74 Telegram Channels

Researchers at Positive Technologies have exposed an integrated disinformation operation that combined fake government emails with a network of pseudo-news websites and synchronized social media channels. The campaign began with emails sent from lookalike domains such as minpromtorg.digital and gosuslugi.digital, requesting employee lists and salary data to prepare targeted phishing attacks. Parallel to the email activity, operators maintained at least 45 domains including rulenta.live and crime24.live that mixed genuine stories with fabricated content and cited nonexistent sources. These sites were amplified through dozens of Telegram channels and accounts on VKontakte, Odnoklassniki, YouTube, Instagram, and TikTok, creating a self-reinforcing loop where fabricated claims were quoted back as credible reporting. Investigators noted a possible infrastructure overlap with the cybercriminal group Rare Werewolf, although direct attribution remains unconfirmed. The operation demonstrates a complete information pipeline from initial reconnaissance via email to wide distribution of disinformation across multiple platforms.

AntiMalwareFraud & Social Engineering

Russian Interior Ministry Advises Citizens Against Posting Personal Dossiers on Social Media

The Russian Ministry of Internal Affairs has issued a public warning urging citizens to reduce the amount of personal information shared on social networks. Details such as places of study and work, home addresses, and family information should remain outside public profiles to avoid attracting the attention of fraudsters and recruiters. According to materials cited by RIA Novosti, such digital self-portraits allow malicious actors to study potential victims, identify vulnerabilities, and craft personalized communication scenarios. The ministry also recommends avoiding public discussions of personal views and refraining from answering questions from strangers. Users are advised to verify profile ownership before engaging and to block suspicious accounts while reporting them to platform moderators. This marks the second such advisory from the ministry within recent months, following an October 2025 reminder about the risks of exposing full names, birth dates, and other identifiable data.

BoletimSecFraud & Social Engineering

Cordial Spider Deploys Work Panel Platform for Tech Support Scams Against Corporate Identities

A criminal platform called Work Panel is turning fake technical support calls into structured operations aimed at taking over corporate accounts. The service combines target research, page cloning, telephony, and credential capture within a single control panel. It is linked to the group tracked as O-UNC-045, also known as Cordial Spider. Campaigns target users of multiple identity providers and combine telephone social engineering with fake authentication pages. Operators research names, job titles, corporate emails, phone numbers, and professional profiles before calling to impersonate help-desk staff. While one operator keeps the victim on the line, a manager monitors the phishing session in real time. Captured credentials are sent only to operation managers via Telegram, reducing internal theft risks among the criminals themselves.

AntiMalwareFraud & Social Engineering

Scammers Deploy Fake Russian Defense Ministry Websites to Harvest Data from Relatives of Fallen Soldiers

Russian threat intelligence firm F6 has uncovered a phishing campaign that used counterfeit Ministry of Defense portals to target relatives of participants in the special military operation. The attackers registered lookalike domains and populated them with official logos, coats of arms, and navigation menus copied from the legitimate mil.ru site, leaving only the registration form under their control. Victims were invited to register for state awards ceremonies and asked to supply full name, phone number, passport details, SNILS, and INN; an additional “Add guest” button collected the same information for accompanying persons. The stolen data can be used to reset access to government services, apply for microloans, or launch follow-on social-engineering attacks against military families. F6 analysts noted that the fraudulent pages were likely generated with a large language model, evidenced by an unhandled JSON error that appeared only after data submission. Although the discovered domains have been blocked inside Russia, the low technical barrier means new clones can be stood up quickly.