Microsoft warns that hackers could spoof Xbox Live site using leaked security certificate (updated)

Before making any changes to your account on the Xbox Live website, double-check to ensure you’re not on a fake page designed to steal your data.

Microsoft has warned today (first reported by ZDnet) that it has “inadvertently disclosed” the security certificate for its Xbox Live website, which resides under the Xbox.com domain. This means that cyberattackers could duplicate an Xbox Live website without triggering any of the warnings you would get for browsing a site with faulty certificates. Hackers could then perform something akin to a “man in the middle” attack where it makes you believe you are communicating directly with Microsoft, but it is instead intercepting and saving all of your sensitive information.

Unlock premium content and VIP community perks with GB M A X!
Join now to enjoy our free and premium membership perks.
Already a member? Sign in