ShadowMap

Dark Web Exposure for microsoft.com

Credentials, devices and data found in dark web stealer logs & breaches
100
Exposure level: Critical
microsoft.com scores 100/100 based on leaked credentials, compromised devices, and stolen financial & session data found on the dark web.
Most recent exposure 20 days ago Last 90 days +12% 0% reuse a top-10 password
Employee exposure
corporate accounts — @microsoft.com
37,817
leaked credentials · 1,026 compromised devices
Top exposed employee accounts
shal***@microsoft.com465
microsoft.com216
ijlobia***@microsoft.com162
pet***@microsoft.com126
***@microsoft.com87
Where staff accounts were caught
msft.sts.microsoft.com3,942
login.live.com2,303
login.microsoftonline.com1,292
corp.sts.microsoft.com997
certauth.msft.sts.microsoft.com724
Customer exposure
stolen logins for microsoft.com
1,142,228
leaked credentials · 7,867 compromised devices
Top exposed customer accounts
admin30
ahmed11
luis10
tusharswainod219
mohammed7
Most targeted services
signup.microsoft.com631,100
developer.microsoft.com201,930
admin.microsoft.com79,749
cmt3.research.microsoft.com29,053
invitations.microsoft.com23,912
1,173,359
Exposed Credentials
7,938
Compromised Devices
4
Credit Cards
204
Crypto Wallets
14,257
Auth Tokens
24,633,723
Stolen Cookies

Exposure over time (credentials leaked per month)

2024-012026-05

Corporate SaaS & shadow-IT exposed (employee logins to third-party services)

Microsoft6,686
Microsoft 3654,537
Amazon/AWS678
LinkedIn141
Adobe103

Most common passwords 0% reuse a top-10 password

ad***in430
Of***65394
P@***rd303
12***56275
Tt***34264
De***d.250
GE***35248
ht***ps239
30***is236
Pa***23233

Stolen sessions (active cookies that can bypass MFA)

youtube.com795,863
google.com432,932
bing.com280,569
pubmatic.com271,344
adnxs.com268,075
criteo.com219,763

Compromised despite antivirus (AV installed on infected devices)

Windows Defender222
Avast Antivirus19
AVG Antivirus7
McAfee7
Panda Dome6
Kaspersky5

Financial, crypto & app tokens

Crypto wallets
metamask121
okx25
exodus19
phantom19
trust14
ronin4
App / session tokens
Google12,854
Discord1,042
Telegram361

Where devices were compromised (by country)

Mexico [MX]44
Colombia [CO]42
Peru [PE]37
Argentina [AR]17
Chile [CL]17
Top cities
Lima25
Caracas7
Bogotá6
La Paz6
Buenos Aires5

Browsers & apps affected

Microsoft Edge (Default)1,620
Edge [Default]1,596
Google Chrome (Default)918
Chrome [Default]487
Google Chrome (Profile 1)378
Google Chrome (Profile 3)227

Stealer malware families seen

RedLine

Related companies

Explore

Check your own exposure →

Free dark web & attack-surface check by ShadowMap

Figures are aggregate counts derived from dark web stealer logs and public breach data. Data is indicative and updated periodically.