A tool for managing user identities, credentials, and access across on-premises and cloud environments
Microsoft’s servers have been hacked according to this article:
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
This afternoon I noticed a successful sign in on my Microsoft account from an IPv6 address. I am located in the US, so this is abnormal. The address is 2a01:111:f402:f0f9::f147. The location shows as Phoenix, Arizona.
Upon looking into the address, the signs point to it being a Microsoft Data Center. I reset my password anyway just out of caution.
I already had MFA enabled, my password was reset two weeks prior to this for unrelated reasons, and I never received a login notification after this event. There are no unknown devices or apps connected to my account.
I did update and shutdown my PC around 10-30 minutes before the login appeared on my account. Could this be from a Microsoft service accessing my account?
A tool for managing user identities, credentials, and access across on-premises and cloud environments
I am getting the same, but from a Microsoft datacenter in Canada. Changed my password after the first time I saw it, but this morning saw another login. I use 2fa using authenticator.
I (based in the US) received the same strange sign-in notification with a similar IP address about 11 hours ago. I also use MS Autheticator to sign in but got no Authenticator notification.
Same thing happened to me. An IPv6 account login successfully 2 days ago from the US (I’m based in Indonesia). My account is passwordless and there is no notification of this login activity on my MS Authenticator app. I forced logout from all devices just to be safe.
Same thing here, guys! I changed my password twice, enabled 2fA, disconnected all active sessions and yet there was this strange sucessful sign in on my account just a few hours ago.
What really intrigues me is that, besides the sucessful log in, there was no activity on my account whatsoever. No password change, nothing! Just the log in.
The first log in was on 24/07, then on 28/07 and lastly on 31/07 (today).
O mais esquisito nisso tudo é que não teve nenhuma alteração na minha conta. Só um login suspeito e mais nada. Eu tava muito tenso de início, mas fiquei tranquilo ao saber que não fui o único.
Yep, me too. Always used 2factor, reset password, signed out of everything, reset backup code.
Mine is coming from Japan every time, basically once a day.
I too have received two logins yesterday, both with a IPv6 address and both pointing to a Microsoft Data centre near Washington (I'm in the UK). I had 2FA and Authenticator but no notifications which is weird as when I went through the process everyone has it gave me loads of warnings things were being changed when I changed them. I wonder if it is some bug.
A little same to me. I am from Germany and it’s showing me probably the same data center. This may make sense because we are both from Europe and this may be the nearest datacenter.
Have the same issue in California. IPv6 successful sign in attempt, Authenticator showing Des Moines, Iowa using Password less and sign-in notification.
3rd time since July 25
Same issue for me.
Device/platform Unknown
Browser/app Unknown
IP address 2a01:111:f402:f154::f140
location: Montreal
is this an issue on Microsoft side?
Same issue for me, have we received any update from Microsoft for this problem?
I'm in Australia, and I've received the same alert from Canada with the address 2a01:111:f402:f078::f164
I was passwordless for as long as it was publicly GA, but out of caution I clicked "Secure account" underneath this successful but suspicious login attempt - I got two prompts in Authenticator this same morning, hence the alarm - and the security dashboard asked me to set a password?!
Now finding this thread, I'm starting to wonder if the seemingly random authentication requests I was getting in Authenticator were this same data center. Since the failed recent attempts appears to have been removed from the security dashboard, I can't see from where they were coming so it's hard to know if it was any of my devices. I checked them all, and all seemed to be able to fetch email from outlook.com at least.
I am glad to see that I am not the only one affected.
No mail notification due to login from a new device.
I asked the same question on reddit a few days ago:
https://www.reddit.com/r/Passwords/comments/1m9vr5n/microsoft_live_account_successful_login_despite/
I also chatted with Microsoft support, but they did not answer my question if these ip adresses really belong to Microsoft.
I would be shocked if this was NOT a Microsoft login, given how many others are experiencing the same issue.
I inquired with MS's Ai Co-Pilot. Basically, it said it is probably part of MS's maintenance ... but I've never seen anything like it before. Co-Pilot did say I can change my password, etc. However, I did not change anything, and I still have control of my account, which would be unusual if it were a hacker. It stinks that MS has not seen fit to tell us what happened, but it is probably a nothing burger. One that will forever be a mystery, it seems.
Hello
I live in France. I had the same issue this morning. The IP adress is 2a01:111:f402:f0a8::f138. It comes from Dublin
I changed my password.
I sent an email to MS support and I'm waiting its answer
Same here in Austria — 2FA enabled and suspicious logins from the following IPv6 addresses.
Paris
26.07.2025: 2a01:111:f402:f149::f143
27.07.2025: 2a01:111:f402:f149::f131
31.07.2025: 2a01:111:f402:f149::f132
Ireland
01.08.2025: 2a01:111:f402:f107::f135
I have the same problem. I'm based in Italy and it looks like someone succesfully accessed my account from Netherlands. However, the IP is slightly different:
2a01:111:f402:f047::f161
Jesus, this was bothering me. I even changed my password and forced a logout on all devices, but this log appeared again. Given the reports, it doesn't seem like a security issue, but rather something Microsoft has done.
Yeah sounds like Microsoft. First time I've ever been "hacked" and by Microsoft, worrying.
Same thing happened to me on Aug. 4 out of San Antonio (successfully log-in). I’m in Illinois. The ip address came back as being associated with Microsoft. My account is set to passwordless and 2FA, so there should be no successful log-in I would be unaware of. I forced logout on all devices and haven’t lost control of my email account or noticed any unusual activity in the account. This scared the shit out of me.
See this scared me too! And I’m actually based out of San Antonio geographically but keep getting logins from Phoenix. The whole thing is sketch and I’m sure there’s a good reason for it or at least an explainable one but big yikes.
Also had one from canada, apparently a Microsoft data center. would love to know if this in a hack or what. Microsoft please respond
Same issue happened to me in Canada as well. And the funny thing is, I changed my email alias 3 times so no one can use the old email for sign in, and guess what happened. That "IPv6" successfully signed in 3 times almost right away after I change the alias. No warning, no message, no authenticator approval, they just sign in like ghost. And Microsoft never responds to my post regarding the same issue.
Same for me although in my case the location is France - Paris to be exact.
No unusual 2fa codes asked for either so is very strange.
I have a similar situation. I checked my activity about a week ago and noticed a sign in the day before (august 3rd) from 2a01:111:f402:f0b1::f161, an address in Ireland. I thought this was a sign-in by someone else and that my password has been leaked at some point and I then secured my account further. I had 2FA and used it actively, but now went all passwordless and removed any legacy app-passwords, signed out from all my devices (which was only a few, and all known to me), moved my sensitve information in OneDrive into the "Personal vault". I created an alias and inactivated my e-mail address as means of sign-in method so now I have to sign in with an alias that no one can connect with my e-mail address. Now if anyone tries to sign in with my e-mail address as username the account doesn't exist. I have then checked my activity a few times per day. This morning I checked it from the MS Authenicator app and there was nothing. I then checked again tonight and there it was again a sign in from 2a01:111:f402:f0b1::f161 in Irland this morning. Pretty much the same time as I did sign in to check my account activity I believe. This lead me to search for the address and found this thread. I couldn't understand how anyone would be able to sign in after all measures I had taken. Yet it would be very good to hear some official response from MS about this and put some ease to this situation and the worries it creates for people. Gaining access to the e-mail alone is less then desirable, but if my OneDrive would be compromised it would be even worse I would say.
I am having the exact same issue. Yesterday, I signed out of every device and change my password, yet I still was able to notice a successful sign-in from San Antonio, even though my phone was not prompted for a 2FA.
Same thing here. It happened a few times now, all of them from Canada (I'm based in Brazil). I have commented in several posts about the same thing here and on reddit. Lots of reports about it.
I thought it was related to opening the outlook or onedrive app on my iPad, but last saturday I got the same successful login from Canada at 3:30am, a time I was obviously sleeping and not using anything. I've been worried about it for days. But now I just gave up.
Just wanted some official answer from Microsoft, cause this is really scary.
I’ve been dealing with the exact same issue. I contacted Microsoft multiple times already, they just keep giving me some generic suggestions, but no real help.
I got same issue. 2a01:111:f402:f0a5::f166 logged into my account from Dublin and I am from Spain.
Passwordless account.
https://unit42.paloaltonetworks.com/microsoft-sharepoint-cve-2025-49704-cve-2025-49706-cve-2025-53770/I came across this today - and it is a global problem. So basically Sharepoint server has been hacked which could make other platforms like onedrive vulnerable ; would definetly recommened to read as it could be the reason Microsoft are being so quiet about these data breaches, also the dates align with what people have been reporting. Take care!
key takeaway from article: "On-premises Microsoft SharePoint servers are currently facing widespread, active exploitation due to multiple vulnerabilities, collectively referred to as "ToolShell" (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771). These vulnerabilities enable attackers to achieve full remote code execution (RCE) without requiring any credentials. A compromised SharePoint server poses a significant risk to organizations, as it can serve as a gateway to other integrated Microsoft services."
Comfort Mmoledi,
Your assumption that those SharePoint vulnerabilities have anything to do with these completely unrelated IPv6 Activity log entries is inaccurate.
Though the article you referenced by PaloAlto Networks doesn't specifically mention it, it's been well known since at least July 22nd, per the following excerpt from the CISA article I'll reference below, that these vulnerabilities only affected on-premise SharePoint servers, not Microsoft's own cloud provided SparePojnt servers.
"CISA is aware of active exploitation of a spoofing and RCE vulnerability chain involving CVE-2025-49706 and CVE-2025-49704, enabling unauthorized access to on-premise SharePoint servers."
UPDATE: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities | CISA
Also note that SharePojnt and OneDrive are entirely separate systems operating on the Azure business and Microsoft Personal account-based systems respectively, so even if they might share portions of the same code that caused the vulnerabilities mentioned, that hasn't been confirmed in anything I've seen, nor should it matter, since the vulnerabilities themselves had been patched by Microsoft for their cloud-provided SharePoint servers before the exploitation of some customers unpatched on-premise SharePoint servers occurred. So even if OneDrive had contained similar code that might have been vulnerable, it's reasonable to expect that Microsoft would have realized this fact and fixed that parallel code as well, though I'd have expected them to mention this via a CISA or similar alert if it were actually true.
Microsoft has not been 'quiet about these data breaches' since everyone here with a level head has been stating there's nothing at all suspicious about these notifications, they're simply not something that most of those posting understand, so they're concerned because they don't have any past experience upon which to base the reason the notifications might be appearing in the Activity logs.
Those of us who understand that the mobile device apps that appear to be consistently involved in causing the log entries are often IPv6-based, quite often make connections with different servers in different countries, and in reality, may have little to do with the normal daily activities of the user himself, only find their sudden appearance for a limited subset of users globally an interesting curiosity.
In my case I've seen similar Activity display issues relating to IPv6 and specifically mobile devices as well back shortly after these first started to be supported officially on the Azure business platform a few years ago, since they also started to display with similar characteristics for Microsoft Personal account logins as well. However, since Microsoft clearly indicated more recently in the Activity logs that no maps were displayed for mobile devices, the appearance of these more likely back-end support connections within the Microsoft services operations displayed using IPv6 are obviously confusing to those without that same past experience.
I'm not saying I know for certain what every single one of these activity items might represent, but absolutely nothing I've seen described by anyone in the recent threads relating to these IPv6 entries has appeared truly suspicious, and in fact have always fit some of the less often described situations relating to either Microsoft Authenticator or other mobile applications like OneDrive that are known to operate in different ways than other apps.
Rob
Thank you for your time on this Rob; I just keep on getting those IPv6 entries appear in my activities and it has peaked my interest to do some digging into what may potentially be the cause.
Again, Thanks for clarifying.
Comfort
Comfort Mmoledi,
To be clear and simple about it, those users able to identify these log entries as related to access for either their Microsoft authenticator requests (think Push Notifications or others that obviously have to communicate directly with the servers to/from the app), or on rare occasions access via other apps like OneDrive, the explanation is simply that these apps are somehow accessing these servers in countries that often aren't typical for that user, which since these are specialized services that may not store data in those particular countries, is likely not strange at all.
The most confusing ones though might be those that occur at times the user himself doesn't seem to be involved at all and is sometimes even sleeping. But remember that maintenance tasks or even automated tasks the user has defined or selected themselves within the app might occur at these less busy moments, which since especially phones are typically 'always on' devices, isn't really so surprising if you think about it.
And since the Microsoft servers themselves often don't perform these tasks directly, since they require a client app to function, things like app clean-up of data on the servers might require a background authentication by either the device or some other process in order to function, leading to another often misunderstood impersonation log entry in the security logs of the device, which is one of the ways that Microsoft allows apps to take over and automate tasks the user himself might typically perform.
So in today's world of dynamic and automated systems we've all become accustomed to, none of this is truly suspicious or out of the ordinary, we just don't always notice or even get to see the actual operation of these actions, in many cases because the log entries themselves are actually suppressed both to reduce the number of excess entries stored, and also to avoid the kinds of confused and worried threads like this one, where non-technical individuals try to make sense of the highly technical and confusing processes required to make it all work.
I personally suspect that these recent IPv6 entries are actually just that, some set of entries that used to be suppressed that somehow a change in the systems involved has allowed a few of them to be logged and viewed.
Note that virtually all of those who've noticed are using the Microsoft Authenticator, and many seem to have been affected by the past issues where likely bots were attempting to attack that individual's Microsoft Personal account via password guessing in order to take over the account. In fact, that's really the reason many of these particular users are still checking the Activity logs, and what had them so rattled. While in truth, someone like me who spent 20 years as a Network Administrator in higher education and other businesses, as well as another 20+ as a security professional, had literally seen so many hundreds of thousands of these occurring daily against my users on the early Novell, Microsoft and Unix systems I managed even back in the 1990's, that I'm truly surprised my own long-ago exposed (to Spam) MSN - Microsoft Personal account has seen almost none of these for nearly a decade.
Rob
For me, this has been a hackathon and it continues. I have tried to lock down my account with multiple MFA‘s, signing out everywhere, password less, TOTP, standing on my head, etc. I still have successful signs from the exact same IPv6 address at the same geo location. Just had another one 12 hours ago
Earlier in August, I had 70 GB of data extracted out of my OneDrive via graph, which I have confirmed through looking at tenant logs. For those that are seeing these connections, make sure you check your https://entra.microsoft.com. I have the classic James Ridgeway in impersonated tenant ID. And since then, all of my information went into the dark web. I will never use OneDrive again.
@ Jim H
Do you use a personal or business Microsoft account? Have you checked the IP? Belongs it to MS?
Personal, formerly. I moved all of my data out of my OneDrive. Previously, I had an unauthorized device attached to my account called “PATROL-6004” near Springfield, Virginia. Has anyone else seen this? I don’t believe this is related to the recent BBC article regarding China’s “hacking“ of SharePoint. The IPV6 address(es) can be a misnomer. The feds and hackers use VPN’s. What concerns me is unauthorized devices connected to my account and seeing graph extractions!
Ok normally you can’t use Enatra ID with personal accouts or am I wrong. I don’t have any devices added to my account which are not mine.
You can see my newest experience in the comment of the BBC article :)
You are correct I think; Entra ID is for business accounts; you would need a tenant ID and you can pay for additional services etc. If you create a personal one drive you would have a seperate ID that just says Microsoft on the authenticator App on your phone. I cannot log into Entra ID because I have not used it in over 200 days so I am permenantly blocked.
I think for the graphs API which i've never heard of btw it only interacts with data people have given it and ofc granted permissions too, if you have a personal Onedrive i'm almost certain that Onedrive developers are not reckless enough for other developers to be able to access anyone's personal data from their personal Onedrives, if i'm wrong tell me I'm wrong but that would be ridiculous!
I have also recently seen this in the UK.
An early morning "successful sign-in" from an IPv6 address in the Netherlands (2a01:111:f402:f0c4:f142). I have 2FA enabled, wasn't in the Netherlands and didn't knowingly get a notification from the Microsoft Authenticator app (unless it timed out when I was asleep).
Microsoft’s servers have been hacked according to this article:
So what I read here is that most people with the problem have a personal Account. And those are not affected by the hack because the hack was on local SharePoint instances.
Also Rob Koch explained it before (see the comments on the first post)
Or I am seeing something wrong?
I think you are right. I think those hacks have nothing to do with our personal accounts.
But it is still really strange. I still think this is some Microsoft bug, but we can't hear anything back from Microsoft, no statements nothing. Really frustrating.
I have actual stated a privacy request to inspect these logins within the privacy team. I am waiting for a response of the team that it was escalated to. I will keep you alle updated.
If nothing of this gives information I will contact the governmental privacy institution to help me get a answer from Microsoft.
Thanks, if you have any answer let us know!
I'm so paranoid now that I've been checking my activities several times a day.
Same,
I use iOS and just tried it again. I opened the OneDrive app not for a 1,5 days. After opening I saw just a few seconds the red banner telling that I have to re login to the account. It disappeared very fast. I logged in to my personal vault and closed it.
And here it is: After looking in my MS Auth App for the activities I saw the login form the same MS IPv6 that I saw the other days too. 2 times Sucessfull login from it.
Sometimes it appears if I not using the OneDrive App. Curios was 2 days the exact time I woke up and used the phone there were those logins too.
Another curios thing: 2 tiles those login entries disappeared really quick or instead of 2 or 3 successful logins it only was one.
So I really think it’s a bug. For some users from SharePoint it could be the hack too but I don’t believe it for personal accounts at this time.
Oh, your account showed the same behavior as mine.
Now my last ipv6 login was last Tuesday, despite using the outlook and onedrive apps on my iPad after that day.
Another curios thing:
I owe 3 personal accounts. Only on the one with the problems I use the OneDrive App. On the others only Outlook. Maybe it is related to OneDrive sessions.
Glad that I’m wrong & the hack isn’t the reason why we’re seeing these entries.
For me it doesn’t seem to be OneDrive related.
Yeah, I asked another person that uses OneDrive app just now to check the recent activities, and there is no strange ipv6 logins in the past 30 days. Only today's login. So probably not OneDrive related?
Just a quick update, it happened again today, at 2am, a time I was obviously sleeping, so I don't have any idea what might be causing it. I just gave up. Lately Microsoft is so full of bugs and it seems that they don't care. They only care about AI recently.
Just to add my two cents regarding the use of the OneDrive Personal Vault which I hadn't tested since putting a couple pictures in it that I wanted secured a year or so ago, that had a different specific effect within my Activity logs.
Though the initial check I made by logging into my Microsoft Account had the usual Device/platform of Windows and Browser/app of Microsoft Edge, the access of OneDrive Personal Vault a few minutes later logged a separate Successful sign-in entry from the same location and map, but with the same Device/platform of Windows, with a different Browser/app of Internet Explorer.
The interesting thing here is that this likely explains the occasional appearance of the legacy Internet Explorer app in these logs as relating to items like the Windows Hello Face (camera) verification of my identity that occurred as a result of this access, since that's probably still tied to portions of those same legacy components of Internet Explorer that still remain embedded in at least Windows 10, and would require major revisions if Microsoft attempted to remove these Internet Explorer components completely, so they simply left them there fulfill this legacy purpose.
Even more interesting in my case, these two particular Activity log entries were logged as occurring from Barcelona, Spain, which just happens to be where I'm sitting at the moment on vacation in a hotel, so perfectly accurate, though obviously different from the previous set of Activity logs from a few days before I left home.
So clearly it isn't simply the use of OneDrive or even the Personal Vault that triggers these special IPv6 entries, nor either Windows Hello from Windows 10 or the act of authentication via Microsoft Authenticator Push notifications and number matching from an Android phone, since all of these actions occurred at some point within the testing I just performed and listed above.
So, it's still unexplained why a subset of users happens to receive these IPv6 log entries from internal Microsoft cloud IP addresses during otherwise seemingly normal activities or occasionally outside typical usage hours as well.
It clearly has nothing directly to do with the SharePoint [unpatched] locally managed server vulnerabilities either, per my earlier post mentioned here by others, though we can't say there's no relation to similar issues without knowledge we don't have.
I still don't believe this is a 'bug' as such though, simply a minor logging annoyance that since many of those affected seem to be the same subset of users who were also affected by the earlier bot attack attempts against their Microsoft account passwords, has been anecdotally linked by these same relatively paranoid users to mean there's some potential relationship to that earlier set of attacks.
In truth there's absolutely no evidence of this at all though, it's simply the coincidental effect that just about the only people who ever bother to look at the Microsoft account Activity logs are these same people who were previously under bot attack, so of course if some portion of this same group overlaps with those experiencing the IPv6 entries, that coincidence would tend to look suspicious to those already paranoid for those legacy reasons.
This appears to me to be a form of confirmation bias, while the process of thinking all of this through has led me to wonder if any of those affected by these IPv6 log entries also happened to be among those that chose to try the workaround solution to that earlier bot attack issue of creating a new account alias and switching to the use of that alias for login, since that's just the sort of account modification I could see potentially requiring some additional internal cloud account interactions that might result in the internal authentication traffic likely to cause these IPv6 Activity entries to display.
Rob
Just for more clarification, I've never created another alias nor have been using the OneDrive vault for a while. Also the person I've checked was under the same bot attack as me for years, and his account does not have any ipv6 logins and he is also using both OneDrive and OneDrive vault regularly. So, I don't think that this is actually related to OneDive as we were thinking before.
I think Microsoft are replying to us indirectly; just googled every single IPv6 entry that I have seen successfully login to my account; check what comes up; and our thread is always on the right hand side; I know it is the AI overview but what a coincidence.
That's crazy, I just checked the last one that appeared on mine, 2a01:111:f402:f078::f142 from Canada, but I didn't get the same AI answer as you.
But the first results are now this thread.
The AI overview spits out a combination of results based on the user, input and sources. There was no link to any of what was said on the AI output but I assume that the original source comes from Microsoft themselves surely???; but all I typed was the IP addresses and that's what came out. I mean it kind of explains what's happening in detail and its usual for IPv6 addresses to keep on changing so you will most likely have different addresses every single time and it explains why we see them in activity even when we are asleep or not even on our phones or pc
I lied there are links on the AI response from various valid sources, some are threads like ours where an Employee or participant has answered a question, i have not viewed all sources but the AI generator pretty much sums up all information and links the sources to back up
I’m noticing the same thing. Same setup as the rest of you, MFA using Authenticator and I have a sign in alia and I changed my pw within the last two months just as standard protocol not due to anything suspicious. The strange thing, I did login to my account a few days ago but I don’t see any activity on that day. I see one for the day after and yesterday evening (Microsoft DC in Arizona) and an IPv6 cluster of five. So I saw a few people mention a bug ace I’m leaning towards that. Just my experience.
我也有相同的問題,不明登入並刪除我的2FA。
請注意你們的郵箱,我發現我的電子信箱被添加了篩選器,會使我的郵件直接進入垃圾桶,並且不會收到電子郵件的通知,我在信箱的垃圾桶發現 "變更密碼"以及"驗證碼"等訊息,我可以確信我的帳號已被登入,並修改內容
I also had this issue, although for me it is from a Microsoft ipv6 in the Netherlands. Started early August for me.
Same as others, no mfa prompt, no notification of unusual activity. The signs ins still happen after forcing log out and changing password etc.
I did contact Microsoft support who gave a fairly unsatisfactory answer that it’s due to having 2fa enabled that activity from Microsoft IPs can show on the session history. I explained that for me the sign in happened well after my last authentication (days after), and they said as long as it’s from a Microsoft IP the account is secure (not sure I agree but that’s what they said…).
I also have a successful sign in from San Antonio on 29 July.
I had 2FA turned on with my Microsoft Authenticator app, set to notify. I have reset my password