1/2
What are your concerns?
Please select at least three.
Concerns info icon Concerns clicked info icon Why do we ask?
How many people do you want to protect? Knowing the customer info icon Knowing the customer clicked info icon Why do we ask?
Potential identity threats notification info icon Potential identity threats notification clicked info icon Why do we ask?

Finding your match...

Loading animation icon
DID YOU KNOW?
10 cents

If your information is exposed or stolen in a data breach, it can end up on the dark web where it can be sold for as little as 10 cents.

100M+

LifeLock monitors hundreds of millions of data points a second.

Based on your concerns, the best plan for you is:
LifeLock Core
(Individual)
LifeLock Advanced
(Individual)
LifeLock Total
(Individual)
LifeLock Core
(2 adults)
LifeLock Advanced
(2 adults)
LifeLock Total
(2 adults)
LifeLock Core
(2 adults + up to 10 kids)
LifeLock Advanced
(2 adults + up to 10 kids)
LifeLock Total
(2 adults + up to 10 kids)
16% OFF*
$10.42 / mo
Pay $124.99 today. Renews annually.
Pricing details below*
16% OFF*
$16.67 / mo
Pay $199.99 today. Renews annually.
Pricing details below*
16% OFF*
$29.17 / mo
Pay $349.99 today. Renews annually.
Pricing details below*
16% OFF*
$18.75 / mo
Pay $224.99 today. Renews annually.
Pricing details below*
16% OFF*
$30.00 / mo
Pay $359.99 today. Renews annually.
Pricing details below*
16% OFF*
$52.50 / mo
Pay $629.99 today. Renews annually.
Pricing details below*
16% OFF*
$28.75 / mo
Pay $344.99 today. Renews annually.
Pricing details below*
16% OFF*
$40.00 / mo
Pay $479.99 today. Renews annually.
Pricing details below*
16% OFF*
$62.50 / mo
Pay $749.99 today. Renews annually.
Pricing details below*
  • Up to $1.05M Reimbursement for identity theft, with up to $25K for Stolen Funds†††
  • Up to $1.2M Reimbursement for identity theft, with up to $100K for Stolen Funds†††
  • Up to $3M Reimbursement for identity theft, with up to $1M for Stolen Funds†††
  • Up to $1.05M Reimbursement for identity theft, with up to $25K for Stolen Funds††† for each adult
  • Up to $1.2M Reimbursement for identity theft, with up to $100K for Stolen Funds††† for each adult
  • Up to $3M Reimbursement for identity theft, with up to $1M for Stolen Funds††† for each adult
  • Up to $1.05M Reimbursement for identity theft, with up to $25K for Stolen Funds††† for each adult
  • Up to $1.2M Reimbursement for identity theft, with up to $100K for Stolen Funds††† for each adult
  • Up to $3M Reimbursement for identity theft, with up to $1M for Stolen Funds††† for each adult
  • Credit Monitoring Coverage1
  • Credit Monitoring1 each adult
  • Credit Monitoring1 for family
  • Credit, Checking & Savings Account Activity Alerts
  • Credit, Checking and Savings Activity Alerts for each adult
  • Credit, Checking and Savings Activity Alerts for family
  • 401K & Investment Account Activity Alerts
  • 401K/Investment Account Alerts for each adult
  • 401K/Investment Account Alerts for family
  • Recurring and Unusual Charge Alerts
  • Unexpected & Suspicious Charge Alerts for each adult
  • Unexpected & Suspicious Charge Alerts for family
  • Stolen Funds Reimbursement†††
  • Stolen Funds Reimbursement††† for each adult
  • Stolen Funds Reimbursement††† for family
  • Lawyers and Experts†††
  • Lawyers & Experts††† for each adult
  • Lawyers & Experts††† for family
  • Automatic Data Broker Removal8
  • Automatic Data Broker Removal8 for each adult
  • Automatic Data Broker Removal8 for family
  • Scam Reimbursement7
  • Scam Reimbursementfor each adult
  • Scam Reimbursement7 for family
  • Credit Reports & Scores1
  • Credit Report & Score for each adult
  • Credit Report & Score for family
  • Social Media Monitoring
  • Social Media Monitoring  for each adult
  • Social Media Monitoring  for family
Plan icon
We have more plans to choose from.
See all plans
Contact icon
Have questions?
Contact sales
*Your subscription begins immediately after payment and automatically renews unless cancelled. Discount for annual plans are compared to monthly billing. Prices subject to change and may be charged up to 35 days before current term ends. Cancel here or contact Member Services.

Why do we ask?

Identifying your concerns gives us the ability to recommend the right plan for your needs.

Return to quiz

Why do we ask?

Knowing this number helps us recommend coverage that fits your needs.

Return to quiz

Why do we ask?

Providing your email address makes you eligible for notifications of potential identity threats.

Return to quiz

Microsoft accidentally exposed 250 million customer records — What you should know

A man alerting customers to an accidental security breach.
  • 250 million Microsoft customer records were exposed on an online database without password protection.
  • The exposed information included customer records from 2005 to December 2019. Exposed customer service and support logs included conversations between Microsoft support agents and customers.
  • Most personally identifiable information was redacted, although some customer email addresses, IP addresses, geographical locations, and other data were exposed.
  • Comparitech security researchers led by Bob Diachenko found the breach and notified Microsoft. Microsoft secured its database within 24 hours.
  • The risk? Cybercriminals could use the exposed information in tech-support scams or phishing scams.
Microsoft has acknowledged an access misconfiguration where 250 million customer records were exposed on a database without password protection.
 
The exposed records — including conversations with customers and Microsoft support agents — date from 2005 to December 2019.
 
The exposed information could raise the risk of tech-support scams targeting Microsoft customers. Scammers might be able to use the information to pretend they’re Microsoft support agents and try to trick customers into sharing their personal information.
 
Microsoft said there in no evidence that cybercriminals accessed the exposed information.
 

What data was exposed?

Most of the information exposed were customer service and support logs. Companies often keep this information as a record of conversations with customers.

In the Microsoft breach, most personally identifiable information was redacted from the records — meaning it was removed.

For some customers, additional information was exposed. Here’s what may have been included in those cases.

  • Customer email addresses.
  • IP addresses.
  • Microsoft support agent emails.
  • Case numbers and resolutions.
  • Internal notes marked as confidential.
“The added information could make you at risk of tech support scams pretending to be Microsoft. How? Scammers may have accessed lists of Microsoft customers and their emails addresses.”
 

How do I protect against tech support scams?

Here are some tips to help protect yourself against tech support scams.

  • Keep in mind most large corporations, including Microsoft, will not reach out to you about your tech problems. You have to initiate the communication. If someone is reaching out proactively, be suspicious. Even if they are following up on a recent, coincidental call of yours, hang up the phone. Call back the official support number on the company page – and not a number that was sent to you.
  • If the inquiry is over email, be careful about the source and destination of the incoming message. Do not share personally identifiable information over email. Most large companies will never ask for your password or other PII (Personal Identifiable Information) over email – and possibly not even over the phone. Most large companies have more secure methods of authenticating users.
  • Report any suspicious activity to the company. This will help the company remediate the situation.
  • If passwords were exposed in a data breach, it’s a good idea to change your password in the relevant account. If you used the same password for any other accounts, change those passwords, too. It’s smart to use a unique, complex passwords for each of your accounts.

What was the timeline on the Microsoft breach?

Comparitech, the company that found the Microsoft data breach, said the data was exposed for about two days. The company included this timeline in a blog post.

  • December 28, 2019 – The databases were indexed by search engine BinaryEdge.
  • December 29, 2019 – Comparitech researcher Bob Diachenko discovered the databases and notified Microsoft.
  • December 30-31, 2019 – Microsoft secured the servers and data. Diachenko and Microsoft continued the investigation and remediation process.
  • Jan 21, 2020 – Microsoft disclosed additional details about the exposure as a result of the investigation.
In a blog post, Microsoft wrote, “We want to sincerely apologize and reassure our customers that we are taking it seriously and working diligently to learn and take action to prevent any future reoccurrence. We also want to thank the researcher, Bob Diachenko, for working closely with us so that we were able to quickly fix this misconfiguration, investigate the situation, and begin notifying customers.”
 

What is Microsoft doing?

Microsoft said it concluded an investigation into a “misconfiguration of an internal customer support database used for Microsoft support case analytics.” The company said it is taking these steps.

  • Sending notifications to customers whose data was affected by the data breach.
  • Taking action to prevent future occurrences of this issue.
  • Auditing the established network security rules for internal resources.
  • Expanding the scope of the mechanisms that detect security rule misconfigurations.
  • Adding additional alerting to service teams when security rule misconfigurations are detected.
A major data breach is a reminder that cybercriminals who access exposed data, which sometimes can include PII, can use it for a variety of crimes, including identity theft. It’s also important to know that many of these crimes can occur years after a breach.
Laptop on table

Was yours one of the billions of records stolen through breaches in recent years?

Start your protection now. It only takes minutes to enroll.

Editors’ note: Our articles provide educational information about identity theft, scams, financial fraud, and other topics that can put your identity or personal accounts at risk. LifeLock offerings may not cover or protect against every type of crime, fraud, scam, or threat we write about. For more details about how we write, review, and update our articles, see our Editorial Policy.

This article contains

Start your protection,
enroll in minutes.

Get discounts, info, protection tips, and more.

Sign up for promotional emails.

Privacy preference center
By clicking "Accept All" you allow cookies that improve your experience on our site, help us analyze site performance and usage, and enable us to show relevant marketing content. You can manage cookie settings below. By clicking “Confirm Selection” you agree with the current settings. See Cookies Policy
We have received a GPC signal from your browser and have modified the default cookie preferences for you accordingly. By clicking “Accept all” you allow cookies that improve your experience on our site, help us analyze site performance and usage, and enable us to show relevant marketing content. You can manage cookie settings below. By clicking “Confirm selection” you agree with the current settings. See Cookies policy
Manage consent settings

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

Preference cookies enable a website to remember information that changes the way the website behaves or looks, such as your preferred language or the region that you are in. De-selecting these cookies may result in improper functionality and setting of the website.

Performance cookies help us improve our website by analyzing how visitors use it and interact with it. De-selecting these cookies may result in poorly-designed content and slow site performance.