Skype users warned of serious security problem – accounts can be hijacked with ease

Graham Cluley
Graham Cluley
@
@[email protected]
@gcluley

SkypeA serious security problem has been uncovered in Skype, which allows hackers to hijack accounts just by knowing users’ email addresses.

The Next Web describes how it managed to reproduce the attack, accessing the Skype accounts of staff by just knowing their email address, and then changing the passwords of their “victims” to lock them out.

According to The Next Web:

“The reason this works is simple, but it’s still worrying. When you use an existing email address to sign up with Skype again, the service emails you a reminder of your username, which is okay, since no one else should have access to your email. Unfortunately, because this method enables you to get a password reset token sent to the Skype app itself, this allows a third party to redeem it and claim ownership of your original username and thus account.”

The issue was reportedly documented on Russian forums months ago, and appears to have been easy to exploit.

Skype has responded to the reports by temporarily disabling password resets for Skype accounts, and published a brief advisory to users:

Skype acknowledges there is a possible problem

“We have had reports of a new security vulnerability issue. As a precautionary step we have temporarily disabled password reset as we continue to investigate the issue further. We apologize for the inconvenience but user experience and safety is our first priority”

Before Skype withdrew the ability for users to reset their passwords, the only protection for users was to change the email address connected with their Skype account to one which was not known by anybody else.

Sign up to our free newsletter.
Security news, advice, and tips.

Microsoft-owned Skype has made the headlines for security reasons in the past. For instance, earlier this year it was accused of being slow to fix a flaw that could allow the gathering of information from Skype users, including a victim’s city, country, internet provider and IP address.

Update: At 15:28 GMT, Skype said it had resolved the issue. Here’s their updated advisory:

“Early this morning we were notified of user concerns surrounding the security of the password reset feature on our website. This issue affected some users where multiple Skype accounts were registered to the same email address. We suspended the password reset feature temporarily this morning as a precaution and have made updates to the password reset process today so that it is now working properly. We are reaching out to a small number of users who may have been impacted to assist as necessary. Skype is committed to providing a safe and secure communications experience to our users and we apologize for the inconvenience.


Graham Cluley is an award-winning keynote speaker who has given presentations around the world about cybersecurity, hackers, and online privacy. A veteran of the computer security industry since the early 1990s, he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows, makes regular media appearances, and is the co-host of the popular "Smashing Security" podcast. Follow him on Twitter, Mastodon, Threads, Bluesky, or drop him an email.

What do you think? Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.