UPDATED: Skype suspends password resets in wake of account takeover fears
Messaging giant responds to reports that email security flaw could leave users exposed to attack.

Skype has suspended its password reset procedures following the discovery of a flaw that could let hackers access an account by guessing a user's email address.
To take advantage of the flaw, a hacker would simply need to create a new account using the victim's email address and request a new password.
The password reset token is then sent to the hacker, via the Skype client, allowing them to take control of the victim's original username and account.
The security hole could be used to lock people out of their accounts, access their chat logs and use up any paid-for credits they may have.
According to a report by The Next Web, the problem was flagged to Microsoft-owned Skype by Russian security researchers two months ago.
The firm acknowledged the issue in a blog post earlier today, adding that it was working on a fix.
"As a precautionary step, we have temporarily disabled password reset as we continue to investigate the issue further," the blog post stated.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"We apologise for the inconvenience but user experience and safety is our first priority."
It is thought, before the company stepped in, the only way users could protect themselves against the problem was by using a separate, hard-to-guess email address for their Skype accounts.
In a follow up statement to IT Pro, Skype claimed only a small number of users had been affected by the issue.
"This issue affected some users where multiple Skype accounts were registered to the same email address. We suspended the password reset feature temporarily this morning as a precaution and have made updates to the password reset process today," it said.
"We are reaching out to a small number of users who may have been impacted to assist as necessary...and we apologise for the inconvenience."
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Court summons Skype after refusal to share customer data
News The VoIP company decided not to aid a criminal investigation with message and call information
By Joe Curtis
-
Malwarebytes unmasks new Skype phishing scam
News Cyber criminals steal validated login credentials while also deploying banking Trojan.
By Jane McCallion
-
Microsoft ordered to clarify Skype privacy fears
News Privacy advocates want Microsoft to publish transparency reports detailing government requests for personal data.
By Khidr Suleman
-
Skype users threatened by worm
News Malware spread by "lol" link could hold PC users to ransom.
By Stephen Pritchard
-
Week in Review: Phone hacking and police snooper sackings
News This week, with the epic phone hacking scandal still raging on, it's reported hundreds of police have been snooping on data they shouldn't be looking at. What a bunch of naughty so-and-sos...
By Tom Brewster
-
Skype Android app flaw places data in danger
News Skype says it is looking into a flaw which could allow hackers to acquire user data including contacts and instant message logs.
By Tom Brewster
-
Trojan taps and records Skype conversations
News Symantec warns Skype users of a threat that could potentially listen in to their conversations.
By Asavin Wattanajantra