‼️Multiple users are reporting suspicious Microsoft passwordless sign-in emails containing legitimate verification codes.
Threat actors are allegedly using leaked databases for large-scale account enumeration to identify email addresses linked to Microsoft accounts, potentially for later credential-stuffing attacks.
Users are advised to ignore unexpected codes, change passwords, and enable 2FA.