logo

Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks

ID: 53bfc33d-ed5b-51c5-97a2-539730aa2c8a

STIX ID: report--53bfc33d-ed5b-51c5-97a2-539730aa2c8a

Feed Name: The Register (Security)

Threat Score
55/100

Date Published: 2025-08-01

Date Updated: 2026-04-26

Author: Avram Piltch

...
...

The article analyzes Microsoft Recall, an AI-driven screenshotting feature on Copilot+ PCs, and finds its sensitive-data filtering and protections are inconsistent: tests captured credit card details, SSNs, and password lists in many cases, and Recall snapshots can be accessed with a PIN or via remote desktop; while Microsoft has implemented encryption and VBS storage, the feature still presents significant privacy and security risks, particularly for vulnerable users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.