{"id":59119,"date":"2025-08-01T19:14:09","date_gmt":"2025-08-01T19:14:09","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/"},"modified":"2025-08-01T19:14:09","modified_gmt":"2025-08-01T19:14:09","slug":"tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/","title":{"rendered":"Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks"},"content":{"rendered":"<p><span class=\"label\">exclusive<\/span> Microsoft Recall, the AI app that takes screenshots of what you do on your PC so you can search for it later, has a filter that&#8217;s supposed to prevent it from screenshotting sensitive info like credit card numbers. But a <em>The Register<\/em> test shows that it still fails in many cases, creating a potential treasure trove for thieves.<\/p>\n<p>Recall was introduced in 2024 as an exclusive app on <a href=\"https:\/\/www.theregister.com\/2025\/07\/28\/copilot_pc_sales_grow_slowly\/\">Copilot+ PCs<\/a>, which are laptops that come with a dedicated Neural Processing Unit (NPU) to help with AI-related tasks. Initially, <a href=\"http:\/\/doublepulsar.com\/recall-stealing-everything-youve-ever-typed-or-viewed-on-your-own-windows-pc-is-now-possible-da3e12e9465e\" rel=\"nofollow\">researchers found<\/a> serious security issues with it, and Redmond pulled it in the spring before re-introducing an ostensibly more secure version in fall 2024. These days, a screen encouraging you to enable it is part of the Windows setup experience on many new PCs.<\/p>\n<div class=\"CaptionedImage Border width_85\" readability=\"7\"><a href=\"https:\/\/regmedia.co.uk\/2025\/08\/01\/recall1.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2025\/08\/01\/recall1.jpg?x=648&amp;y=364&amp;infer_y=1\" alt=\"Microsoft's out of the box experience pushes you to enable Recall\" title=\"Microsoft's out of the box experience pushes you to enable Recall\" height=\"364\" width=\"648\"><\/a><\/p>\n<p class=\"text_center\">Microsoft&#8217;s out of the box experience pushes you to enable Recall &#8211; Click to enlarge<\/p>\n<\/div>\n<p>Although Microsoft claims that Recall is <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/support.microsoft.com\/en-us\/windows\/privacy-and-control-over-your-recall-experience-d404f672-7647-41e5-886c-a3c59680af15\">safe and private<\/a>, the software could be a goldmine of personal information if a miscreant manages to break into your system. The app has a &#8220;Filter sensitive information&#8221; setting enabled by default that&#8217;s supposed to exempt personal data such as credit card numbers and passwords from capture. However, according to our tests, that filter frequently fails. And there&#8217;s no way it would know to avoid potentially damaging entries in your web history that you&#8217;d rather keep private (such as things related to your medical history or personal life). Just as bad, the screenshots Recall takes are available to anyone who has your PIN number, even via remote access.<\/p>\n<h3 class=\"crosshead\">Sensitive information filtering: good, but not good enough<\/h3>\n<p>To find out just how well the sensitive information filter works, I took a Lenovo Yoga Slim 7x Copilot+ PC with Recall enabled and tried entering many types of personal data that no one would want getting into the wrong hands. To give credit where it&#8217;s due, the tool correctly identified and excluded a lot of financial data, some passwords, and most instances of Social Security numbers.<\/p>\n<p>When I logged into my bank account, Recall snagged both my bank&#8217;s home page and several screens where my balance and a list of deposits appeared. On the bright side, it correctly excluded the screen with my account and ABA routing numbers on it. So an attacker would know which bank I use and how much money I have, both details that could help them, but not my credentials or account number.<\/p>\n<p>Recall did a pretty good job with shopping forms. When I went to the Microsoft site and added a credit card to my account, it took a screenshot with the card number, CVC and date fields blank. And when I created my own fake web page with a credit card entry form (with the letters CC: in front of the number field), the software filtered it out.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"condor\" data-xsm=\",fluid,mpu,dmpu,\" data-sm=\",fluid,mpu,dmpu,\" data-md=\",fluid,mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aI77lmaiTdwJBlxY4P-6ngAAAJE&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" target=\"_blank\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2aI77lmaiTdwJBlxY4P-6ngAAAJE&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>However, when I removed text such as &#8220;checkout page&#8221; and &#8220;Enter payment info&#8221; from the form, leaving the credit card number, expiration date, and CVC, Recall captured it. Maybe it&#8217;s unfair to expect the software to identify a credit card number without words like &#8220;credit card&#8221; or &#8220;pay&#8221; near it, but not all shopping forms look the same.<\/p>\n<div class=\"CaptionedImage Border width_85\" readability=\"7\"><a href=\"https:\/\/regmedia.co.uk\/2025\/08\/01\/recall2.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2025\/08\/01\/recall2.jpg?x=648&amp;y=380&amp;infer_y=1\" alt=\"Recall captured a credit card entry form I created\" title=\"Recall captured a credit card entry form I created\" height=\"380\" width=\"648\"><\/a><\/p>\n<p class=\"text_center\">Recall captured a credit card entry form I created &#8211; Click to enlarge<\/p>\n<\/div>\n<p>The password blocking was mixed. When I opened up Google Chrome&#8217;s password manager, Recall correctly filtered it out. The tool gets extra credit for not screenshotting this sensitive info, even when I took a screenshot of it in the Snipping Tool and displayed that on-screen. It also worked when I created a text file in Notepad with the words username and password in it.<\/p>\n<p>However, when I just listed usernames and passwords in a text file without those identifiers, it captured the screen. Perhaps we shouldn&#8217;t expect Recall to know that a text file is full of passwords \u2013 and, no, you shouldn&#8217;t keep your passwords in a text file \u2013 but many people probably have lists of their passwords without the word &#8220;password&#8221; printed next to them.<\/p>\n<div class=\"CaptionedImage Border width_85\" readability=\"7\"><a href=\"https:\/\/regmedia.co.uk\/2025\/08\/01\/recall3.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2025\/08\/01\/recall3.jpg?x=648&amp;y=380&amp;infer_y=1\" alt=\"Recall screenshotted a Notepad file full of passwords\" title=\"Recall screenshotted a Notepad file full of passwords\" height=\"380\" width=\"648\"><\/a><\/p>\n<p class=\"text_center\">Recall screenshotted a Notepad file full of passwords &#8211; Click to enlarge<\/p>\n<\/div>\n<p>There are so many ways that people store and refer to personal data that it&#8217;s impossible to imagine Recall or any software catching them all. For example, when I entered a Social Security number in a Word document with the prefix &#8220;My SS#:&#8221; before it, the tool only captured an image with the first three digits in it. However, when I made the prefix &#8220;Soc:,&#8221; it captured all the digits.<\/p>\n<div class=\"CaptionedImage Border width_85\" readability=\"7\"><a href=\"https:\/\/regmedia.co.uk\/2025\/08\/01\/recall4.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2025\/08\/01\/recall4.jpg?x=648&amp;y=379&amp;infer_y=1\" alt=\"Recall captured a Word doc with a social security number in it\" title=\"Recall captured a Word doc with a social security number in it\" height=\"379\" width=\"648\"><\/a><\/p>\n<p class=\"text_center\">Recall captured a Word doc with a social security number in it &#8211; Click to enlarge<\/p>\n<\/div>\n<p>When I logged into my PayPal account, Recall captured the login screen showing my username, but not my password. It correctly avoided screenshotting the account page, which showed my transactions, but if a bad actor had my username, that&#8217;s some of the information they would need to get in.<\/p>\n<div class=\"CaptionedImage Border width_85\" readability=\"7\"><a href=\"https:\/\/regmedia.co.uk\/2025\/08\/01\/recall5.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2025\/08\/01\/recall5.jpg?x=648&amp;y=378&amp;infer_y=1\" alt=\"Recall captured by PayPal username\" title=\"Recall captured by PayPal username\" height=\"378\" width=\"648\"><\/a><\/p>\n<p class=\"text_center\">Recall captured by PayPal username &#8211; Click to enlarge<\/p>\n<\/div>\n<p>In another instance, I had a photo of my passport visible on the screen and Recall correctly avoided it. However, when that photo was partially covered by another window, Recall took the screenshot.<\/p>\n<h3 class=\"crosshead\">A work in progress<\/h3>\n<p>When contacted about our findings, Microsoft declined to comment. To be fair, though, Microsoft doesn&#8217;t claim that Recall&#8217;s sensitive data filter is perfect. In a <a href=\"https:\/\/blogs.windows.com\/windows-insider\/2024\/11\/22\/previewing-recall-with-click-to-do-on-copilot-pcs-with-windows-insiders-in-the-dev-channel\/\" rel=\"nofollow\">blog post<\/a> from November, when it officially started giving Windows Insiders access to the feature, Principal Product Managers Amanda Langowski and Brandon LeBlanc wrote that &#8220;we&#8217;ll continue to improve this functionality, and if you find sensitive information that should be filtered out, for your context, language, or geography, please let us know through Feedback Hub.&#8221;<\/p>\n<p>Users also have the option to block specific apps or websites from being screenshotted. To do so, you have to add them to a blacklist in Windows settings-&gt;Privacy &amp; Security-&gt;Recall &amp; snapshots. However, you&#8217;d have to anticipate in advance what you want to block. And, if you&#8217;re really being diligent, you&#8217;d block your browser apps, which effectively makes Recall useless.<\/p>\n<div class=\"CaptionedImage Border width_85\" readability=\"7\"><a href=\"https:\/\/regmedia.co.uk\/2025\/08\/01\/recall6.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2025\/08\/01\/recall6.jpg?x=648&amp;y=504&amp;infer_y=1\" alt=\"You can block Recall from capturing specific apps and sites in Settings\" title=\"You can block Recall from capturing specific apps and sites in Settings\" height=\"504\" width=\"648\"><\/a><\/p>\n<p class=\"text_center\">You can block Recall from capturing specific apps and sites in Settings &#8211; Click to enlarge<\/p>\n<\/div>\n<p>Redmond also labels Recall as a &#8220;preview&#8221; app. However, if you&#8217;re pushing the app during the Windows OOBE process on new laptops, it&#8217;s hard to argue that it&#8217;s in beta and therefore immune from criticism.<\/p>\n<h3 class=\"crosshead\">Just how secure is Recall?<\/h3>\n<p>Microsoft has also made a lot of noise about Recall&#8217;s security. In June 2024, after security researcher and former Microsoft employee Kevin Beaumont <a href=\"https:\/\/doublepulsar.com\/recall-stealing-everything-youve-ever-typed-or-viewed-on-your-own-windows-pc-is-now-possible-da3e12e9465e\" rel=\"nofollow\">detailed serious problems<\/a>, including the fact that Recall&#8217;s database was stored in plain text, the company pulled the product out of previews for several months and made some changes.<\/p>\n<p>In a September <a href=\"https:\/\/blogs.windows.com\/windowsexperience\/2024\/09\/27\/update-on-recall-security-and-privacy-architecture\/\" rel=\"nofollow\">blog post<\/a>&nbsp;from VP of Enterprise and OS Security David Weston, Microsoft detailed a number of security improvements. Most importantly, the snapshots and database are now encrypted and stored in a Virtualization-based Security Enclave (VBS). It also requires Windows Hello logins for you to view or search Recall snapshots.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xmd=\",fluid,mpu,leaderboard,\" data-lg=\",fluid,mpu,leaderboard,\" data-xlg=\",fluid,billboard,superleaderboard,mpu,leaderboard,\" data-xxlg=\",fluid,billboard,superleaderboard,brandwidth,brandimpact,leaderboard,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44aI77lmaiTdwJBlxY4P-6ngAAAJE&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44aI77lmaiTdwJBlxY4P-6ngAAAJE&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<div class=\"adun_eagle_desktop_story_wrapper\">\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"mid\" data-raptor=\"eagle\" data-xxlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33aI77lmaiTdwJBlxY4P-6ngAAAJE&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33aI77lmaiTdwJBlxY4P-6ngAAAJE&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<\/p><\/div>\n<p>&#8220;Recall snapshots are available only after you authenticate using Windows Hello credentials,&#8221; Weston wrote. &#8220;Specifically, Windows Hello Enhanced Sign-in Security biometric credentials protect your privacy and actively authenticate you to query your semantic indices and view associated snapshots.&#8221;<\/p>\n<p>However, Weston didn&#8217;t note that Windows Hello <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/support.microsoft.com\/en-us\/windows\/configure-windows-hello-dae28983-8242-bb2a-d3d1-87c9d265a5f0\">also supports<\/a> using a PIN code for access, in addition to faces or fingerprints. So, if you have someone&#8217;s PIN code or can guess it, you can access all of their Recall screenshots.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xsm=\",fluid,mpu,dmpu,\" data-sm=\",fluid,mpu,dmpu,\" data-md=\",fluid,mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44aI77lmaiTdwJBlxY4P-6ngAAAJE&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44aI77lmaiTdwJBlxY4P-6ngAAAJE&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>Lack of physical access to the PC with the Recall data is not a blocker either. I installed free TeamViewer remote desktop software on the Copilot+ laptop and was able to view my entire Recall history from a second computer. When it asked for my face, I just gave it my PIN instead.<\/p>\n<p>It&#8217;s also possible that the VBS enclave and encryption are not infallible.<\/p>\n<p>&#8220;Attackers have prior exploited side\u2011channel flaws in VBS and Hyper\u2011V to infer secrets from enclaves unless hyper-threading is disabled or fully patched,&#8221; Huntress Security Senior SOC Manager Dray Agha told <em>The Register<\/em>. &#8220;So, administrators must apply all mitigations promptly and patch as Recall will inevitably become vulnerable to attacks over the years, which &#8211; as we know from multiple exploited vulnerabilities over the years &#8211; many folks simply do not do. Recall is an unnecessary security and privacy risk for not that much usability gain.&#8221;<\/p>\n<h3 class=\"crosshead\">Privacy risks: even worse for vulnerable users<\/h3>\n<p>Privacy advocates are also concerned about the consequences of the wrong people gaining access to users&#8217; personal information. In July, the makers of Brave browser announced that it would be <a href=\"https:\/\/www.theregister.com\/2025\/07\/23\/brave_browse_block_microsoft_recall\/\" rel=\"nofollow\">blocking Recall<\/a> by designating every tab as &#8220;private,&#8221; something which Microsoft&#8217;s software respects.<\/p>\n<p>Peter Snyder, principal privacy researcher at Brave Software, told <em>El Reg<\/em> that the company is concerned about vulnerable users, such as domestic violence victims, being harmed by Recall screenshots. An abusive partner would be able to see that they were visiting websites that offer support, medical help, or a way to escape.<\/p>\n<p>&#8220;Many users need to hide certain bits of Web browsing from people who have access to their computer or phone,&#8221; Snyder said. &#8220;Recall makes it extra-difficult for Brave to provide these kinds of protections because Recall isn\u2019t designed to give software control over what is included in Recall\u2019s snapshots.&#8221;<\/p>\n<div aria-hidden=\"true\" class=\"adun\" id=\"story_eagle_xsm_sm_md_xmd_lg_xlg\" data-pos=\"mid\" data-raptor=\"eagle\" data-xsm=\",mpu,dmpu,\" data-sm=\",mpu,dmpu,\" data-md=\",mpu,dmpu,\" data-xmd=\",mpu,dmpu,\" data-lg=\",mpu,dmpu,\" data-xlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33aI77lmaiTdwJBlxY4P-6ngAAAJE&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/front&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33aI77lmaiTdwJBlxY4P-6ngAAAJE&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>Snyder explained that Brave has a feature called &#8220;Off-the-Record,&#8221; which helps users hide their browsing behavior, even from someone who has physical access to their PC. It has another feature called &#8220;Forgetful Browsing&#8221; that clears cookies and other storage from a site as soon as you leave it. Recall&#8217;s screenshotting makes both of these features useless.<\/p>\n<p>Whether you&#8217;re the type of person who blocks cookies or just someone who doesn&#8217;t want your identity stolen, there are lots of reasons to be concerned about Recall.<\/p>\n<p>&#8220;I don&#8217;t dispute that Microsoft has the best intentions at heart, along with doing as much as they can to ensure the security of this feature,&#8221; said Sean Wright, Director of Application Security at Featurespace. &#8220;However, there are so many caveats, that I personally don&#8217;t see how one would be able to have all these areas covered from a privacy and security concern.&#8221; \u00ae<\/p>\n<p> READ MORE <a href=\"https:\/\/go.theregister.com\/feed\/www.theregister.com\/2025\/08\/01\/microsoft_recall_captures_credit_card_info\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Our tests have shown there are ways to get around the promised security improvements exclusive\u00a0 Microsoft Recall, the AI app that takes screenshots of what you do on your PC so you can search for it later, has a filter that&#8217;s supposed to prevent it from screenshotting sensitive info like credit card numbers. But a The Register test shows that it still fails in many cases, creating a potential treasure trove for thieves.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":59120,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-59119","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2025-08-01T19:14:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/regmedia.co.uk\/2025\/08\/01\/recall1.jpg?x=648&amp;y=364&amp;infer_y=1\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks\",\"datePublished\":\"2025-08-01T19:14:09+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\\\/\"},\"wordCount\":1749,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\\\/\",\"name\":\"Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks.jpg\",\"datePublished\":\"2025-08-01T19:14:09+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks.jpg\",\"width\":648,\"height\":364},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/","og_locale":"en_US","og_type":"article","og_title":"Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2025-08-01T19:14:09+00:00","og_image":[{"url":"https:\/\/regmedia.co.uk\/2025\/08\/01\/recall1.jpg?x=648&amp;y=364&amp;infer_y=1","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks","datePublished":"2025-08-01T19:14:09+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/"},"wordCount":1749,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/08\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/","url":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/","name":"Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/08\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks.jpg","datePublished":"2025-08-01T19:14:09+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/08\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/08\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks.jpg","width":648,"height":364},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/tested-microsoft-recall-can-still-capture-credit-cards-and-passwords-a-treasure-trove-for-crooks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Tested: Microsoft Recall can still capture credit cards and passwords, a treasure trove for crooks"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/59119","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=59119"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/59119\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/59120"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=59119"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=59119"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=59119"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}