Xbox Live users are being urged to check their accounts after some say they were scammed by a fake email.
The phishing attack sent users to a fake website where they
were asked to input personal details like addresses, emails and credit
card details.
Microsoft is investigating but doesn't know how many users are affected.
"We take the security of the Xbox Live service seriously and
work to improve it against evolving threats," a Microsoft spokesman
said.
"Very occasionally, though, we are contacted by members
regarding alleged unauthorized access to their accounts by outside
individuals.
We highly recommend all Xbox Live users follow our account security guidance in order to protect their account details
Microsoft statement
"We work closely with impacted members directly to resolve any
unauthorized changes to their accounts and, as always, highly recommend
all Xbox Live users follow our account security guidance in order to
protect their account details."
Microsoft says there is advice on its website about staying
safe online but advises that people should never give out passwords or
email addresses.
They say users should never type personal information into websites unless they are sure that they are genuine.
Jason Hart, MD of Cryptocard and a former ethical hacker,
said: "Xbox customers are finding that they might have had more than
£100 pilfered from their accounts.
"This is the third instance of hacking to hit the gaming
industry in as many months and it is clear that hackers are finding it
all to easy to steal gamers identities and access the financial
information they need to make off with users cash."