About 20 percent of Microsoft Account logins are found on lists of compromised credentials in the wake of hack attacks on other service providers. Microsoft regularly gets lists of third-party login details from ISPs, law enforcement and vendors, as well as from lists published on the internet by hackers. Company also revealed that it is working to tighten its security and one of such measures is going to be increase in the character limit in passwords to make Brute Force attack more difficult. Last week, both Yahoo! Voices and the Android forums at website Phandroid were hacked, resulting in the leakage of almost 1.5 million usernames and passwords.
Source: https://thehackernews.com/2012/07/fact-one-in-five-microsoft-logins.html