Hacked Outlook or Microsoft Account: How to Take It Back
Official Microsoft page for this problem: account.live.com — we link it because the official flow is always the real path; this guide exists to help you get through it.
Discovering that someone else has been inside your Outlook.com or Microsoft account is unnerving, and the priority order matters: first get control back, then evict the attacker completely, then repair the damage. Most compromised accounts are fully recoverable, especially if you act quickly. What can’t always be undone is what the attacker already did — emails they read, messages they sent, or data they downloaded are outside your control.
Before you start
- Work from a device you trust. If you suspect malware on your usual computer (a keylogger is how many accounts get compromised twice), run a full antivirus scan first or use a different, clean device.
- Have your phone available for verification codes.
- Note the evidence: what tipped you off, when it started, and any bounce-backs or complaints from contacts. Timestamps help you read the activity log later.
- List other accounts that use this email address for login or password reset — the mailbox is a master key, and the attacker may have used it.
Step 1: Try to sign in and change the password
If your password still works, sign in immediately and change it: account settings, Security, then change password. Pick a long, unique password you have never used anywhere else. If it works, skip to Step 3.
If your password no longer works, the attacker probably changed it. Go to Step 2.
Step 2: Reset the password, or use the recovery form
Go to account.live.com/password/reset and request a security code to a phone number or alternate email on file. A useful thing to know: when someone changes security info on a Microsoft account, the change typically sits in a pending state for up to 30 days before old info is removed. So even if the attacker added their own phone number, yours may still work — pick the option you recognize.
If none of the verification options are yours, use the account recovery form at account.live.com/acsr. It is fully automated, so the quality of your answers decides the outcome:
- Submit from a device and network location you have used with this account before.
- Provide old passwords, subject lines of recent emails, addresses you have written to, and any Microsoft purchase details (Xbox, Microsoft 365, Skype). Approximate answers beat empty fields.
- Use a contact email you check; the decision usually arrives within 24 hours.
- If it fails, gather stronger details before resubmitting rather than repeating the same weak form.
Step 3: Evict the attacker completely
Changing the password alone is not enough. Attackers routinely leave back doors. Work through all of these in your account’s Security and mailbox settings:
- Sign out everywhere. Use the option to sign out of all sessions/devices so any active attacker session dies.
- Review security info. Remove any phone number or alternate email you don’t recognize. If Microsoft holds removals in a 30-day pending window, start that clock now.
- Remove app passwords and revoke access for any connected apps or services you don’t recognize.
- Check mail forwarding. In Outlook.com settings under Mail, look at Forwarding — attackers commonly forward a copy of all your mail to themselves. Turn off anything you didn’t set up.
- Check inbox rules. Delete rules you didn’t create, especially ones that move messages to RSS/Archive folders or delete mail containing words like “password” or “verification” — a classic trick to hide reset notices.
- Check the Sent and Deleted folders to gauge what the attacker did, and restore anything they deleted (Deleted Items, then “Recover items deleted from this folder”).
- Review recent activity on the account’s security page to see when and roughly where the unauthorized sign-ins happened.
Step 4: Turn on two-step verification
Once the account is clean, enable two-step verification in Security settings, ideally with the Microsoft Authenticator app rather than SMS. Generate a recovery code and store it somewhere safe offline. Consider passkeys if your devices support them. This is the single change most likely to prevent a repeat.
Step 5: Repair the collateral damage
- Change passwords on other accounts that shared this password or use this mailbox for resets — banking and shopping first. Check those accounts for password-reset emails you didn’t request.
- Warn your contacts if the attacker sent mail from your address, so nobody clicks a malicious link “from you.”
- Check connected services: OneDrive files, Skype, Xbox, and any subscriptions billed to the account, for unauthorized changes or purchases. Dispute unauthorized charges through Microsoft’s order history.
What NOT to do
- Never share verification codes with anyone, including someone claiming to be Microsoft helping you “secure” the account. Real Microsoft systems only ask you to type codes into Microsoft’s own pages.
- Ignore “Microsoft support” calls and browser popups. Microsoft does not cold-call about hacked accounts, and full-screen “your account is compromised, call this number” popups are scams. Close the tab; never install remote-access software for a caller.
- Do not pay account recovery services. Nobody outside Microsoft can force access to a Microsoft account. These services either fill in the same free form you can, or simply take your money — and your personal details.
- Do not hammer the recovery form with rushed, half-empty submissions. Attempts are limited per day and each weak one teaches you nothing. Improve each submission instead.
- Do not delete the account or mailbox contents in frustration before you’ve checked what other services depend on it.
If nothing works
If the attacker changed all security info more than 30 days ago and the recovery form keeps failing, the hard truth is that consumer Microsoft accounts have no human-review escalation. The account, and any mail still in it, is effectively lost to you.
Prioritize containment: treat every account that used that address for login or recovery as at-risk. Move each one to a new email address, change its password, and update recovery info — starting with financial accounts and your other email accounts. Watch for phishing aimed at you specifically, since the attacker now has your correspondence and contacts. Then start fresh with a new account protected from day one: two-step verification, an authenticator app, a saved recovery code, and a second verification method. Report the compromised address to your contacts so they distrust mail from it.
Frequently asked questions
How do I know if my Outlook account was actually hacked?
Common signs: contacts receive spam from you, sent items you didn't write, sign-in alerts from unfamiliar locations, changed security info, or mail rules that forward or delete messages. Check the recent activity page once you're back in.
The hacker changed my password. Can I still get my account back?
Often yes. Use the password reset flow first; if your security info was changed, the account recovery form at account.live.com/acsr is the remaining path. Microsoft holds security info changes in a pending state for up to 30 days, which works in your favor.
Should I delete the emails the hacker sent from my account?
You can, but first screenshot anything relevant if you may need evidence, and warn recipients not to click links. Deleting them doesn't undo the compromise — securing the account does.
Can the hacker still read my email after I change the password?
Yes, if they left behind app passwords, connected devices, forwarding rules, or an active session. Sign out everywhere, remove unknown devices and app passwords, and check forwarding and inbox rules.
Will Microsoft tell me who hacked me?
No. The recent activity page shows approximate locations and IP addresses of sign-ins, but Microsoft will not identify a person, and location data from VPNs is unreliable anyway.
recover.email is not affiliated with Microsoft. This guide is informational and cannot guarantee recovery.