Got hacked by a rambler.ru account

Reported
Anonymous
2023-02-08T07:58:18+00:00

My microsoft account got hacked by a rambler.ru account and replaced my original email with theirs. that email address is [PII Removed] i requested a security info change from that email address back to my own but now my account is locked for two days and i'm not sure if requesting a security info change alone would be enough to keep the hacker from my account.

from my understanding too, I believe that they originally got to my microsoft account by hacking my email credentials.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
DaveM121 930.8K Reputation points Independent Advisor
2023-02-08T08:33:39+00:00

Hi Keiran,

I am Dave, I will help you with this.

Usually when a hacker changes the Email on a Microsoft Account, then that account cannot be recovered, it is lost and there is no method to recover the account.

If you have been luck enough to be able to recover your account, when the 2 day time period has lapsed, it would be best to ensure you have a very strong password on your account and enable 2 factor authentication on your account to ensure the hacker no longer can access your account.

0 comments No comments
Answer accepted by question author
Don Varnau 19,930 Reputation points Volunteer Moderator
2023-12-31T15:50:36+00:00

Jo Leal wrote:

i got hacked and i need your help

  1. If the hacker/hijacker has changed the email address by creating an alias then deleting your address, now a non-primary alias, you will not be able to recover this account.

Check for that by trying to sign-in with the original address https://outlook.live.com If you are told that the account doesn't exist, you're out of luck.

  1. Relevant article #1

https://support.microsoft.com/en-us/account-billing/how-to-recover-a-hacked-or-compromised-microsoft-account-24ca907d-bcdf-a44b-4656-47f0cd89c245 

  1. Article #2

https://support.microsoft.com/en-us/account-billing/help-with-the-microsoft-account-recovery-form-b19c02d1-a782-dee6-93c3-dc8113b20c42 

4. And... since people ask...

Microsoft Support contacted via phone or chat won't be able to help you with this.

In this article https://support.microsoft.com/en-us/account-billing/contacting-support-for-a-microsoft-account-bb65aa6a-9135-31df-0b36-d6318d6f4e0f 

is the warning that

"Important:****To protect your account and its contents, our support agents and advocates are not allowed to send password reset links or access and change account details."

Don

0 comments No comments

148 additional answers

Sort by: Most helpful
  1. Anonymous
    2023-11-06T13:11:09+00:00

    I agree with Sasha. I too have been hacked by rambler.ru and I too worked for Microsoft for many years. I have not received any useful help or direction on how to recover my account to regain access to my OneDrive or the O365 app I paid for. I have followed the instructions to recover the account multiple times but the hacker is so good, none of my responses to questions is accurate anymore. Please find an answer!

    0 comments No comments
  2. Anonymous
    2023-11-06T01:15:39+00:00

    Hi Rob

    I am impressed. Your background sound somewhat similar toind except I have 2nd level support plus data base correction with enterprise functional support and a little cyber security thrown in. You can imagine how freaked out I was to see my emails were taken over and spamming ppl.. Mostly you have been correct and have comprehended all facets of my issue. The only part that was nott completely known was that I have 3 other registered accounts used for sisterting each other and multifmulti factor authentication. I had my phones linked to Microsoft as well but the Pi link from microsoft... which I never requested not touched I suspect was the trigger. The Microsoft website states since 2020 that this trojan/bot does bypass all multifacotor authentication such you discussed above and I had/have in place now. Trust me. The issues that arise from having a multifacotor authentication method that you can it log into and update are mindbending.

    Many thanks for some intelligent and focused replies...

    0 comments No comments
  3. Rob Koch 26,160 Reputation points Volunteer Moderator
    2023-11-05T21:11:02+00:00

    Yes, Sasha, that email indicates the person, or more likely bot, that took over your account had already managed to acquire and use whatever password and other security verification method(s) were breached or collected in order to receive that email providing access to managing the account.

    That's not the question, you've established you lost control of the account. The only question that remains to be answered is how they got access to most likely the password, as well as at least one other form of verification in order to be allowed to generate that message, since the password alone has never been enough.

    It may not ever be possible to confirm this with any certainty, but it's critical that you understand how the account might have been breached in order to ensure you're protecting your new one. If your password was relatively short and especially simple, like a word or two, that alone could have allowed that to be breached, but duplicate passwords used on other websites that were breached, along with malware on your personal systems are possibilities as well.

    As for the other form of verification, it's less likely they managed to directly breach a phone number or text, though if you ever responded to a supposed text message sent by Microsoft or provided this information to a 3rd party, those are common ways these are acquired from the account owner himself. Easier though is to acquire access to an alternate email account that's not as well protected, like a cable or similar email address that was included in the list of optional verification methods for your original account.

    My own verification methods including the wireless company personal account that provides access to my smartphone information, as well as my alternate email account, all include 2-factor (2-Step in Microsoft terminology) authentication. Meaning you'd need 2 forms of identification typically including the password as the first, so the password can never be used alone and is never the same on any of these sites as any other, as well as relatively complex with no simple words or other easily hacked patterns.

    Only you can determine what combination of less well secured verification method(s) may have been used to hack that older account, since only you know the answers to these questions, if anyone. In some cases, it's not possible to know how your password was acquired, but understanding the risks lets you better create and protect this in the future to avoid it ever happening again.

    Note that I'm a past computer administrator and security professional who worked for and with computer, education and other major corporate customers, so I have a background in dealing with these issues for hundreds or thousands of users for over 40 years. In that time, I've seen all sorts of things, but typically my greatest problem was the employees, students and personal users of the devices themselves, since they've always been the easiest way to breach any system or account.

    Rob

    0 comments No comments