Got hacked by a rambler.ru account

Reported
Anonymous
2023-02-08T07:58:18+00:00

My microsoft account got hacked by a rambler.ru account and replaced my original email with theirs. that email address is [PII Removed] i requested a security info change from that email address back to my own but now my account is locked for two days and i'm not sure if requesting a security info change alone would be enough to keep the hacker from my account.

from my understanding too, I believe that they originally got to my microsoft account by hacking my email credentials.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
DaveM121 930.8K Reputation points Independent Advisor
2023-02-08T08:33:39+00:00

Hi Keiran,

I am Dave, I will help you with this.

Usually when a hacker changes the Email on a Microsoft Account, then that account cannot be recovered, it is lost and there is no method to recover the account.

If you have been luck enough to be able to recover your account, when the 2 day time period has lapsed, it would be best to ensure you have a very strong password on your account and enable 2 factor authentication on your account to ensure the hacker no longer can access your account.

0 comments No comments
Answer accepted by question author
Don Varnau 19,930 Reputation points Volunteer Moderator
2023-12-31T15:50:36+00:00

Jo Leal wrote:

i got hacked and i need your help

  1. If the hacker/hijacker has changed the email address by creating an alias then deleting your address, now a non-primary alias, you will not be able to recover this account.

Check for that by trying to sign-in with the original address https://outlook.live.com If you are told that the account doesn't exist, you're out of luck.

  1. Relevant article #1

https://support.microsoft.com/en-us/account-billing/how-to-recover-a-hacked-or-compromised-microsoft-account-24ca907d-bcdf-a44b-4656-47f0cd89c245 

  1. Article #2

https://support.microsoft.com/en-us/account-billing/help-with-the-microsoft-account-recovery-form-b19c02d1-a782-dee6-93c3-dc8113b20c42 

4. And... since people ask...

Microsoft Support contacted via phone or chat won't be able to help you with this.

In this article https://support.microsoft.com/en-us/account-billing/contacting-support-for-a-microsoft-account-bb65aa6a-9135-31df-0b36-d6318d6f4e0f 

is the warning that

"Important:****To protect your account and its contents, our support agents and advocates are not allowed to send password reset links or access and change account details."

Don

0 comments No comments

148 additional answers

Sort by: Newest
  1. Rob Koch 26,160 Reputation points Volunteer Moderator
    2023-11-05T21:11:02+00:00

    Yes, Sasha, that email indicates the person, or more likely bot, that took over your account had already managed to acquire and use whatever password and other security verification method(s) were breached or collected in order to receive that email providing access to managing the account.

    That's not the question, you've established you lost control of the account. The only question that remains to be answered is how they got access to most likely the password, as well as at least one other form of verification in order to be allowed to generate that message, since the password alone has never been enough.

    It may not ever be possible to confirm this with any certainty, but it's critical that you understand how the account might have been breached in order to ensure you're protecting your new one. If your password was relatively short and especially simple, like a word or two, that alone could have allowed that to be breached, but duplicate passwords used on other websites that were breached, along with malware on your personal systems are possibilities as well.

    As for the other form of verification, it's less likely they managed to directly breach a phone number or text, though if you ever responded to a supposed text message sent by Microsoft or provided this information to a 3rd party, those are common ways these are acquired from the account owner himself. Easier though is to acquire access to an alternate email account that's not as well protected, like a cable or similar email address that was included in the list of optional verification methods for your original account.

    My own verification methods including the wireless company personal account that provides access to my smartphone information, as well as my alternate email account, all include 2-factor (2-Step in Microsoft terminology) authentication. Meaning you'd need 2 forms of identification typically including the password as the first, so the password can never be used alone and is never the same on any of these sites as any other, as well as relatively complex with no simple words or other easily hacked patterns.

    Only you can determine what combination of less well secured verification method(s) may have been used to hack that older account, since only you know the answers to these questions, if anyone. In some cases, it's not possible to know how your password was acquired, but understanding the risks lets you better create and protect this in the future to avoid it ever happening again.

    Note that I'm a past computer administrator and security professional who worked for and with computer, education and other major corporate customers, so I have a background in dealing with these issues for hundreds or thousands of users for over 40 years. In that time, I've seen all sorts of things, but typically my greatest problem was the employees, students and personal users of the devices themselves, since they've always been the easiest way to breach any system or account.

    Rob

    0 comments No comments
  2. Anonymous
    2023-11-05T09:33:15+00:00

    ----- Original Message -----

    From:  "Microsoft (do not reply)" <maccount@microsoft.com> To: <###########@#####.au>

    Sent: Thu, 13 Apr 2023 07:09:41 -0700

    Subject: Here's the link that you requested

    Hello there, <br> :---
    Here's the link that you requested!<br><br>Select Manage communication permissions to update the emails that you receive from Microsoft.<br><br><br> Manage communication permissions <br> :---: <br> :---
    Microsoft respects your privacy. To learn more, please read our Privacy Statement.<br><br>Account questions? Visit Customer Support. <br> :--- <br> <br>

    Note the different time zones

    0 comments No comments
  3. Rob Koch 26,160 Reputation points Volunteer Moderator
    2023-11-05T03:35:03+00:00

    Sasha Jones,

    Since there's simply no way from what I've read to get back a Microsoft account that's had the primary alias renamed, deleted and all of the associated verification information changed, I think the primary item of interest at this point should be to try and understand how that happened in order to avoid it in the future.

    One obvious way is to never get another Microsoft or any other account, since if you can't determine how it happened, the failure is likely to be repeated. It seems from your list that you had the Microsoft Authenticator installed, but I don't understand listing the "main Authenticator account" and main Microsoft account" separately, since these would typically be the same thing?

    Though there have been complex hacks using tokens, I suspect that most personal account hacks are much simpler combinations of a breached, brute forced or phished password along with possibly a less secure verification email from someplace like a cable company or other less secure provider who doesn't offer or simply didn't have 2-factor authentication enabled. The other common method has been gamers who've downloaded either cracks, cheats or mods for games, all of which virtually always contain malware and would have provided a hacker with everything they need to bypass 2-Step (2FA) authentication.

    Though I believe Microsoft and Google should have either worked faster to provide more secure methods of authentication and/or worked harder to explain these relatively complex issues to their customers, I do understand why this may not have been possible several months ago, since many of the improvements to these systems weren't available at that time.

    So, this isn't an excuse, simply an explanation of reality in hopes that some might spend the time necessary to better protect their own accounts, since the bad actors are no longer script kiddies, but rather nation states who are obviously making big money or getting other value out of acquiring existing accounts, personal or business.

    Rob

    0 comments No comments