Yes, Sasha, that email indicates the person, or more likely bot, that took over your account had already managed to acquire and use whatever password and other security verification method(s) were breached or collected in order to receive that email providing access to managing the account.
That's not the question, you've established you lost control of the account. The only question that remains to be answered is how they got access to most likely the password, as well as at least one other form of verification in order to be allowed to generate that message, since the password alone has never been enough.
It may not ever be possible to confirm this with any certainty, but it's critical that you understand how the account might have been breached in order to ensure you're protecting your new one. If your password was relatively short and especially simple, like a word or two, that alone could have allowed that to be breached, but duplicate passwords used on other websites that were breached, along with malware on your personal systems are possibilities as well.
As for the other form of verification, it's less likely they managed to directly breach a phone number or text, though if you ever responded to a supposed text message sent by Microsoft or provided this information to a 3rd party, those are common ways these are acquired from the account owner himself. Easier though is to acquire access to an alternate email account that's not as well protected, like a cable or similar email address that was included in the list of optional verification methods for your original account.
My own verification methods including the wireless company personal account that provides access to my smartphone information, as well as my alternate email account, all include 2-factor (2-Step in Microsoft terminology) authentication. Meaning you'd need 2 forms of identification typically including the password as the first, so the password can never be used alone and is never the same on any of these sites as any other, as well as relatively complex with no simple words or other easily hacked patterns.
Only you can determine what combination of less well secured verification method(s) may have been used to hack that older account, since only you know the answers to these questions, if anyone. In some cases, it's not possible to know how your password was acquired, but understanding the risks lets you better create and protect this in the future to avoid it ever happening again.
Note that I'm a past computer administrator and security professional who worked for and with computer, education and other major corporate customers, so I have a background in dealing with these issues for hundreds or thousands of users for over 40 years. In that time, I've seen all sorts of things, but typically my greatest problem was the employees, students and personal users of the devices themselves, since they've always been the easiest way to breach any system or account.
Rob