My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Anonymous
    2019-01-04T15:53:03+00:00

    I just ran into the same IMAP automatic sync problem.  There have been multiple successes in the past one month from various locations, and I just got notified.  I am really damn pissed!

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-11-20T05:39:02+00:00

    they dont care.   they blame it on you the user.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-11-20T04:40:51+00:00

    So, I recently get a text notification that someone attempted to sign into my account.  After signing in, checking, changing my password, I check account activity and notice that IMAP has been setup and synched..to someone in Pakistan and the Netherlands, on the same day... 2 weeks ago.  It made me curious why exactly I did not receive a notification about this on my phone.  I checked some more, and there was a 3rd attempt on the same day in Thailand, but, it was unable to synch due to incorrect password.  However, noticed that it was not doing an IMAP synch through a mobile device, but, a simple login, and it was unsuccessful. 

    My question is:  why is Microsoft waiting 2 weeks not notify people?

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-11-12T01:47:50+00:00

    I had the same issue today even though I had 2 factor set up.  At first i thought i was in the clear because I didn't have any emails on the account, but then remembered that I used to have my other email accounts downloaded to this account 2 years ago to alias accounts.  So worst case, someone got 2 year old emails.

    So I was curious to see if they would only get emails from the main account or from all alias accounts as well.  I set up a POP3 client and tried to connect via one of my alias accounts, but kept getting errors and was never able to get anything from the account.  Tonight I looked and see 1 notification of an attempt to sync POP3 on the alias account - which must have been me - and it says "successful sync", even though I wasn't able to successfully get the client to connect.

    Last year I had a bigger scare because I got a notification from MS that my Wife's account was compromised.  She had some files with sensitive info on her OneDrive account and I totally freaked out.  Once again, it wasn't clear whether anyone actually successfully got into her account or not.  I ended up purchasing credit monitoring service for my family and have been watching carefully since.  We locked down our bank accounts and changed all of our passwords.

    This time, right or wrong, I'm not as worried.  I don't trust the MS recent activity information.  But I did change my password and delete all of the old email.  I disabled my OneDrive syncing on all of my computers last year because I don't trust MS as far as I can throw Bill Gates.

    Was this answer helpful?

    0 comments No comments