My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Anonymous
    2018-07-14T18:05:31+00:00

    Same problem today : 

    Protocol: IMAP

    IP: 115.135.0.13

    Account alias:

    Time: 12 hours ago

    Approximate location: Malaysia

    Type: Successful sync

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-08-15T15:15:33+00:00

    This is clearly a massive security hole by Microsoft. Last night I also got the email telling me I needed to change my password as my account has been compromised. I changed password and then checked the logs. My account successfully synced with IMAP from Brazil!!!! Then checking, successfully synced from India 2 days ago with IMAP again. Further back I have a successfully synced from Belarus over a month ago and now Microsoft suddenly a month later think it is a good idea to let me know my account has been compromised and obviously using IMAP that means whoever has been able to use IMAP to connect to my account  has downloaded a copy of my hotmail account that I have had for over 15 years. This is unacceptable that Microsoft doesnt block IMAP connections from random locations around the world.

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2019-02-07T03:18:48+00:00

    I've had "automatic sync" show up in my "Recent Activity" numerous times - a couple of weeks later (seriously!) I've gotten a notification of "We think that someone else might have accessed (insert-mail address here)..."

    At which point I'm forced to change my password. Again.

    MS never actually tell me why they think someone else has accessed my account, and "Recent Activity" never shows any suspicious events within the preceding 24 hours or so.

    I have two-stage authorisation set up, and am using Authenticator. Just checked "Recent Activity", and there are four more attempts at Automatic Sync in the last few hours - three from Brazil, one from Malaysia. As I'm a resident of neither, you'd think Microsoft would automatically block them. Not so...

    It gets worse! Here's the Recent Activity showing the four attempts as being "unsuccessful":

    BUT... if I click on "Secure your account", the exact same events suddenly change to "successful":

    What on earth is going on?

    I'll confess that my Internet knowledge is scant and there may be reasons why not, but I'm an Australian living in Australia - literally ALL my legit account activity is from IP's based in Australia. If Microsoft detects an attempt to access my account from, y'know, the other side of the world, why would they allow it to proceed?

    If ALL my account activity is from, say, Sydney, then someone tries to login / automatically sync from Brazil, why wouldn't they automatically flag that as suspicious, and block it?

    Makes no sense to me...

    Hi there!

    Thank you for your inquiry.

    I am pleased to inform you that the change from "unsuccessful sync" to "successful sync" after you clicking Secure your account is just a visual bug. The hacker cannot log in to your account if you have two-step verification enabled.

    If you do not have two-step verification enabled, Microsoft security algorithms will proactively block login attempts with unrecognised devices from unfamiliar locations/networks. This is when the Recent activity page truly matters.

    Otherwise, you do not have to monitor your Recent Activity page because the hacker would need very sophisticated resources/equipment to hack accounts with 2-Factor Authentication in place… usually for targeted state-sponsored attacks.

    Cheers!

    — XP

    Was this answer helpful?

    6 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-01-23T09:22:16+00:00

    I have the same problem,. Can someone from Microsoft please help!

    Was this answer helpful?

    6 people found this answer helpful.
    0 comments No comments