My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Anonymous
    2019-05-04T13:00:09+00:00

    It seems that this is not goin to be fixed... Well, i think is time to change email, it happened to me 12 days ago and a few hours ago apeared again, this time unsuccesfuly AND the past 2syncs just dissapeared... Fuh...

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-04-16T10:20:08+00:00

    They are still getting your emails trust me. I have a work around so they cant get new emails but when I set this up they LOGGED in and changed my settings allowing them to again get my emails. Its a total mess really.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-04-15T18:38:45+00:00

    This hack mentioned in your link is an entirely different issue. The problem we are all facing has been going on for years, and is not due to the hacking of a microsoft support agent's account. The problem people here are facing has been going on for years, whereas this only hack was in January 2019. We still don't know how hackers were able to access our account data (emails, passwords, etc.). It would be nice to have a definitive answer from Microsoft.

    I know personally that I was hacked because my sim card was cloned, which gave the hackers access to different accounts (including microsoft) and led to similar problems that people here are mentioning. But what happened to me is also different then the problem that people here are facing, which is the bypassing of 2-factors authentication, and getting access to the account with IMAP sync, even if the hackers do not have the account's password.

    My sim card got cloned in February 2018 (more than a year ago), and the hackers are still trying to sync  to my account on a daily basis. The last unsuccessful sync attempt was made 3 hours ago from Columbia (I do not use a VPN service).

    It's all very disturbing and trust-eroding, especially that at the time of writing this, 380 other users have the same question, and that it's been going on for so long.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-04-15T12:07:24+00:00

    Try contact microsoft becasue they will blame your security tactics. Just move from microsoft or risk all your banking, apps, everything.

    Was this answer helpful?

    0 comments No comments