I believe what all of this stems from, in most of our cases, is our email addresses appearing - at one point or another - in a list of compromised usernames/passwords in hacked database leaks. I figure that multiple attackers are
constantly running through these lists looking for accessible accounts.
Sites like Haveibeenpwned are pretty good at telling you if your e-mail appears in any of the breaches that have been made public.
Anyways, I think I figured out a fix or work-around for these issues.
Warning : go through these steps carefully. Going about this a different way initially, I was given a prompt that informed me I would permanently lose the ability to receive or send e-mail from the hotmail account I was trying to fix if I clicked Yes. Done right, you should not run into that prompt, and will merely be using the new alias to sign in.. you will no longer be able to sign in with your old email address, but will still be able to send and receive mail from it and use it normally.
- First, go to the Your Info link at the top of your Microsoft Account page. Click Manage how you sign in to Microsoft.
- Under 'Account aliases', add an e-mail address or phone number. Verify it, and then click Make primary on the new alias.
- Under 'Sign-in preferences' on the same page, click Change sign-in preferences.
- Remove the check mark next to your old, initial email address and only leave the new primary alias checked. Click Save.
Just to be safe, for the new alias, I used a gmail account that I know hasn't been compromised in the past, has a strong password, and has 2 factor authentication enabled.
After doing the aforementioned things, sync and login attempts instantly dropped to zero and have stayed that way. Hope this helps some of you find relief from this frustrating and anxiety-inducing debacle.