My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Anonymous
    2019-08-02T15:38:35+00:00

    i say lets file lawsuit against Microsoft ,

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-09-17T17:13:31+00:00

    I'd like to contribute to this thread that I recently encountered the same issue.

    I was notified this past weekend of a log-in from a neighboring state, and when I saw similar "Successful Syncs" starting from the end of August, I locked down the account.

    The previous password for my account was as strong alphanumeric password unique to the account and less than 2 years old.

    The account alias was an @hotmail.com account that I've had since the late 90's. There are only four devices I ever access it from. 2 mobile devices, a work pc, and a personal PC. All those devices have relatively strong security, do not install software from untrusted sources, and use browsers with current security updates. I believe the last time I used the account for e-mail was around 2001 when the Hotmail e-mail access was shut down due to "inactivity".

    Also of note was the fact that until a month ago I had never logged into Outlook.com to use the e-mail functionality of my MS account. I don't know if that factors into it, but I do find it noteworthy. Thankfully because of this I had (hopefully) nothing of note that could have been sync'd, although I do not know what there were able to access with the few minutes from a browser-based log-in. There were some XBox Live e-mails, spam, and apparently a Uber account someone had mistakenly signed up for using my e-mail (Uber e-mails were all in Spanish and addressed to someone else's name).

    I don't know how long the sync's have been going on for since apparently we only get 28 days of history, but there doesn't appear to be any browser based log-in attempts outside of the one that triggered the alert e-mail. I don't see any failed log-in attempts in my history for that matter. Since I do not use my account for e-mail nothing should be attempting to sync via IMAP. What's also odd is that the sync attempts were typically 2-5 days apart. The earliest entry shows a successful pop3 sync which I find odd since according to the Outlook.com settings POP3 is disabled.

    None of my other accounts with other services have had any suspicious activity.

    I've since change the password, enabled 2fa, and switched the alias as well as disabled logging in for the previous alias.

    While I understand MS wants us to use their services, I don't understand why we don't have an option to opt out here. It seems the IMAP sync attempts are a common theme in the thread and other posts here and I feel we should at the very least have the option to disable IMAP access to our accounts. It feels like we are having a possible security hole vector forced on us.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-08-07T16:17:54+00:00

    This also happened to me, with a 14 character strong password. Like others, I wasn't informed until 10+ days after the first successful sync. I spoke to someone at Microsoft via their support chat and much like has been said above, they tried to place the blame on a VPN. It was a frustrating conversation because while they implied I was safe, I wanted a guarantee that my data hadn't been accessed or stolen and it wasn't forthcoming.

    In a case like this, activity from another country should be instantly blocked until the user's identity can be verified. That the access happened over IMAP suggests to me a long standing vulnerability that Microsoft is trying to cover up.

    So what's going on Microsoft?

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-01-23T14:58:28+00:00

    It happened because you had an easy to guess password on your account, you used the same password on a hacked website, or you have malware on one of your systems.

    I would suggest that you turn on multifactor authentication and be sure to have multiple devices setup.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments