My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Anonymous
    2020-10-18T07:18:31+00:00

    I got this yesterday!!!! what's going on! and what's they sync from my email!!!

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2020-09-05T19:20:26+00:00

    So like many others i have been notified by microsoft of suspicious activity on my account. It was a notification after a successful IMAP sync which tells me all my email has now been compromised - and Microsoft detected it as suspicious activity. 

    Now IMAP syncs are being attempted from all over the globe. I have secured my account (password changed and twi factor authentication enabled) however like most of the other respondents to this thread i can not understand why Microsoft allows an obviously fraudulent access go unchallenged.

    As a technology company that prides itself on security how can you allow this to continue. Unusual activity must be blocked. Allowing it to process successfully and then notifying us is ridiculous. Fail suspicious activity and notify us.

    Please address this obvious limitation on your security and fraud prevention controls and protect your customers.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2020-06-19T12:27:59+00:00

    I've the same problem! (2020 Jun)

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2020-05-22T11:03:49+00:00

    Microsoft is leaking information to Facebook and Google like names ,emails , letters , family pictures , phone numbers , bank accounts , Facebook basically a front , they sell data , credit report . background checks . it goes lot further i can send you link but you buy your family's credit , photo's , work history , where they lived , past bills .work history , company's hire this company owned by Facebook . they got company's all around the world . they nothing they don't no about you or your family , they report to credit company but you never see them , https://www.dnb.com/business-directory/company-search.html?term=Microsoft&page=1   , this is just part of it , Facebook ,Google they all bunch up , Google Corporate Office Address: Erika-Mann-Straße 33, 80636 München, Germany

    Hours

    Open ⋅ Closes 9PM   Phone+49 89 839309029.   https://www.corian.com/the-new-microsoft-germany-hq-facade-features-fascinating-depth-thanks-to-corian      then you got Facebook trading with Microsoft for $$$ , https://www.dnb.com/business-directory/company-search.html?term=Facebook&page=1  and google . https://www.dnb.com/business-directory/company-search.html?term=google&page=1   ,then comes Experian . but you can buy your credit report ,your history , from any of these company's .  it works in circle , the company pays the around 800.00 a person ever month maybe two weeks not sure . the company reports your work ,payroll ,address, they report back more information . You can look all this up and find more company's tied to your Email ,home ,work ,family , but thank these for making a living off of us .then Data Breach , that just data dump , upload new information ,

    Was this answer helpful?

    0 comments No comments