My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Anonymous
    2020-01-07T14:17:47+00:00

    Hello, i just had a similar issue. I got a notifications this morning of a successful sync in Pakistan, and when i woke up this morning I immediately changed my Microsoft password and am beginning to strengthen security all around. I had many unsuccessful attempts from random countries before, including one shortly after my password change. I did find out i was actually pwned, but it was from several months ago, making it surprising nothing happened till now if it was legitimate. Any idea if this is related to previous issues in this thread or if this is a new issue to take seriously? I am very nervous.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2019-04-20T08:17:39+00:00

    Hi everyone, it's looking increasingly likely that Microsoft is hiding the extent of the hack. It seems most of us affected here is due to the recent reported hack. Keep in mind intially Microsoft played down the hack until motherboard exposed them so they admitted to it. Microsoft says it a "minor" user base that was affected but i don't think that's true, most people are probably not even aware they were hacked. 

    Their support when contacted continued to blame us for a long time despite us reporting this to Microsoft for a while now. Hackers were able to read and download our entire email history, make changes to our outlook settings (e.g adding certian rules, etc), our identity and online security is at serious risk. This is unacceptable, Microsoft sent a notice and that's it ? i believe some form of serious investigation and action should be conducted.

    There are 10K views on this thread and 400 users with the "Same question" , this is no minor incident

    Some articles about this topic

    https://www.independent.co.uk/life-style/gadgets-and-tech/news/microsoft-outlook-emails-hacked-hotmail-msn-live-hackers-a8870566.html

    https://www.theverge.com/2019/4/15/18311112/microsoft-outlook-web-email-hack-response-comment

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2019-01-31T19:11:16+00:00

    Hey guys,

    I also got hacked.

    The thing I am really worried about are all my files on OneDrive.

    I looked up the recent activity and there is an entry called "automatic syncronisation". There are numerous sub-entries telling me that numerous IMAP syncs were successful. Does that mean that the hacker only accessed my account via IMAP Server and most likely wasn't able to check out my OneDrive files?!

    Thanks a lot for your help!

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2019-01-19T18:38:25+00:00

    Is it safe to delete my MS account? I moved on and made sure all the sites my email has been on has been removed and or changed.

    I don't like MS anymore and I'm dead worried.

    Like Microsoft please disable Email sync, there's a reason why it must be password only or no sync at all.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments