My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Newest
  1. Anonymous
    2019-03-05T17:23:48+00:00

    the change to 'successful' is a fault in the page when it updates after the password change

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-03-02T03:47:39+00:00

    This is getting ridiculous, I've also had multiple sign in attempts with IMAP and POP3 from multiple IPs. They are unsuccessful, but when I change my password and I click, "Secure your account", it then changes to "successful sync." Is this just an error on MS' end? If so, how do you fix it? Is it possible for a hacker to bypass 2FA since I have it enabled?

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-02-25T09:21:14+00:00

    I recently had an account have its password reset, and the only way that could have happened is if my @hotmail emails were accessed.

    My hotmail account:

    -Crazy strong password

    -2FA enabled

    -No app passwords

    Lots of unsuccessful automatic IMAP sync attempts around that time from Brazil, Indonesia, Japan, Russia, Colombia, India, Mexico, Vietnam, United States, China....

    I reckon they got in this way.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-02-15T08:36:28+00:00

    In my Windows 10 settings Sync = off. Yet several successful sync attempts from Russia and Korea and finally one failed attempt from Japan. I haven't left the Netherlands the last 12 month. I want to find out what they sync if sync=off. I did not sign in with any Microsoft account until recently. I had to because I wanted to use Skype. I had two Skype accounts under my own name and Microsoft found out the 2 Skype and the old hotmail account were one person. I had a password that only could be guessed after several million tries. I did not use this password for other services.  Microsoft asked me to change it, which I did. I hope this problem is unrelated, but the tax service, Belastingdienst, says that I authorized someone to do my taxes. I never authorized anyone. They don't say whom I authorized, they only give the name of a software company that does the authorizations for them. With a false authorization you can change the bank account, change 5 years of income to 0 and then receive all taxes back on the hacker's bank account. Later I would have to pay back plus fines and interest. In Europe everybody has the right to ask all personal data that are stored. So I believe Microsoft is obliged to tell me what data they leaked to Russia, Korea and Japan, even if they claim it is my own fault.

    Was this answer helpful?

    0 comments No comments