My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Newest
  1. Anonymous
    2019-01-15T23:59:04+00:00

    I have had a similar experience to most on this post.  I have never used a VPN.  I was notified fairly quickly (Thankfully) that an attempt to log in to my account was blocked.  The same happened when I secured my account, an unsuccessful sync became a successful one.  I decided to totally phase out my microsoft email all together and to switch to a secondary one I have entirely separate from my microsoft account.  I also changed my password.  This happened on the day I post this so I am not sure if my actions have been successful or not.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-01-08T09:22:51+00:00

    Hey i got the same issue, can someone from MS contact me plz. from what i hear it sounds like a data breech is it? i had a few successful syncs now I'm really scared plz help!!!

    i located some of the successful syncs it says one is from Republican Unitary Telecommunication Enterprise Beltelecom who the hell is that! i located others and its saying Belorussian and Russian ISPs there were blank ones aswell what is going on.

    PS. im extremely disappointed as a shareholder if its hack notify the authorities STAT

    PPS checked more one synced with a Bangladesh ISP and another one Malaysian ISPs 

    PPPS i don't know if they used the WHOIS hide away service but still

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-01-06T00:49:33+00:00

    Same thing here. I used a strong 15 char password on this account and only this account, and some how I got successful sync from around the world.  I noticed there were no log in attempts associated with these syncs, either successful or unsuccessful attemps. These guy might be using some sort of applications authentication bypass or exploit for these syncs.  I wish Microsoft would come online an warn users and then take action to prevent it from happening again.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2019-01-04T15:53:03+00:00

    I just ran into the same IMAP automatic sync problem.  There have been multiple successes in the past one month from various locations, and I just got notified.  I am really damn pissed!

    Was this answer helpful?

    0 comments No comments