My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Newest
  1. Anonymous
    2018-09-18T18:30:56+00:00

    And another PayPal scam email just today!  This time my name is on it.   It's like these posts are being read and it just so funny to send me another one.   This is why I think my email was downloaded.  At least 2-3 of these per week.    I just forward these to *** Email address is removed for privacy ***.

    Click here to view this<br> message in your browser.
    <br> --- --- <br><br><br><br><br><br><br><br><br> <br> --- <br> --- <br><br><br><br><br> Dear Richard Burbage:  <br><br> <br><br>We're sending you a copy of our Annual Error Resolution Notice to provide helpful information if you have a billing error or unauthorized transaction on your PayPal account. Just remember that you can check out our Error Resolution<br> Notice anytime by going to the section of our User<br> Agreement "Liability for Unauthorized Transactions and Other Errors". <br><br> <br><br>As always, if you need help or have any questions, visit our Help<br> Center. You can also find the link on any page of our website. <br><br> <br><br>Thank you for being a PayPal customer.  <br><br> <br><br>Sincerely,  <br><br>PayPal <br> --- <br> Annual Error Resolution Notice <br> In case of errors or questions about your electronic transfers, please call us at 888-221-1161 or write us at PayPal, Attn: Error Resolution Department, P.O. Box 45950, Omaha, NE 68145-0950<br> as soon as you can, if you think your statement or receipt is wrong or if you need more information about a transfer listed on the statement or receipt. We must hear from you no later than 60 days after we sent the FIRST statement on which the problem or error<br> appeared.<br><ol><br><li>Tell us your name and account number (if any).</li><li>Describe the error or the transfer you are unsure about, and explain as clearly as you can why you believe it is an error or why you need more information.</li><li>Tell us the dollar amount of the suspected error.</li></ol><br>If you tell us orally, we may require that you send us your complaint or question in writing within 10 business days.  <br><br> <br><br>We will determine whether an error occurred within 10 business days after we hear from you and will correct any error promptly. If we need more time, however, we may take up to 45 days to investigate your complaint or question. If we decide to do this, we will<br> credit your account within 10 business days for the amount you think is in error, so that you will have the use of the money during the time it takes us to complete our investigation. If we ask you to put your complaint or question in writing and we do not<br> receive it within 10 business days, we may not credit your account.  <br><br> <br><br>For errors involving new accounts, point-of-sale, or foreign-initiated transactions, we may take up to 90 days to investigate your complaint or question. For new accounts, we may take up to 20 business days to credit your account for the amount you think is<br> in error.  <br><br> <br><br>We will tell you the results within three business days after completing our investigation. If we decide that there was no error, we will send you a written explanation. You may ask for copies of the documents that we used in our investigation.
    Please do not reply to this email. We are unable to respond to inquiries sent to this address. For immediate answers to your questions, visit our Help Center by clicking "Help" located on any PayPal page<br> or email. <br> --- --- <br> PayPal, Inc. is Licensed as a Money Transmitter by the New York State Department of Financial Services. PayPal, Inc., NMLS #910457, License #FT3345,<br> Massachusetts Foreign Transmittal License. PayPal, Inc., Transmit Money By Check, Draft or Money Order By The Department of Banking, Commonwealth of Pennsylvania. PayPal, Inc. Rhode Island<br> Licensed Money Transferor. PAYPAL, INC., NMLS #910457, LICENSE #34967, IS LICENSED BY THE GEORGIA DEPARTMENT OF BANKING AND FINANCE. <br> Copyright © 2018 PayPal, Inc. All rights reserved. PayPal is located at 2211 N. First St., San Jose, CA 95131. <br><br><br> <br><br> <br><br>NA07122

    I was just informed from PayPal that this was a legitimate email from PayPal.   The domain name was different.  They need to correct that.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-09-18T14:35:19+00:00

    According to MS non of my accounts were compromised despite the activity log showing as 'successful sync' after a password change, however they've not supplied any detail beyond that so I am still monitoring more frequently than usual. I've not seen anything of concern after six months from the first notification so I m fairly sure that the problem is a fault in the report but it can't be guaranteed at the moment.

    For me its significant that the only 'successful sync' are before the password change and everything since has been unsuccessful; that lends some credence to MS assertion that nothing was actually compromised - I would expect to see one or two 'unsuccessful' before the password change if the reporting were accurate.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-09-18T14:22:27+00:00

    I have just today discovered the very same problem. The Sync attempts showed as unsuccessful until I changed my password, as which point they changed to show successful. I've changed all my major passwords now, but do you think I should be concerned or does it just seem to be something faulty in what we are being shown?

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-09-18T12:09:00+00:00

    That's similar to what I was seeing and after investigation the back office team said the 'successful' entries were in fact 'unsuccessful' but the reporting page was giving incorrect information. Since they looked at it (and I setup a new password just in case) there have been no 'successful' sync and the previously 'successful' ones appearing in the log now say 'unsuccessful'. Without some detail of what's changed and why the 'compromise' email was triggered I am not 100% convinced that I've not lost data but, so far, I've not appeared on haveIbeenpwned more than the ones that I was already aware of

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments