My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Newest
  1. Anonymous
    2018-09-17T17:13:31+00:00

    I'd like to contribute to this thread that I recently encountered the same issue.

    I was notified this past weekend of a log-in from a neighboring state, and when I saw similar "Successful Syncs" starting from the end of August, I locked down the account.

    The previous password for my account was as strong alphanumeric password unique to the account and less than 2 years old.

    The account alias was an @hotmail.com account that I've had since the late 90's. There are only four devices I ever access it from. 2 mobile devices, a work pc, and a personal PC. All those devices have relatively strong security, do not install software from untrusted sources, and use browsers with current security updates. I believe the last time I used the account for e-mail was around 2001 when the Hotmail e-mail access was shut down due to "inactivity".

    Also of note was the fact that until a month ago I had never logged into Outlook.com to use the e-mail functionality of my MS account. I don't know if that factors into it, but I do find it noteworthy. Thankfully because of this I had (hopefully) nothing of note that could have been sync'd, although I do not know what there were able to access with the few minutes from a browser-based log-in. There were some XBox Live e-mails, spam, and apparently a Uber account someone had mistakenly signed up for using my e-mail (Uber e-mails were all in Spanish and addressed to someone else's name).

    I don't know how long the sync's have been going on for since apparently we only get 28 days of history, but there doesn't appear to be any browser based log-in attempts outside of the one that triggered the alert e-mail. I don't see any failed log-in attempts in my history for that matter. Since I do not use my account for e-mail nothing should be attempting to sync via IMAP. What's also odd is that the sync attempts were typically 2-5 days apart. The earliest entry shows a successful pop3 sync which I find odd since according to the Outlook.com settings POP3 is disabled.

    None of my other accounts with other services have had any suspicious activity.

    I've since change the password, enabled 2fa, and switched the alias as well as disabled logging in for the previous alias.

    While I understand MS wants us to use their services, I don't understand why we don't have an option to opt out here. It seems the IMAP sync attempts are a common theme in the thread and other posts here and I feel we should at the very least have the option to disable IMAP access to our accounts. It feels like we are having a possible security hole vector forced on us.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-08-18T22:32:25+00:00

    What we need is a whistleblower at Microsoft

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-08-18T19:22:19+00:00

    Hey wideawakewesley,

    I had same problem recently.  I'd gotten a generic warning from Microsoft that my Hotmail account MAY have been compromised.  On the surface, everything looked OK.  Like you I have a double-digit strong password. I have spybot installed on top of Windows Defender.  Neither spotted anything.

    I spent hours on Chat with numerous Microsoft people.  One showed me how to check recent activity and that's when I spotted an IMAP intrusion with a successful sync. Was told it happened because my account is linked to an app that was compromised.  I purposely link to no apps but was told that my Skype account is linked by default to my Microsoft account.  I rarely use Skype.  Unfortunately, Skype account cannot be delinked.  Also, Skype account cannot be closed without closing the Microsoft account. 

    The chat session folks could offer me no fix other than the standard change the password which I'd already done.  They couldn't even make a report of this hack and told me that I had to make a post on the support and/or community forum.

    To make matters worse, the Windows Defender and Spybot provided no protection because the hack happened outside of my laptop or PC. 

    I agree with you that Microsoft is not being totally transparent about this problem.

    Microsoft needs to address this problem ASAP!!

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-08-15T15:15:33+00:00

    This is clearly a massive security hole by Microsoft. Last night I also got the email telling me I needed to change my password as my account has been compromised. I changed password and then checked the logs. My account successfully synced with IMAP from Brazil!!!! Then checking, successfully synced from India 2 days ago with IMAP again. Further back I have a successfully synced from Belarus over a month ago and now Microsoft suddenly a month later think it is a good idea to let me know my account has been compromised and obviously using IMAP that means whoever has been able to use IMAP to connect to my account  has downloaded a copy of my hotmail account that I have had for over 15 years. This is unacceptable that Microsoft doesnt block IMAP connections from random locations around the world.

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments