My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Newest
  1. Anonymous
    2018-08-07T18:03:21+00:00

    My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

    Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

    Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

    I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

    How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

    I have sent you a private message requesting more information.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-08-07T16:23:25+00:00

    It gets worse! Here's the Recent Activity showing the four attempts as being "unsuccessful":

    BUT... if I click on "Secure your account", the exact same events suddenly change to "successful"

    This is actually a little bit encouraging, it implies that what's at fault is the reporting on the activity page in that it's incorrectly reversing the 'unsuccessful' flag as part of the 'Secure your account' process but this is a very slim hope to base our security on and until MS deign to reply I'm going to assume the account is compromised.

    "If ALL my account activity is from, say, Sydney, then someone tries to login / automatically sync from Brazil, why wouldn't they automatically flag that as suspicious, and block it?"

    Absolutely!

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-08-07T16:17:54+00:00

    This also happened to me, with a 14 character strong password. Like others, I wasn't informed until 10+ days after the first successful sync. I spoke to someone at Microsoft via their support chat and much like has been said above, they tried to place the blame on a VPN. It was a frustrating conversation because while they implied I was safe, I wanted a guarantee that my data hadn't been accessed or stolen and it wasn't forthcoming.

    In a case like this, activity from another country should be instantly blocked until the user's identity can be verified. That the access happened over IMAP suggests to me a long standing vulnerability that Microsoft is trying to cover up.

    So what's going on Microsoft?

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-08-07T13:15:19+00:00

    I also had the same issue:

    1. Successful syncs from several countries where i have never been at;
    2. Only received an e-mail warning, around 10 days after those successful syncs occurred.

    I don't use any VPN.

    Already applied a few countermeasures (applied two factor authentication, changed password, applied a new primary alias and deactivated sign-in with previous primary alias) but seems to me my e-mails already are compromised.

    The information on those e-mail's aren't critical but still frustrating.

    If i live in a certain country, any attempts to sign-in on other countries, should be suspicious enough, to demand more from a user who wants to sync. Plus, message warning should be sent immediately.

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments