My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Newest
  1. Anonymous
    2020-05-16T19:40:12+00:00

    Microsoft ask me how i like the response i don't like it . None of it everyone is getting hacked in outlook but gmail okay ,AOL okay ,Yahoo they had breach in 2018 but AOL and Yahoo is basically the same mail . and behind the curtain gmail had data breach but what up with Microsoft it over and over . it comes down to SSL  servers  and Facebook and one other Google if each one of would stop steeling information like emails ,passwords , identity ,names ,  family names , members , it comes down to Dun & Bradstreet  where you can sell data . buy your credit report , hire them to monitor , do background check , do lot things . i bought mine . Bill Gates this hacking you allowing is not right  just because you have billions along with your friends at Google and Dun & Bradstreet  don't give you right to keep steeling our information and sharing it i think they get enough as it is . stick what you you don't no playing with medicine bottles all day trying to figure out how a virus works since you can't fix the ones on your computer system but can snoop

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2020-05-15T05:31:21+00:00

    in 2020 and I had the same problem my email was hacked using auto sync and all of my videogames releated accounts were stolen.

    the hacker got access to my messages and he sent a "forgot my password" for my steam account and when he recieved the email from steam to change the password he changed it and deleted the message to avoid leting me know that I got hacked.

    thank god I managed to get back all of my accounts and after that I secured my email with 2FA but I still have unsuccessfull syncing attempts.

    thank you microsoft

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2020-05-11T15:03:14+00:00

    Hi, all very well but my problem started in 2017, and still have discrepencies to this day, i still have a hyper link on my account, my headers change??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2020-05-11T11:59:04+00:00

    DailyMotion has allegedly been hacked and tens of millions of users information have been stolen.

    Breach notification service LeakedSource announced the data breach on Monday after the company obtained 85.2 Million records from Dailymotion.

    According to LeakedSource, the DailyMotion data breach appears to have taken place on October 20, 2016, which means it is possible that hackers have been circulating the data for over a month.

    The stolen data consists of 85.2 Million unique email addresses and usernames and around 20 percent of the accounts (more than 18 Million users) had hashed passwords tied to them.

    The passwords were protected using the Bcrypt hashing algorithm with ten rounds of rekeying, making it difficult for hackers to obtain user's actual password.

    Bcrypt is a cryptographic algorithm that makes the hashing process so slow that it would literally take centuries to actual brute-force password of a user.      , On the other data breach , In October 2019, security researchers Vinny Troia and Bob Diachenko identified an unprotected Elasticsearch server holding 1.2 billion records of personal data.   Equifax   https://www.hackerone.com/   

    ZDNet received a sample of the stolen data and confirmed that the data came from the Dailymotion website, but representatives for Vivendi, the majority owner of Dailymotion did not yet respond to any comments. i looked on this ,and and you have to ask Dunn&BradStreet , Facebook owns it ,,   https://hackerone.com/equifax

    Was this answer helpful?

    0 comments No comments