My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Oldest
  1. Anonymous
    2020-05-01T15:28:13+00:00

    My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

    Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

    Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

    I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

    How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

    what about hyper links, i have evidence that emails have been removed and conversations have been changed,i have hard copies from 2 years ago, these emails were changed and removed so the said party could lie in court. i believe that this was done through a hyper link that the party attached to my account, 

    1st email was sent to my email account with a link in the email, i didn't reply but the email was opened.

    2nd email was sent to a recipent cache in my email account.

    3rd email was a reply to the 2nd email sent from a shared address book, my name and the email address in a hyperlink

    i have got hard copies from my emails from my email address, to the party in my recovered deleted box, the same email was in my sent box but from a shared address book, my name with my email address in a hyper link,

    I have the same email x3, all three emails have different headers, different times, different lay out, different font, three different servers i believe.

    the third email wasn't in my email account, i obtained the third email via a subject access request from the said party, they have illegally obtained the email, after the email was obtained by the party they dropped there case, the email that was illegally obtained was to my solicitor about the said party lying in court,

    hyperlinks are legal to place on any ones account by anybody, very concerning, but 3rd parties forwarding my infomation with out my permission is illegal. this can only be done in a shared address book.

    i believe that even if i'd spent 1000s on security on my laptop, this would not have protected me,it's outside my firewall in the web. 

    3 year this has gone on for and still is. 

    i've had over a 1000 pictures of discepences go missing and old phones with evidence on shut down never to work again, you might say this is a coincidence, but in three year there has far to many coincidences, after reading about hyperlink and shared address books we dont have any protection.

    i've just been advised by microsoft to take the party to court.

    they cannot help me in anyway

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2020-05-01T15:44:10+00:00

    Dear Tech community,

    as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

    Cheers

    Volker

    P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

    https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

    All other email providers have the same challenge to help their customers to secure their username/password authentications. 

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2020-05-01T15:59:01+00:00

    stop with the copy pasting already -_- you're not helping here

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2020-05-01T16:09:54+00:00

    how dose that answer that my emails have been illegally obtained????????????????????????????????????

    Was this answer helpful?

    0 comments No comments