My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Anonymous
    2019-03-30T09:40:43+00:00

    Hello everyone, 

    So glad i have found this thread, this is a massive security issue with Microsoft Outlook.com. My Outlook was also hacked more than once in similar circumstances over the past one month or so. 

    In this hack the hacker seems to have gained access to all my emails, created a rule to hide password reset email of another website, and succesfully reset the password on that website since he gained access to my emails. The hacker might have done this across multiple websites. The rule created by the hacker auto-deleted the website reset emails so i only discovered them much later. 

    I have done the following:

    1. Changed password
    2. 2 factor authnetication
    3. deleted ALL linked devices
    4. Deleted ALL linked mobile devices
    5. Changed app passwords and recovery passwords

    My computers are 100% clean and i never clicked on any phishing.

    Yet one week later (Today) the hacker once again appears to have gained access to my email again despite 2 factor authnetication and all the steps that i took above!! My activty logs show IMAP and SMTP attemps from all over the world Brazil, India, Iran, etc along with some Unknown Ipv6 addresses. Hackers are still able to get through this is very serious!

    I received ZERO warning from Microsoft about this, nothing on my two factor either.

    I contacted Microsoft the very first time i identified the issue but they kept responding with generic responses, completely ignoring what i am telling them, they completey failed to protect my account depsite reporting it to them and i got hacked again (or maybe the hackers never lost access and continue to have access to my email due to this exploit) 

    Folks, there is a VERY SERIOUS securtiy situation here and a Massive security failure by Microsoft. There is a massive security breach/exploit that Microsoft is complete ignoring and hackers have gained access to our entire emails of all our life and put us at huge risk of identity theft, financial theft and various other crimes, etc. Clearly there is some form of exploit (most likey in relation to IMAP) that hackers have discovered, Microsoft has completed ignored this as i can see complaints since 2016 and earlier with similar issue but it looks like it has spread in 2018-2019. 

    Has anyone found any solution to this ? Currently even if you take ALL the security steps i mentioned above including 2 factor the hackers are still able to bypass this. I am extremely concerned in regards to my emails, my personal online security and identity theft. Microsoft has not provided me with any solution or satisfactory answer when i contact them, they continue ignoring the seriouness of this issue and they keep closing the ticket even though it's not resolved!

    Hope we can figure this out together or we hear from Microsoft

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-03-12T00:30:04+00:00

    More bad news about this problem and the lack of a satisfactory action or answer on Microsoft part...

    I am now being attacked by phishing on a daily basis and then the same ip doing the phishing is trying to sync.

    The phishing button does nothing to stop this...

    One can think that if you report a phishing attempt at least if the same ip sends a mail again or tries to sync to the account some form of alert should be given or the ip responsible for the attack should be banned.

    Instead it just says to ignore it and move on next to the failed sync attempt.

    i am literally under attack here.

    This could be easily fixed if we where able of disabling syncing altogether or have an option to prevent syncing from other countries . I dont need sync at all.

    I see mi mails on my desktop and if i do see them elsewhere it will most likely be on the god damned country i **** live in. 

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-03-10T14:45:24+00:00

    I have had the same scenario in the last couple of days, Is anyone able to tell me what information is available from a successful sync? I have had the same account for 10+ years and it contains lots of important and personal documents, have all these now been downloaded to someones computer?

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-03-05T17:30:08+00:00

    when you changed your password a fault in the report page changes 'unsuccessful' to 'successful' but it's unlikely anyone actually  got access especially if you have 2 factor auth enabled. If Belastingdienst are saying you authorised someone then ask them for the paper trail, they are subject to GDPR and have to give you the information.

    Was this answer helpful?

    0 comments No comments