My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Anonymous
    2019-06-28T09:18:04+00:00

    Ok, so this morning I got all the messages and emails from Microsoft telling me someone may have access to my account (password was unique to outlook, 2fa enabled). First thing I do is change my password to then go and check my sign-in activity. 44(!) successful syncs over the past 30 days to countries all over the world!?!?! And I only get a message now that my account MAY be compromised. I'm a bit freaked out right now because I don't know what they can do with my e-mail history. Do I need to go change every single password for every account I've ever created? Do I need to replace my SIM-card since they somehow got past the 2fa without me ever noticing? Do I clean install all my devices since they somehow got my password?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-06-26T16:10:03+00:00

    I would also like to note that I just tried syncing my account via IMAP with an incorrect password and the correct password. Even though using the correct password showed 'successful sync' on the security page, the IMAP client still gave the same error it did when I used the wrong password - it refused to sync. I believe 2 factor authentication does cause these syncs to be rejected even if the password was correct, meaning - for what it's worth - an attacker would never realize they had the right password or actually be able to sync anything. Could be wrong - don't have a ton of knowledge on this aspect - but did try it via Python's IMAPClient and on my iPhone and both refused to sync & returned the same errors.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-06-22T04:10:57+00:00

    So what happened?

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-06-22T03:26:56+00:00

    Never posted here in almost 15 years using this email, but this thing happened to me and it's infuriating, after taking so much care online having this happen feels like it was all for nothing. I really, really don't want to lose this address. I have swapped passwords, enabled 2FA (I know it's kinda worthless in this situation but still) and deleted all trusted devices (massive inconvienience to have to set again).

    I've read through this thread and I share your frustration. Here's hoping my tiny post adds up to the mountain of demands for answers from MS.

    Was this answer helpful?

    0 comments No comments