My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Anonymous
    2018-09-17T22:02:57+00:00

    This will sound like typical MS fake-out but:...

    As a result of this thread I've exchanged a few emails with the outlook back office support team, they think, and are trying to prove, that the automated IMAP Sync which are appearing in the log as 'Successful' is a fault in the reporting page which changes the status to Successful after account details have been changed (I'm going to test this at next password change) , they've checked all the ones I supplied and assured me that non of them actually led to information leaving my account. They haven't yet said why the notifications come when they do but the timing would indicate that they are not connected to the IMAP sync. It's still not satisfactory but I am a little reassured that data has not actually been compromised.

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-08-18T19:22:19+00:00

    Hey wideawakewesley,

    I had same problem recently.  I'd gotten a generic warning from Microsoft that my Hotmail account MAY have been compromised.  On the surface, everything looked OK.  Like you I have a double-digit strong password. I have spybot installed on top of Windows Defender.  Neither spotted anything.

    I spent hours on Chat with numerous Microsoft people.  One showed me how to check recent activity and that's when I spotted an IMAP intrusion with a successful sync. Was told it happened because my account is linked to an app that was compromised.  I purposely link to no apps but was told that my Skype account is linked by default to my Microsoft account.  I rarely use Skype.  Unfortunately, Skype account cannot be delinked.  Also, Skype account cannot be closed without closing the Microsoft account. 

    The chat session folks could offer me no fix other than the standard change the password which I'd already done.  They couldn't even make a report of this hack and told me that I had to make a post on the support and/or community forum.

    To make matters worse, the Windows Defender and Spybot provided no protection because the hack happened outside of my laptop or PC. 

    I agree with you that Microsoft is not being totally transparent about this problem.

    Microsoft needs to address this problem ASAP!!

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-08-06T08:38:13+00:00

    It happened because you had an easy to guess password on your account, you used the same password on a hacked website, or you have malware on one of your systems.

    I would suggest that you turn on multifactor authentication and be sure to have multiple devices setup.

    yeah but no, it's happened on my account in the last month, password was changed 30 days ago (and changes every 72 days), two factor authentication has been on since it was available and the password itself is 14 characters long, with mixed case, special characters, and a random number. Despite this I can see successful sync from Malaysia, Russia, china and Vietnam over a three week period. I've changed my password (obvs) and the last two attempts from China and Sweden are unsuccessful which implies its not an internal sync within the Microsoft network.

    Microsoft support have convinced themselves I am using a VPN but that doesn't explain what the syncs were, why it took 4 weeks to notify me or why two factor auth wasn't triggered for any of them.

    Also the VPN I use is for a corporate machine which wasn't in use when this was happening because I was on leave.

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2019-06-26T16:05:12+00:00

    I believe what all of this stems from, in most of our cases, is our email addresses appearing - at one point or another - in a list of compromised usernames/passwords in hacked database leaks. I figure that multiple attackers are constantly running through these lists looking for accessible accounts.

    Sites like Haveibeenpwned are pretty good at telling you if your e-mail appears in any of the breaches that have been made public.

    Anyways, I think I figured out a fix or work-around for these issues

    Warning : go through these steps carefully. Going about this a different way initially, I was given a prompt that informed me I would permanently lose the ability to receive or send e-mail from the hotmail account I was trying to fix if I clicked Yes. Done right, you should not run into that prompt, and will merely be using the new alias to sign in.. you will no longer be able to sign in with your old email address, but will still be able to send and receive mail from it and use it normally.

    1. First, go to the Your Info link at the top of your Microsoft Account page. Click Manage how you sign in to Microsoft.
    2. Under 'Account aliases', add an e-mail address or phone number. Verify it, and then click Make primary on the new alias.
    3. Under 'Sign-in preferences' on the same page, click Change sign-in preferences.
    4. Remove the check mark next to your old, initial email address and only leave the new primary alias checked. Click Save.

    Just to be safe, for the new alias, I used a gmail account that I know hasn't been compromised in the past, has a strong password, and has 2 factor authentication enabled.

    After doing the aforementioned things, sync and login attempts instantly dropped to zero and have stayed that way. Hope this helps some of you find relief from this frustrating and anxiety-inducing debacle.

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments