My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Anonymous
    2019-09-26T00:21:02+00:00

    Cheers DingDong, Yes indeed he is using a vpn he purchased it with my paypal account (from the details he gleemed from my emails, that Microsoft kindly updated him with post password change), but his greed got the better of him when he ordered new trainers and other clothing from sports direct Latvia to his home address, he's also short and a size 36 if only knowing could do something to help. Fingers crossed for more false positives for future posters. :)

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-09-25T23:55:51+00:00

    I got this notification as well. With the new Android update that went out, I enabled the Google VPN service, I also use the Outlook app. Turns out they route through some of the places that were flagged such as Indonesia, Uruguay, Russia, Brazil, etc.. 

    If you recently updated your mobile OS and enabled the VPN services, these security features might be sending false positives.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-09-25T22:30:35+00:00

    How is that helpful at all. I was notified yesterday of an attempt on my account, so I swiftly changed my password made sure both text and authenticator was still enabled. All attempts (half dozen from china starting 12 hrs before the notification) showed as unsuccessful, went to bed feeling safe. Today they have been successful, accessed and changed my paypal credentials and have been on a $400 spending spree. And yes all those failed attempts I clicked on in a hope a block syncing turn or off syncing option are now showing as successful attempts. I say to you that this is microsoft's way of making it appear that they got it right and made me aware I had been compromised. 

    If this situation was with a credit card hack not an email account hack a bank would block ALL use of that card until identification could be ascertained. Yet Microsoft cannot put similar technology in place for its users, with real, realtime protection. Every site app and online store I know would endeavour to protect its customers by blocking activity until the threat was over, allowing the closure or freezing of the account. Have you tried that with Microsoft emails, I have and it doesn't close it simply goes dormant until accessed again.

    Something needs to be changed and to reiterate the support article link, to very poor security measures advice and options, is a hollow and nonsensical response Microsoft have you using. Im sure every poster of these 14 pages can agree on that much. As for me I will be leaving Microsoft for my email activity and highly untrusting of them with my personal information in future.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-09-24T15:12:42+00:00

    Hello All again,

    this time with my correct Microsoft Credentials. First of all please follow these best practices, to secure your accounts as best as possible. 

    https://support.microsoft.com/en-us/help/12410/microsoft-account-how-to-help-keep-your-account-safe-and-secure

    Afterwards please check your activity logs, which should state "Unsuccessful logins".

    Cheers

    Volker

    Was this answer helpful?

    0 comments No comments