My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  2. Anonymous
    2019-09-30T02:59:12+00:00

    Just in case this may help someone else. On 09/27/2019 I was informed that my account was hacked for almost a week from different countries. Since then multiple attempts have been made to hack my account again but they have been unsuccessful. These are the steps I took. first changed all of my passwords that had sensitive information like banks, also reset my router and changed the wifi password. Added an antivirus and malware software from two different companies to my computer. I deleted my email from Microsoft Outlook app on my phone and then delete the app, also disable the sync function on my phone. On my phone, the sync helps for "sync your account with the phone to share content with your other devices". Remember that the hacker syncing the information. And lastly, I got a new SIM card and added an antivirus and malware to the phone as well. All of this may seem like a lot, but it is worth it. I hope this information may be helpful for someone else.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-09-28T03:29:42+00:00

    I've just had my credit card hacked, 260 Euros down the drain. I don't really know if this is a coincidence, as I only use Paypal to buy with credit card. (That was not a question by the way).

    I recommend everyone to switch to another email provider immediately, your data and computer are not safe with microsoft. I'm starting to migrate my data soon and won't log into my hotmail account anymore, after around 10 years of daily usage.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-09-27T22:02:03+00:00

    My account has been hacked since 09/22/2019 and just got a notice today  09/27/2019 that they notice something suspicious. Thanks, Microsoft!!! for the notice 7 day later. It says my account has been hacked in Brazil, Colombia Russia, Nigeria, India, Thailand, Indonesia, Zimbabwe, Korea, Cambodia, Poland. I already change my password and will be monitoring this more closely. Exactly what information do they steal from the account, what are they looking for, and what can they do with it. Unfortunately, I did have really sensitive information in my account. Can they use this for identity theft? Does anyone knows someone that has been affected by this?

    Was this answer helpful?

    0 comments No comments