My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Anonymous
    2019-10-15T20:05:07+00:00

    Creating the 2-factor auth doesn't work, that is something Microsoft created to make people think their information is safe. Your account is not being hacked from all those countries. The individual who is doing it is using a program to change its IP address. It could even be your neighbor and he can change his location somewhere in Europe. 

    Yes, I agree, 2-factor authentication is weak.  I also understand VPN's are used to spoof locations; I use one myself when torrenting.  VPN services own blocks of IP's and are known to anyone willing to look.  The IP addresses used by VPN services can be blocked if that were an option offered through Microsoft email account settings.  I feel your frustration...but, I don't think Microsoft should be doing nothing because the problem is so big or because there are ways to get around IP's being blocked from countries other than the users.  Something (anything) is better than doing nothing at all, and the more obstacles MS can place in the way of would-be hackers; the better.  I would venture to say that half of them are unskilled with limited hacking abilities.  Preventing even 10% of them is worth doing IMHO.  There's got to be a way we users can lock down email access more than Microsoft is currently doing and I hope for all our sake; they are reading this and taking notes.  As a Hotmail user since 1998, I'm seriously considering Gmail as a viable replacement and with that, I'd be dropping my Office 365 for Google Docs.  I don't think I'm alone in this either.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-10-15T19:43:58+00:00

    i changed my outlook server ,reset my computer , and went into safe mode mode and found a bug by running Webfoot it was not found running in normal windows but it had access to all my passwords , so i went i had to to reset all my passwords from start and i added other firewall just for outlook ,so everything that goes in gets scanned  and a password is needed to get passed the firewall . after all this trouble i have not had any more problems but Microsoft needs to fix the problem it is causing to much information to be leaked to cyber hackers and hackers  

    I assume you meant Webroot AntiVirus, and not Webfoot?  What was this bug you found exactly?

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-10-15T11:55:11+00:00

    i changed my outlook server ,reset my computer , and went into safe mode mode and found a bug by running Webfoot it was not found running in normal windows but it had access to all my passwords , so i went i had to to reset all my passwords from start and i added other firewall just for outlook ,so everything that goes in gets scanned  and a password is needed to get passed the firewall . after all this trouble i have not had any more problems but Microsoft needs to fix the problem it is causing to much information to be leaked to cyber hackers and hackers

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-10-15T03:39:37+00:00

    Either way its still getting hacked, how do i stop this?

    Was this answer helpful?

    0 comments No comments