My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Anonymous
    2019-10-29T00:09:41+00:00

    Dear Tech community,

    as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

    Cheers

    Volker

    P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

    https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

    All other email providers have the same challenge to help their customers to secure their username/password authentications. 

    This is so strange and  infuriating!   I have had multi-factor authentication turned on for my account for quite some time. Yet I received the same notice and same experience in the recent activity page.   Has Microsoft figured this out yet? 

    Cheers, 

    Jimmy

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-10-26T05:03:59+00:00

    I have the same problem as others and have too lost a bit of money because they saw an old shopping account and made some purchases on it. That account had the same password as the outlook account (my mistake i know). But how they got the original outlook password is beyond me and my own plan is to delete the whole account now after going through all my emails and deleting them.  This whole thing worries me because i have other microsoft accounts with way more serious things in them.  This is terrible and i am sorry especially for those that have the serious problems metioned above.

    Its obvious to me now that a comment earlier from "XP" about it just being a bug with the sync saying success falsely etc, and others implying no one has been compromised etc, appears very false. Today i have what i would consider near perfect proof that all my emails were and maybe still are being viewed.  I am surprised very surprised by all this. I do wonder why this hasn't gotten into the mainstream voices. I will be cleaning out any of my other one drives that's for sure.

    Hello CB103+5,

    Thank you for your response.

    Microsoft staff have now confirmed and issued a public statement that this is indeed a UX bug, and no one accounts' was compromised because of this.

    You can check whether your personal data was compromised online with this website: https://haveibeenpwned.com/

    Your digital identity could have been compromised by various 3rd party service providers in the past few years, and hackers have accumulated as much compromised data as possible about you to build up an identity of you.

    If that was the case, please change your Microsoft account password and all accounts on other websites you use to prevent identity theft and fraud transactions.

    I hope my answer is helpful to you.

    Regards,

    XP

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-10-26T04:22:15+00:00

    Is there an update about this fix? I need to know if my account was compromised. I'm also not sure why it took 2 weeks to notify me that someone had hacked my account. I have multi-factor authentication and didn't get anything to my phone or other linked email account. Only an email to my outlook account with suspicious activity. Once I go in to view the activity, I see it's a successful automatic sync from Serbia. When I expand it, I see 5 different successful syncs from other countries (Serbia/Russia/Brazil/etc.) dating back to 10/11/19. Why did it take 2 weeks to notify me that my account was compromised and why was my multi-factor authentication not alerted?

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-10-25T02:47:08+00:00

    Dear Tech community,

    as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

    Cheers

    Volker

    P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

    https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

    All other email providers have the same challenge to help their customers to secure their username/password authentications. 

    Has this bug been fixed yet?  I recently got an email about suspicious activity and checked my account to see multiple successful syncs from random countries.  Really concerned about information being stolen.

    Was this answer helpful?

    0 comments No comments