My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Anonymous
    2019-11-29T20:19:07+00:00

    Hi, most likely nothing has leaked from your account at all. You can test this by yourself to use a simple LDAP client and try accessing your account with your username and password with all security tips followed from all the other posts here and check the activity log. You might see a success, but you can see that no data will flow to the LDAP client at all. I really recommend to reset all your app passwords, which are the weakest part for LDAP sync attempts and you can just reset all of them. Here once more some tips:

    1.) Reset your password to become really strong (use a trusted password manager to generate a really complex password)

    2.) Go to your additional security options and reset all your app passwords and remove all your trusted devices, which will prevent old leaked app passwords from being usable anymore especially from LDAP clients.

    3.) Enable Multi Factor Authentication with Azure Authenticator App on your smartphone or use a Fido2 key.

    4.) Don't use your MSA email address and related password anywhere else, besides for your MSA account.

    5.) Keep all your devices and used apps always up to date

    6.) Enable End Point Protection of your choice on any device (we recommend of course Windows Defender)

    7.) Business IT-Pros please use Azure Sentinel, Azure Security Center and Microsoft Advanced Threat Protection.

    Sorry for all your pains and irritations here in this thread, but please keep your trust in Microsoft Solutions, which already evolved to one of the most trusted, compliant and secured technologies available today globally.

    Take care

    Volker

    P.S.: If you think your email alias is really used for several attacks or leaked many times, you can also just change your alias in MSA to a brand new email address and remove the old alias, without loosing your data or unique ID.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2019-11-27T05:52:50+00:00

    I've also received such emails but don't worry too much about that. Most of us had their old passwords leaked due to websites that you used that password on that had security breaches and got its user/pass list leaked. Those scammers would just fetch your (old) leaked password from the large database of previously hacked accounts and paste it in the email, so that it looks like he cracked it himself. In general just make sure to frequently change your passwords, as even popular websites encounter security issues that may lead to serious breaches.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-10-31T13:15:59+00:00

    Today i found out that my account had a successful IMAP login in China.Although all previous attempts show that they are unsuccessful.If i reload they might appear all as successful.Only the last attack appears successful no matter what.Can someone officialy confirm that this is just a UX problem that still exists?Or give us an update on the issue?

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-10-31T00:09:46+00:00

    Please can you give us an update on this?

    I have the same issue and i'm really concerned. I've had my account since the early days of Hotmail, almost 15 years of emails and I am considering closing my account and moving to Gmail.

    I don't want to do this, though i'm so concerned that there seems to be no way to reverse the issue, can you confirm if there is a way to stop the syncing?

    Please can you tell me if this is reversible, and please can you explain clearly what has happened? As I understand it, my emails are now visible and syncing regularly in countries such as Bangladesh, Brazil, China etc - even though I have changed my password and I have two factor, they are still showing up as 'Successful Sync' - does this mean my emails continue to be synced on devices that aren't mine?

    Please help!

    Was this answer helpful?

    0 comments No comments