My Outlook account got hacked. E-mails leaked by IMAP automatic sync. How this happened?

Anonymous
2017-12-27T07:24:23+00:00

My Outlook account got hacked. Have been using this e-mail  account from the early days of Hotmail. E-mails leaked by IMAP automatic sync despite using different password than on other sites and having two factor authentication activated.

Got warning SMS from Microsoft and when checking recent activity, i saw multiple "Successful Syncs" listed from countries like China, Thailand, Russia, Poland, Brazil, Ukraine, Philippines, Kazakhstan and Iran. These syncs took place in two different times in four hour intervals. How could this be possible? Why Microsoft detected that something fishy is going on but allowed sync to be completed anyway? Doesn't IMAP sync have some kind of location based checks in place like when logging in into other MS sites and services?

Since then, I have changed the password of my account, unlinked Skype from my Microsoft account, deleted any active app passwords.

I see again some IMAP syncs in my activity tab and they are now marked as "Unsuccessful". Small consolation knowing that your whole e-mail history is already leaked into some Chinese servers :(

How this all could have happened? Is there a security hole in Microsoft's IMAP sync implementation?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2019-10-19T13:55:26+00:00

Dear Tech community,

as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

Cheers

Volker

P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

All other email providers have the same challenge to help their customers to secure their username/password authentications.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments

224 additional answers

Sort by: Most helpful
  1. Anonymous
    2020-01-13T07:40:49+00:00

    Dear Tech community,

    as far as we know now, there was an UX issue on the MSA recent activity page, where a subset of unsuccessful IMAP syncs are erroneously shown as successful. This bug should be fixed in a couple of days and we hope that no one was ever compromised.

    Cheers

    Volker

    P.S.: IP addresses are translating to countries like Bangladesh, Brasil, China etc. A hacker can  simply fake their source IP, therefore it is difficult to say, where the hack attacks are coming from. Please just keep using security best practices for your hotmail/outlook accounts with difficult passwords to be changed as often as possible and leverage multi factor authentication.

    https://www.microsoft.com/en-us/microsoft-365/blog/2018/11/20/sign-in-to-your-microsoft-account-without-a-password-using-windows-hello-or-a-security-key/

    All other email providers have the same challenge to help their customers to secure their username/password authentications. 

    This happened recently, 20 or so unsuccessful sync attempts from IP's around the world and one success. Can you tell us whether this is a UX bug or our accounts are being compromised? It seems like a biggy here.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2020-01-07T18:11:42+00:00

    unlike Gmail outlook email is not encrypted  it might say it is but it not . I found this out sending a file from Gmail to outlook and got warning saying outlook is not encrypted they send it back anyone can read this file . Like if i send emails out they get read and if i send one out that look strange and i do it on purpose . You got settings go through each one , add password after you run outlook through malware ,spyware , change your settings , n the MS Outlook File menu (MS Outlook Backstage View) click Options and in the Trust Center tab click Trust Center Settings…. In the resulting window click E-mail Security, then check the Encrypt contents and attachments for outgoing messages option, then your password , at this point they got your new password

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2019-12-17T04:06:42+00:00

    Me too, I have the same problem. It's really scary got the message everytime I check my account activity.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2019-11-30T10:28:07+00:00

    Hey

    I am not very tech savvy and i come seeking advice please. I have had Warning emails saying someone is trying to hack my microsoft account (unusual  activity detected). i have logged in and changed my password to a newer stronger one and looked at all of the unusual attempts to log in which are all from one place but the last attempt they made is showing that they have made a succesfull synct. What does this mean? Does this mean they have all my info and emails?

    Was this answer helpful?

    0 comments No comments