I have been experiencing the same recurring issue as the OP described above.
On June 11, 2020, I received an email to reset my Microsoft account's password. I've never made any such request, nor was I anywhere near internet access that day, so it immediately caught my attention the next day. Unlike most confirmation/verification
emails I've seen, this one from Microsoft did not offer solutions in case the request was erroneous or, even worse, malicious. The only option listed by Microsoft was unlinking the email account. This was of absolutely no use to me, because while the pw
reset request was fraudulent, the email address is completely valid. So, against my better judgement, I merely made a mental note and considered the issue closed.
On June 15th, I found another password reset code in my email inbox. This time I went seeking tech support and stumbled across this community thread. Unfortunately, I found no real solutions here, but I did learn about the ability to monitor recent login
attempts. On the account security webpage, I saw the multitude of access attempts supposedly originating from IP addresses in China, Taiwan, Moldova, Russia, Italy, Thailand, Vietnam, Argenina, and the USA. Next to each entry, I also saw noticed a message
prompting me to click 'Secure your account', if I failed to recognize that account activity. On clicking the hyperlink, I recived a pop-up notification thanking me for informing MS and assuring me there's no need to be concerned. So, I proceeded to click
this link on each unathorized login attempt. With no other solution at-hand, once again I called a it day and hoped for the best.
Unfortunately, I just found two password reset codes, waiting in my inbox today. It is both astonishing and unacceptable that Microsoft doesn't seem to have any real solutions available for this situation. It's becoming more than inconvenience and I'm
very disappointed.