Managing personal Outlook.com account settings, security, and privacy
Please see if this page helps:
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I've had a huge increase of people trying to sign in to my email account the past few days. As in multiple attempts every hour, every day, from all of the world. I've had to change my password daily and I'm worried about my email getting hacked. Is there any extra security or anything else I can do other than the two factor authentication that can protect my email from being hacked. It's insane the amount of login attempts that are happening lately. Multiple attempts at the same time in different ends of the world. I've never had this happen before. Will it decrease eventually?
Managing personal Outlook.com account settings, security, and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Please see if this page helps:
This is still an ongoing issue, my friend and i recently (i mean last 4 days) had this happen with almost the exact same locations. I know in azure theres a way to block ip address or limit sign ins to specific geo locations or ip addresses. Is this not something we can do as a standard user?
Every hour now according to the Authenticator. No code requests since I moved to that. Annoying and yeah Microsoft should give the option to report and log ip addresses. Brazil Russia Ukraine Bolivia amongst many others.
The attempts on my account are even more frequent than hourly!
I really don't like being targeted.
China China China bots (usually 5 times all with different IPs) Brazil, Russia, Bolivia etc. etc. And it never stops.
If Microsoft see this level of activity surely they must know it has to be malicious and they should find some way to prevent it.
The issue with geofencing is that as the perps use VPNs, eventually they will hit a location that isn't geofenced. Thus the interaction they see when attempting a login would have to be the same whether or not it was geofenced (or they might eventually, given enough attempts, find your IP.
Just a thought (I'm sure it won't be practical) - give the user an option of there being no way to either enter a password or authenticate or log-in unless the user enters the first 6 digits of their IP (be it static or dynamic or a vpn) followed by a user chosen (long) phrase?
I'd be prepared to trade that inconvenience against the perpetual worry of bad actors getting access.
I'm getting the same thing, around 20 or more attempts per day from all over the world. This has been going on for around 6 months now. (I have changed my password multiple times and done the double verification) - they've not managed to get in but am wondering whether I should do the alias thing now.
Worryingly, today, without thinking, I made a schoolboy error, I opened an email in my Inbox from 'Marks and Spencer' which obviously was not from them but had crept into my inbox; I was half asleep and had opened it as I had unsubscribed from them and was annoyed they had sent me an email (Duh!?!).
In my defence it should have gone into the junk folder, and am concerned that Microsoft didn't pick it up and it slipped through, now I'm wondering, did they obtain any information and if doing the alias email is enough.
Sigh!!