Anyone with an old outlook.com account – including Hotmail, Live, or MSN addresses – is highly likely to have the address “out in the wild”, either due to a data breech or posted to a public forum or website.
You can google for your address to see if it was posted on any public facing websites.
You can check to see if addresses were in data breeches at https://haveibeenpwned.com/. Note: it is safe to enter your address on this site, the site’s owners are Microsoft MVPs and are trusted by Microsoft.
If the hackers have your address, especially with a password from a data breech, they will try to log into your account. This has the potential to create problems, even if they can't get in, because Microsoft may make you change your password frequently.
Enabling 2-step verification will help to protect your account, as long as you don't accidently approve access on your app. Or you may be annoyed by the number of notifications you receive that are not you.
If you have a lot of sign in attempts in the activity list at https://account.live.com/Activity you can block the attempts by changing the primary alias, then disabling sign in permissions on the address that was the primary alias.
When you sign into your account, you will need to use the new primary alias (or another alias on the account). Do not use the address on other websites. Use it only to sign into your account.
If you have existing aliases on the account and have not used them to set up accounts on other websites, you can use one of those as the new primary. The goal is to use addresses hackers don’t know about.
I recommend having at least two addresses you can use to log in with – just in case you forget one. (I speak from experience!)