How can I stop all the unauthorized login attempts from around the world?

Anonymous
2024-07-02T04:20:16+00:00

I've had a huge increase of people trying to sign in to my email account the past few days. As in multiple attempts every hour, every day, from all of the world. I've had to change my password daily and I'm worried about my email getting hacked. Is there any extra security or anything else I can do other than the two factor authentication that can protect my email from being hacked. It's insane the amount of login attempts that are happening lately. Multiple attempts at the same time in different ends of the world. I've never had this happen before. Will it decrease eventually?

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

111 answers

Sort by: Most helpful
  1. Anonymous
    2025-03-25T03:15:31+00:00

    KEVIN

    YOU MUST CHANGE YOUR PASSWORD IMMEDIATELY!

    If you're getting authenticator messages they must have your password!

    Also use the alias method to change your email to a different one and set it so the old (current) email can't be used to log in. Your current email will still work when you've done that, just not to log in.

    It's explained in this thread...

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Hal Hostetler MVP-Outlook 12,011 Reputation points MVP Volunteer Moderator
    2025-03-24T01:16:05+00:00

    Anyone with an old outlook.com account – including Hotmail, Live, or MSN addresses – is highly likely to have the address “out in the wild”, either due to a data breech or posted to a public forum or website.

    You can google for your address to see if it was posted on any public facing websites.

    You can check to see if addresses were in data breeches at https://haveibeenpwned.com/. Note: it is safe to enter your address on this site, the site’s owners are Microsoft MVPs and are trusted by Microsoft.

    If the hackers have your address, especially with a password from a data breech, they will try to log into your account. This has the potential to create problems, even if they can't get in, because Microsoft may make you change your password frequently.

    Enabling 2-step verification will help to protect your account, as long as you don't accidently approve access on your app. Or you may be annoyed by the number of notifications you receive that are not you.

    If you have a lot of sign in attempts in the activity list at https://account.live.com/Activity you can block the attempts by changing the primary alias, then disabling sign in permissions on the address that was the primary alias.

    When you sign into your account, you will need to use the new primary alias (or another alias on the account). Do not use the address on other websites. Use it only to sign into your account.

    If you have existing aliases on the account and have not used them to set up accounts on other websites, you can use one of those as the new primary. The goal is to use addresses hackers don’t know about.

    I recommend having at least two addresses you can use to log in with – just in case you forget one. (I speak from experience!)

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2025-03-03T18:58:00+00:00

    Locking the account by MS could only be a very last resort and only for accounts which don't have MFA (multi factor authentication), it would be extremely inconvenient and a bad decision if they were to lock the accounts which have MFA, in fact I would go as far as to say it would be disastrous.

    For those without MFA it would also be extremely inconvenient.

    They need to do what I suggested above, and not do something which would inconvenience hundreds of thousands of customers.

    Having some sort of second level of authentication (preferably authenticator) should be mandatory, without it you're at the mercy of the hackers.

    The alias hack is just a stickng plaster on a gaping wound, it might stop the attempts (until they find the alias) but the real fix has to be amputation of the limb (the limb being the hackers).

    Microsoft, you can fix this or make it lot better (hopefully without inconveniencing customers).

    A security setting for geo-restriction would be good first step.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2025-03-02T20:49:10+00:00

    yes I am baffled!

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2025-03-02T19:27:53+00:00

    He's just said he hasn't used it for anything

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments