Managing personal Outlook.com account settings, security, and privacy
I think they're probably just too lazy to fix it
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I've had a huge increase of people trying to sign in to my email account the past few days. As in multiple attempts every hour, every day, from all of the world. I've had to change my password daily and I'm worried about my email getting hacked. Is there any extra security or anything else I can do other than the two factor authentication that can protect my email from being hacked. It's insane the amount of login attempts that are happening lately. Multiple attempts at the same time in different ends of the world. I've never had this happen before. Will it decrease eventually?
Managing personal Outlook.com account settings, security, and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
I think they're probably just too lazy to fix it
Well, if your info has been sold on the dark web, that is one way in. New aliases found so quickly may be from a malicious screen share malware file. I have had two removed in three weeks by the Geek Squad.
It seems to me that if you choose the no-password route with a 2 Factor Authentication, it becomes way more intrusive for the user than having a password and 2 Factor Authentication, because you're constantly being made aware that there are login attempts.
I appreciate that given the latter method there is a slight element of "ignorance is bliss", but I'd rathe have that than constantly being asked to authenticate (which in itself carries a further risk).
However irritating it might be it's worth choosing an alias (or trying an alias) that is fairly complex - as long as you can remember it.
I don't know how on earth they (the hackers) would get hold of the new alias as long as it's not posted or used to log into anywhere, unless MS servers are being hacked or your computer isn't clean.
(Important: You must disable the "hack-attempted" email address from being used to log in.)
Please have a look at the article, it has full instructions on how to set this all up:
I dont have a password, I use the authenticator password less option