Am I hacked? (received an email from my own emailaddress)

Anonymous
2024-07-03T11:48:35+00:00

Hi,

I received an email presumably send from my own emailaccount, subject 'You've been hacked' starting with

'I want to inform you about a very bad situation for you. However, you can benefit from it, if you will act wisеly. Have you heard of Pegasus? This is a spyware program that installs on computers and smartphones and allows hackers to monitor the activity of device owners. It provides access to your webcam, messengers, emails, call records, etc. It works well on Android, iOS, macOS and Windows. I guess, you already figured out where I’m getting at.'

Etc.

So the content of the email doesn't worry me, but what I can't understand is why the e-mail is send from my account. Or why it looks like it is send from my account. It doesn't show any other address.

When I check Source of the message, the following pops up, but this to me is jibberisch... Can anyone explain to me why it looks like I send this to myself and if I indeed been hacked or not?

Thank you!

Received: from DU2P193MB2049.EURP193.PROD.OUTLOOK.COM (::1) by AM0P193MB0690.EURP193.PROD.OUTLOOK.COM with HTTPS; Tue, 2 Jul 2024 02:16:52 +0000 Received: from DB8P191CA0021.EURP191.PROD.OUTLOOK.COM (2603:10a6:10:130::31) by DU2P193MB2049.EURP193.PROD.OUTLOOK.COM (2603:10a6:10:2fd::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7719.32; Tue, 2 Jul 2024 02:16:51 +0000 Received: from DB1PEPF000509F2.eurprd02.prod.outlook.com (2603:10a6:10:130:cafe::3c) by DB8P191CA0021.outlook.office365.com (2603:10a6:10:130::31) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7719.33 via Frontend Transport; Tue, 2 Jul 2024 02:16:51 +0000 Authentication-Results: spf=fail (sender IP is 156.233.162.9) smtp.mailfrom=hotmail.com; dkim=none (message not signed) header.d=none;dmarc=fail action=none header.from=hotmail.com; Received-SPF: Fail (protection.outlook.com: domain of hotmail.com does not designate 156.233.162.9 as permitted sender) receiver=protection.outlook.com; client-ip=156.233.162.9; helo=me38.com; Received: from me38.com (156.233.162.9) by DB1PEPF000509F2.mail.protection.outlook.com (10.167.242.148) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7741.18 via Frontend Transport; Tue, 2 Jul 2024 02:16:51 +0000 X-IncomingTopHeaderMarker: OriginalChecksum:B7E61057C8BBFB70EF50497922FD678074E0F9A31342B2EC67232B534F644AAC;UpperCasedChecksum:73FB0F26A3EF0B4B3D6161FA408F0E9E4FD4F1ADF156DCD03D089677C4C90F7B;SizeAsReceived:290;Count:7 Message-ID: <___@___.___> From: ___@___.___ To: ___@___.___ Subject: You've been hacked Date: Mon, 1 Jul 2024 19:16:51 -0700 Content-Type: multipart/alternative; boundary="09a361167eba959ebd170be015f0ce2424" X-IncomingHeaderCount: 7 Return-Path: ___@___.___ X-MS-Exchange-Organization-ExpirationStartTime: 02 Jul 2024 02:16:51.7662 (UTC) X-MS-Exchange-Organization-ExpirationStartTimeReason: OriginalSubmit X-MS-Exchange-Organization-ExpirationInterval: 1:00:00:00.0000000 X-MS-Exchange-Organization-ExpirationIntervalReason: OriginalSubmit X-MS-Exchange-Organization-Network-Message-Id: aea22e83-f6b2-44ad-16bc-08dc9a3d0931 X-EOPAttributedMessage: 0 X-EOPTenantAttributedMessage: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa:0 X-MS-Exchange-Organization-MessageDirectionality: Incoming X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: DB1PEPF000509F2:EE_|DU2P193MB2049:EE_|AM0P193MB0690:EE_ X-MS-Exchange-Organization-AuthSource: DB1PEPF000509F2.eurprd02.prod.outlook.com X-MS-Exchange-Organization-AuthAs: Anonymous X-MS-UserLastLogonTime: 7/1/2024 2:19:15 PM X-MS-Office365-Filtering-Correlation-Id: aea22e83-f6b2-44ad-16bc-08dc9a3d0931 X-MS-Exchange-EOPDirect: true X-Sender-IP: 156.233.162.9 X-SID-PRA: ___@___.___ X-SID-Result: FAIL X-MS-Exchange-Organization-PCL: 2 X-MS-Exchange-Organization-SCL: 5 X-Microsoft-Antispam: BCL:0;ARA:1444111002|58200799015|461199028|47200799018|9800799012|1360799030|1290799027|1370799030|440099028|3412199025|7310799015|7112599012|2980499032|7110799015; X-MS-Exchange-CrossTenant-OriginalArrivalTime: 02 Jul 2024 02:16:51.5787 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: aea22e83-f6b2-44ad-16bc-08dc9a3d0931 X-MS-Exchange-CrossTenant-Id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa X-MS-Exchange-CrossTenant-AuthSource: DB1PEPF000509F2.eurprd02.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: Internet X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000 X-MS-Exchange-Transport-CrossTenantHeadersStamped: DU2P193MB2049 X-MS-Exchange-Transport-EndToEndLatency: 00:00:01.2088581 X-MS-Exchange-Processed-By-BccFoldering: 15.20.7719.007 X-Microsoft-Antispam-Mailbox-Delivery: ucf:0;jmr:0;ex:1;psp:1;auth:0;dest:J;OFR:SpamFilterAuthJ;ENG:(5062000308)(920221119095)(90000117)(920221120095)(90011020)(91015020)(90015022)(91040095)(9050020)(9080021)(9100341)(1018006)(944500132)(2008001181)(4810010)(4910033)(10005027)(9620004)(9525003)(10150021)(9320005)(9245025)(120001);RF:JunkEmail; X-Message-Delivery: Vj0xLjE7dXM9MDtsPTA7YT0wO0Q9MjtHRD0yO1NDTD02 X-Microsoft-Antispam-Message-Info: =?utf-8?B?MnhlL3FHT29EOFkyNUJLNlpiWXltWktPU1lBU3hZdHp5TEdQU1ozRFZnTTNJ?= =?utf-8?B?N09NK1lKOVhlZHFGUXlHWnIzS0tzM0FpdllCOUY4WTE2THQvUzhvWVVIL1hp?= =?utf-8?B?TUVva2ZxV0VBN0NrY2hCTWhxYisyZEZPaFVrUkRjSjNGWi95NVExVU5QYVpt?= =?utf-8?B?aVZQK0IvNStIcnlMTmtSdWxIekovcXRCRmhzZmdBdVdzM0hJUUx1bUpQekJu?= =?utf-8?B?NjFmWi95eWZFVmxydy9PMDd2TDBRTlJDcW4wUUtsdVFWT0d4SzBMNjJ2QU9I?= =?utf-8?B?cHloZVU0K09aaWZyZjVReW91bS9HNHpON1h3WThPN1B6ejM3aXZBR1h5aEtT?= =?utf-8?B?TERMTU1mMHFMVTkyN2RmNmYyS3RyR3BTVTlvRTY2M3ozSXBaTHJ5S1h6eG5q?= =?utf-8?B?dEpYREJKeC90R09la1JVMzZELzhPakZEemNYUlJsVmY1YkV0M0RHSWxhTWFI?= =?utf-8?B?QXlBS3cwc3ZkS3hOUFpNR3c1Z1FiSkNRYW9FQjVlRGhscm1idjZ0NHJBenZo?= =?utf-8?B?L0JrVGh6U1cweGhtaWo3NkwwR3B2c2QwaC9aQ2NXajVENTF1Y3FhZTlhMEU4?= =?utf-8?B?YVhDdEN3QSt0aUhtcXliT1JFUnlPR3JLaUZ6VXJKWXJ6QitxNTU0bHVtbkV5?= =?utf-8?B?T040QXNmbVRac2NtbUx3WVBHaTJYZzFQc0w2ZS9FeThha0JhVUs1dHl3L08w?= =?utf-8?B?RUszRWNaVWJsYkc5bzJtcDVTMm81WkF0OHVzTCtqZktqQ0MzOTVlWW5uaEww?= =?utf-8?B?bEFuOUVvV2R2ODhEZVY0Q0pwR0U2Vk1pZG1mVk5UVUU5V21NK1pLNElTSE5B?= =?utf-8?B?V2cwdlQ4TUFDS1gwdVNRUEVWT3EwSkZFSDRQM1FOemZYS0d0M3JVbXgydXpj?= =?utf-8?B?SW9sbHBNYnQxd3Z2VVFjKzRlT2E0NmxXbjdSaHBxa09jd2dLVEJ0V0lnTWd3?= =?utf-8?B?YWVtd3MvZ0dlMFJpUnJZQ0dMOW1ncjdpejR2V0ZKWkkwUWVCYW1LRjNOdXhI?= =?utf-8?B?UXZVRFlOL3FaUXB6eHN4OUNrZGY3ZmtsMTdNendUT2FlWGg0U0JQaHpPczRU?= =?utf-8?B?RC9SdTVlWFFEcTFaYmpNQUNpWmU4Z0pNMnp3ODZMYVVTWG1YMmpVWkY4bStC?= =?utf-8?B?UjFhYVkrU29aR3NxbGhRVm1rSVRsN2dNUHh6Rmk1VGlqVlB1bFZLcGszL1Zh?= =?utf-8?B?WUhaMVcrYnh1eHJ3QWtoVFNxZ1Z6UDl2NCs3QW5xaUEyN3Y3MW02czRWS3Yr?= =?utf-8?B?dUh3c1lsaGp3TkQxUE9JMzRmbzdacGc5aUM1QS9OVkU1NS9hWWdBQi80NHRl?= =?utf-8?B?a1B3YjM5SEEvRmgrMmdIQ0J6aW44b3l1OFdWOVhSMlBJUitkeW5jOWloSzJY?= =?utf-8?B?QmdMRFNzTTFTZWhMZnY4ZjY4VDhEZExKWVk3Qm05ZUJsbUVPbm0rbEV2ZDlu?= =?utf-8?B?RWkzQzZsK2pTOUc3ZDAyZnhxc0UvUEt1cEJpVHRSMGNwVDNzcUE3akt6QmNu?= =?utf-8?B?N0tXUnA0UzFOWnA4N003TjFlR0UyYXlQUERlNEV0TzBPdm9QU2dVVEtMM3NN?= =?utf-8?B?Y3VhS3JSanVRMFRXeW5nbnlGNVZnSmd2T29HUy90YVovemJ3SGU2d2RlMUtV?= =?utf-8?B?U0NJZUcrZjc4dVZBb1pSZkRPZlh3RlZPRkJLdVFZUW1xS3RqK1ZpeUFLbWFF?= =?utf-8?B?MFcyK1dPaG02U2FnRjVqQjFId25rbGZRTVlYTUpCMVg5MXNmWG82cmtvcEdI?= =?utf-8?B?dXM3K1hTbnQxbVVXeElUSFNzWlpFSEZ4MVBwd0pGbmR5c3BXZmpwV0xZRWh2?= =?utf-8?B?a3lESndUTC9iYkVRWlZqMGc3U2FBVk94NXVuZlc0eVYrU1RxbnF0ZEhDTkZw?= =?utf-8?B?RjUvZkJVNmZpRXY5SkJ3S2ZJUGJud1VWOHNKWmhQNEU4RUp1VW1nLzE3bGVX?= =?utf-8?B?N084YituemZDTk5xSHpBb050Sm4vZTlEcGZxdXRYS0NLSkg5d050OENtak82?= =?utf-8?B?d0xQL095VzdBQVN5cXdTam5NOXVySWsxNnpHc0M2MGRwb2tGV21sZHFDaCtw?= =?utf-8?B?bVMvYXpXMDdIR3lldG5uZjRyazRHanFwYzVGcmdlMytMelhwV1phMW1qcVRE?= =?utf-8?B?K0JLaVAyU2E4WTdRZEJXanc1bElWY2czT0d3M2JPVGYyUlZiU1FDeWd5bGlX?= =?utf-8?B?aGRVWmkxMDVTRVRKWVovRE4xdjhOVXRwT1N6U1J2TXQzNkllcExOTTJaZTl2?= =?utf-8?B?R25jSEpiMG90eHJSZ002M2NQM0xuYk9MV0gxK21JNDRKZFBuQStab1FDRUdO?= =?utf-8?B?ZXFsQ2hGREpKWlNtQ0R0bUJkVkFBWmVFeldybmNUeWVNeTArS0tzemMva2Jn?= =?utf-8?B?Nk9Ba3RCeGxXRklQT3E0SVUwRm4vTUJqcG0zak9SR1M5SzBNcytiUi9DeSs5?= =?utf-8?B?MEJzOUk4djRzcXUwYkdjczI1N1JPRDRWTEhJOTVQSjk4RFQ5NXpXTTRFZW81?= =?utf-8?B?by9vZUVpMGtUTktOSG95elJHYnFDMysxR0Z0Z09GUHVSWGI2SDc1Z1l5Y2pw?= =?utf-8?B?VlZtRzlvWE1kOE44RXFOWkFDWEYzbVhGSU93NkZYODRwWjlLOENtME5PNE1W?= =?utf-8?B?SXJDYVB0cEhqaHlnUC9ySUxmb3RrWnlkWTlsdUdrMjZlV3FPUm5jVHd2NDNT?= =?utf-8?B?VHRwVDZlSkhsaU1pNzJ3bENVSUJabFBHQnhNd0toM3R6OW15Q1l2ZHJYSXFB?= =?utf-8?B?bktCL3JjbnBaWHlkZTE0WVc5cHcrTU5MSGR1ZmM0UEk5TUFlS0R0bGhiRGVr?= =?utf-8?B?aWVoQ05MZjRzZUFUZVJCdkVzSi9JOWVwZ1pEVGtReHI1cklEblJuaXIvWWwy?= =?utf-8?B?TlVXc1hocTA1MDRoTzRiYTlZSHFQYVdzMVBwcE1IWkwxdzlERXRGMllhUDRi?= =?utf-8?B?NitKeDVub0VTenI0MnkxUUlSZ2N6UHdzWlh6bUQyamNsNlgwdGp5VlBGNWhI?= =?utf-8?B?K3pwQWlsc0dqdzJLTFN4NHE0SUdLUGJYSks3dGRzTC8wTVFPcTVjUzdEWURF?= =?utf-8?B?S0RGc3Z3eTJLdUdjVjV4UzYvV2hCV2w2RnVJdTBBcktzb2FVOUl1a1BkQUcx?= =?utf-8?B?VHhlV2I4Rk9OdVY3eUtoV0dyNEltSEhGQVd3UlFEL1pOdWVsZG5ETjdZTnQx?= =?utf-8?B?T1I0K3dpU0FSTWhncE9OYkhyYVErREJyWXpnQWVJTGZGekxLalFCbldGMWs5?= =?utf-8?B?QVpNbzZzeTN1ckhKazBOU1VnTkhkb2tNUUp5ZDJPL3ZXVU12VEV1S1lBZ3Ev?= =?utf-8?B?M2FGaGNUWEJ3TlJtVFgyQnEwaEtiZ1JveU41UkVRWnZxRGRCbmlqN1JIU3Q0?= =?utf-8?Q?FQIRipV7nlLsjFrHuqkDl?= MIME-Version: 1.0 --09a361167eba959ebd170be015f0ce2424 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

108 answers

Sort by: Most helpful
  1. Ron-6928 4,991 Reputation points
    2024-07-10T16:43:04+00:00

    >> I would've thought that if someone truly did hack into our accounts, one of the first things they'd do is change our passwords?

    Exactly. The first thing they would do is kick you out and make sure you can't get back in. They'd change your password, second factor, recovery questions etc.

    No one can help you verify except yourself (the person who receives the email). Check the mail header:

    • right mouse click the email, click View - View Message Details

    Was this answer helpful?

    30+ people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-07-29T15:19:14+00:00

    Same here, a lot of unsuccessful sign in attempts from different locations in the world. Also checked the source message and it did give me an IP completely different from mine... Anyways I'm not responding either.

    Funny how there hasn't been much on Microsoft end to acknowledge that it seems as of July of 2024 this scamming has once again resurfaced.

    Was this answer helpful?

    20+ people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2024-08-08T00:12:00+00:00

    Hi all,

    In layman, the malicious actor spoof your email address to send you this email. From the email header, you can see that the spf, dmarc, dkim failed, ie it is a spoof email.

    Don’t worry about it.

    Was this answer helpful?

    20+ people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2024-08-07T10:57:13+00:00

    Hello Everyone,

    Likewise, I have received the same formatted email more or less. I have enabled 2FA a long while back, checking recent acitivity, I do see multiple attempts to log into my hotmail from Brazil. Do I have anything to worry about if I have not received any request to log in hotmail on another device? Much thanks.

    Hi everyone,

    Today I received the same mail as mentioned at the beginning in my spam. It does scare me although I also enabled 2FA years ago. However looking at recent activity, something I’ve never done before, I see that EVERY DAY MULTIPLE (unsuccessful) attempts are being made from all over the world to log in to my account. Is that very abnormal? Should I do something, like get a new mail address and inactivate this one?

    Was this answer helpful?

    20+ people found this answer helpful.
    0 comments No comments
  5. Ron-6928 4,991 Reputation points
    2024-07-31T16:21:15+00:00

    We tech people understand that perfectly. Unfortunately for the majority of users who aren't tech minded, the scare tactic gets into their head. No amount of explanation will ease their mind. They will be worried forever.

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments