As you all see, even this was posted under anseres.microsoft.com there are no microsoft replies.
the suggestions give:
- go to the Recent activity page. (for what? I already know there are login attempts from abroad).
- strengthen your account security (we already did that, this is redundant, since we already use single-use code. it is right there in the original)
all useless.
have received many of those, even with emails that have no ms accounts.
("We couldn't find an account with that username." once I entered the email address listed in that original email..)
Conclusion:
- Microsoft does not care
- pushes responsibility on the end user.
MS needs to block and close those accounts that are attacked.
Provide users with new replacement accounts, or have a one-use accounts (like those single-use credit card numbers)..
Of course, MS will not close the accounts, since they need you to serve you adds, sell goods, services, games.. through those.
what can be done:
- close those "attacked" accounts.
- do not use MS if you do not have to. (but we all have to.. (office, steam, even new windows).
- do create new accounts on regural basis for one-or-two years use. then dump and create a new one.
most likely your account t is in the email dumps: (check: https://haveibeenpwned.com/)
No need to complain (and ask for help) from MS.
No need to seek advise of independent advisors (they are here to provide MS vision of things).
No need to read my reply either.