Single Use Codes - repeated email request notifications

Anonymous
2024-02-29T22:22:56+00:00

Why do I keep getting these messages in my email:

We received your request for a single-use code to use with your Microsoft account.

Your single-use code is: 123456 [I changed this]

If you didn't request this code, you can safely ignore this email. Someone else might have typed your email address by mistake.

Thanks,

The Microsoft account team

Privacy Statement: https://go.microsoft.com/fwlink/?LinkId=521839

Microsoft Corporation, One Microsoft Way, Redmond, WA 98052

Microsoft 365 and Office | Subscription, account, billing | Other | Windows

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

60 answers

Sort by: Most helpful
  1. Anonymous
    2024-09-20T14:28:35+00:00

    Thanks to everyone who has contributed to helping on this. I followed the instructions to check the activity on my account after I got a few emails saying I requested a SUC. I found two recent successful attempts which were definitely not from me. I have changed my password.

    Both oe the suucessful attempts are from places where I have never logged in. The Postal Code is the same as that of my ISP, but the devices which logged in are never the devices that I would use for logging in to Microsoft. The browsers used for the successful log-ins were also ones that I never use.

    Microsoft refuses to help because there were two successful attempts, and MS simply says I have used the IP address before.

    Is there any other way to investigate?

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-09-09T19:46:35+00:00

    This is a concerning matter. Looking at my recent activities shows almost 20 attempts every day and unsuccessful log-in, coming mostly from China. Is there any solution for this? What if one day, it will be a successful attempt?

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2025-02-09T13:34:46+00:00

    What sux even more is they have to know your full recovery email as well in order for the one time code to be sent. Best thing to do is CHANGE your passwords at MSN and your recovery to something that you NEVER use for anywhere else, and make sure they too are different from one another. It may not stop the emails, but atleast you have piece of mind knowing they are different, and not the same as any other site, making it harder to just "guess" at it. Make sure it is something off the wall that no one can just guess at it and get it right, meaning no mention of kids, or kids birthdays, and the like so that it can never be guessed no matter what other info they may have on you, and change it ever few months. I actually had my google and msn hacked in the past and is a PITA to get fixed once they do get in. I learned the hard way to make sure my bank, emails, and all sites dont have the same passwords for one another, yeah makes it easy to remember it for you use it everywhere, but its all they need to get in.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2024-11-08T01:44:13+00:00

    This happens to me quite frequently. My recovery email address is guessed and a single use code is generated. I rely heavily on my Microsoft account and have become increasingly concerned that it could be compromised. This is happening because my full name and email address is out there on lists from when online businesses were hacked. Check your email address with haveibeenpwned.com. Hackers can then look up your name online (e.g. LinkedIn) and look for clues to guess your recovery email address (since the beginning letters are shown as a clue). The main way around this is to change your recovery email address to one that is unknowable. It's annoying, but I will finally be doing this today.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2024-09-04T17:34:48+00:00

    To but it bluntly: There is absolutely nothing that any of us, or anyone ever can do.

    You get these codes because someone, somewhere on this planet, has entered your email address in the login field. Anyone can do that.

    All you can do is ignore them, or set up 2FA to make it even harder for them to get into your account, should they ever be able to correctly guess the one in a million combination of digits that is sent your way.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments