Outlook.com hacked – sextortion draft keeps reappearing

Konstantinos Diamantis 15 Reputation points
2026-01-21T21:36:45.8866667+00:00

My Outlook.com/Hotmail account was compromised and I found a sextortion draft email (Bitcoin blackmail text) that was created inside my mailbox.

I have already done the following steps: – Changed my password several times and enabled two-factor authentication (2FA). – Signed out of all sessions/devices. – Disabled POP and IMAP for this account. – Checked and deleted all inbox rules; forwarding is turned off. – There are no third-party apps or services with consent/access to my account. – Performed full and offline antivirus scans on my Windows machine; no active malware was found.

However, this specific draft email with the blackmail text keeps reappearing by itself with a new timestamp after I delete it from Drafts and Deleted Items (and even after emptying recoverable items). It never appears in Sent Items, and I don’t see any new suspicious sign-in events in the “Recent activity” page.

Please check on the server side if there are any hidden mailbox rules, scripts, BHMailer or any other malicious configuration left in my mailbox that is recreating this draft, and remove them.

I want to make sure my account is fully clean and that this draft will not be recreated again.

Outlook | Web | Outlook.com | Account management, security, and privacy

1 answer

Sort by: Newest
  1. AI answer

    2026-01-21T21:36:58.8233333+00:00

    It sounds like your Outlook.com account has been compromised in a way that is not fully resolved by the steps you've taken. Here are some additional recommendations to help secure your account and address the issue with the recurring draft email:

    1. Check for Suspicious Inbox Rules: Even though you mentioned checking and deleting all inbox rules, it's important to ensure there are no hidden or malicious rules that could be recreating the draft. You can use PowerShell to view all inbox rules if you have access to that environment.
    2. Review Account Activity: Continue monitoring the "Recent activity" page for any suspicious sign-ins. If you notice any unfamiliar locations or devices, take immediate action.
    3. Revoke Active Sessions: Ensure that you have revoked all active sessions. This can be done through the security settings of your account.
    4. Enable Multi-Factor Authentication (MFA): You mentioned enabling 2FA, which is good. Ensure that it is set up correctly and that you are using a secure method for authentication.
    5. Contact Microsoft Support: If the issue persists, it may be necessary to contact Microsoft support for further assistance. They can investigate server-side issues and check for any hidden configurations that may be causing the draft to reappear.
    6. Consider a Full Account Review: If you suspect that your account is still compromised, consider a full review of your account settings and connected services. This includes checking for any linked accounts or services that might have access to your Outlook account.

    By following these steps, you should be able to further secure your account and address the issue with the recurring draft email.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.