Managing personal Outlook.com account settings, security, and privacy
Follow these steps to stop the hacker’s access and the reappearing rules as much as possible while the 30‑day security change is in effect:
- Secure all devices used with this account
- Run a full, up‑to‑date antivirus/malware scan on every PC/phone/tablet that has accessed this Outlook.com account.
- If malware is found, remove it and rescan. Do not sign back in to Outlook.com from an infected device.
- Make sure the operating systems and apps on these devices are fully updated.
- Use Microsoft’s hacked‑account recovery flow
- Go to the official “How to recover a hacked or compromised Microsoft account” flow and start from there. It will guide through:
- Verifying identity.
- Regaining access if sign‑in fails.
- Locking down the account.
- If sign‑in is still possible, complete the steps even if the password cannot yet be changed because of the 30‑day security info change.
- Go to the official “How to recover a hacked or compromised Microsoft account” flow and start from there. It will guide through:
- Check and clean Outlook.com mailbox configuration
After signing in to Outlook on the web (from a clean device):
- Rules:
- Go to Settings → Mail → Rules.
- Delete every rule that is not clearly created intentionally (including rules named with dots like ".." or anything suspicious).
- Forwarding:
- Go to Mail → Forwarding.
- Turn off forwarding or remove any address that is not recognized.
- Automatic replies:
- Go to Mail → Automatic replies.
- Turn off automatic replies or remove any text the hacker may have set.
- Archive/other folders:
- Check Archive and any strange folders (like "..") for misdirected mail and move legitimate messages back to Inbox.
- Rules:
- Sign out all sessions and revoke app access
- From the Microsoft account security pages, use Sign out everywhere to invalidate existing sessions so the attacker’s active logins are dropped.
- Review connected accounts and app permissions and remove anything not recognized. This helps prevent the attacker from using an app or service that still has delegated access even after rules are deleted.
- Monitor recent activity
- Go to the Recent activity page for the Microsoft account. Review sign‑ins and security events:
- If unfamiliar locations/devices appear, use the options there to secure the account.
- Continue to monitor this page regularly over the next days.
- Go to the Recent activity page for the Microsoft account. Review sign‑ins and security events:
- Complete password and security hardening as soon as allowed
When the 30‑day restriction ends:
- Change the password immediately using the official password‑change page.
- Ensure the password is strong and unique.
- Confirm that multi‑factor authentication (MFA) is enabled and that only trusted phone numbers/authenticator apps are listed.
- Add/verify alternate email and mobile number as security info so recovery is easier in the future.
- Inform contacts and watch for missing mail
- Because the attacker already sent messages to contacts and diverted mail to Trash/other folders, notify important contacts from a different, safe email address that the Outlook.com account was compromised and that any unusual messages from it should be ignored.
- If messages seem to be missing, check filters, rules, Archive, and Trash as described above.
If the account ever becomes inaccessible again, use the Microsoft account recovery form and provide as much accurate detail as possible (previous passwords, frequent contacts, subject lines, etc.) from a familiar device and location.
References:
- How to recover a hacked or compromised Microsoft account
- Email is missing from your Outlook.com inbox
- Help protect your Outlook.com email account
- Hacker set up continuous draft ransomware email - Microsoft Q&A
- I have seen great advice for deleting the idtienphuoc1 Rule but none for stopping it from re-adding itself - Microsoft Q&A
- My personal hotmail account hacked by hacker with authentication app enabled. - Microsoft Q&A
- hello my email was (Moderator note: PII removed)@icloud.com and now its (Moderator note: PII removed)@jerkoffmail.com can please someone help me and the team change it my username in xbox is (Moderator note: PII removed) please help me team and change it - Microsoft Q&A
- fraud charges on microsoft account - Microsoft Q&A