Microsoft account hacked, hacker still has access to my Outlook and keeps adding rules sending my mail to trash

Joe Dillard 0 Reputation points
2026-03-11T23:59:50.72+00:00

My email was hacked over a week ago, and I got back into the account and changed my phone number from a landline to my mobile number, but now I cannot change my password until after the 30 days, or check if they are still in my account. I noticed the hacker had put a rule on my emails and used it to send many emails from me to all my contacts. I had Geek Squad at Best Buy help me in-store with removing the rule that was sending all of my inbox to trash on the 5th, but i noticed my emails stopped being received again a couple days ago. I am here at Best Buy again and they found another rule labeled as ".." put on the emails again to move some of the emails to trash, and a folder marked as ".." where some emails were going to. I can't get the hacker out of my account it seems. I have gone through the global support line twice now, and they cannot properly direct me to Outlook.com support specifically. Yes I click the still need help option but then it directs to another search bar and "Get community help" so here I am.

Outlook | Web | Outlook.com | Account management, security, and privacy
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-03-12T00:00:11.9533333+00:00

    Follow these steps to stop the hacker’s access and the reappearing rules as much as possible while the 30‑day security change is in effect:

    1. Secure all devices used with this account
      • Run a full, up‑to‑date antivirus/malware scan on every PC/phone/tablet that has accessed this Outlook.com account.
      • If malware is found, remove it and rescan. Do not sign back in to Outlook.com from an infected device.
      • Make sure the operating systems and apps on these devices are fully updated.
    2. Use Microsoft’s hacked‑account recovery flow
      • Go to the official “How to recover a hacked or compromised Microsoft account” flow and start from there. It will guide through:
        • Verifying identity.
        • Regaining access if sign‑in fails.
        • Locking down the account.
      • If sign‑in is still possible, complete the steps even if the password cannot yet be changed because of the 30‑day security info change.
    3. Check and clean Outlook.com mailbox configuration After signing in to Outlook on the web (from a clean device):
      • Rules:
        • Go to Settings → Mail → Rules.
        • Delete every rule that is not clearly created intentionally (including rules named with dots like ".." or anything suspicious).
      • Forwarding:
        • Go to Mail → Forwarding.
        • Turn off forwarding or remove any address that is not recognized.
      • Automatic replies:
        • Go to Mail → Automatic replies.
        • Turn off automatic replies or remove any text the hacker may have set.
      • Archive/other folders:
        • Check Archive and any strange folders (like "..") for misdirected mail and move legitimate messages back to Inbox.
    4. Sign out all sessions and revoke app access
      • From the Microsoft account security pages, use Sign out everywhere to invalidate existing sessions so the attacker’s active logins are dropped.
      • Review connected accounts and app permissions and remove anything not recognized. This helps prevent the attacker from using an app or service that still has delegated access even after rules are deleted.
    5. Monitor recent activity
      • Go to the Recent activity page for the Microsoft account. Review sign‑ins and security events:
        • If unfamiliar locations/devices appear, use the options there to secure the account.
        • Continue to monitor this page regularly over the next days.
    6. Complete password and security hardening as soon as allowed When the 30‑day restriction ends:
      • Change the password immediately using the official password‑change page.
      • Ensure the password is strong and unique.
      • Confirm that multi‑factor authentication (MFA) is enabled and that only trusted phone numbers/authenticator apps are listed.
      • Add/verify alternate email and mobile number as security info so recovery is easier in the future.
    7. Inform contacts and watch for missing mail
      • Because the attacker already sent messages to contacts and diverted mail to Trash/other folders, notify important contacts from a different, safe email address that the Outlook.com account was compromised and that any unusual messages from it should be ignored.
      • If messages seem to be missing, check filters, rules, Archive, and Trash as described above.

    If the account ever becomes inaccessible again, use the Microsoft account recovery form and provide as much accurate detail as possible (previous passwords, frequent contacts, subject lines, etc.) from a familiar device and location.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.