A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Take these actions immediately to protect both the Microsoft account and the credit accounts.
- Secure devices from malware
- On each Windows 10/11 or 8.1 PC used to sign in to the Microsoft account, run a full antivirus scan before changing any passwords.
- If using Windows Defender:
- Select Start.
- Search for Windows Defender or select Windows Defender.
- Turn on protection and run a full scan.
- Ensure antivirus is set to auto‑update and scan regularly.
- Recover and secure the Microsoft account
- Use the official hacked/compromised account flow: select Start in the article “How to recover a hacked or compromised Microsoft account” and follow the guided steps to regain access.
- After regaining access:
- Change the Microsoft account password immediately using a strong, unique password.
- If unable to sign in, use the reset your password option from the same article.
- Remove attacker persistence in Outlook/Microsoft account Once signed back in:
- Check Outlook/Email settings that attackers often abuse:
- Connected accounts: remove any unknown connected accounts.
- Forwarding: remove any forwarding addresses that are not recognized.
- Automatic replies: turn off or correct any replies the attacker set.
- Sign out of all sessions and revoke suspicious app permissions (via Microsoft account security pages referenced in the Q&A context) so the attacker loses access tokens.
- Strengthen Microsoft account security (Authenticator)
- Install and configure the Microsoft Authenticator app as a primary sign‑in method, following “How to help keep your Microsoft account secure”:
- Use the app to add another security layer and enable passwordless sign‑in if desired.
- In Additional security options, turn on Passwordless account and approve the request in Microsoft Authenticator.
- Ensure two‑step verification/MFA is enabled and that only trusted devices and phone numbers are listed as security info.
- Protect credit and debit card accounts Because credit accounts have already been used:
- Sign in to each bank/credit card provider using only:
- The official app, or
- A manually typed or search‑found official website (never links from email/SMS/ads).
- Review recent transactions back to at least the date of the breach and note anything not recognized, including very small test charges (e.g., around $1) which criminals use to test cards.
- Work with the bank/issuer to:
- Report fraudulent transactions and dispute charges.
- Cancel and reissue cards if needed.
- Consider setting up credit monitoring with Microsoft Defender’s identity theft monitoring feature to watch for unexpected credit activity and get alerts about new events.
- Ongoing monitoring and damage control
- Monitor the Microsoft account for unusual sign‑ins or new security alerts.
- Inform important contacts that the account was compromised so they can ignore suspicious emails or messages that appear to come from that address.
These steps combine: cleaning devices, regaining control of the Microsoft account, hardening it with Microsoft Authenticator/passwordless sign‑in, and working with financial institutions plus monitoring tools to limit and detect financial fraud.
References:
- How to recover a hacked or compromised Microsoft account
- What to do if your credit or debit card info is stolen
- How to help keep your Microsoft account secure
- My personal hotmail account hacked by hacker with authentication app enabled. - Microsoft Q&A
- Hacker set up continuous draft ransomware email - Microsoft Q&A