A victim of a recent a Hotmail account compromised and change of alias, with no recovery option.

Craig L 0 Reputation points
2026-04-17T08:28:13.04+00:00

I’m posting this out of pure frustration, but also to warn others.

My Hotmail/Microsoft account was recently hacked and completely taken over. The attacker didn’t just change the password — they changed the primary alias (login email) and removed my original email entirely. Now when I try to log in or recover the account, Microsoft says the account “does not exist.”

Let that sink in — my account still exists, but because the hacker swapped the login email, I’m effectively locked out of my own account with no direct recovery path.

I’ve tried everything:

  • Account recovery forms (won’t work because the email is no longer linked)
  • Support pages (endless loops back to automated recovery)
  • Trying to contact a human (almost impossible)

There is no clear escalation path for a situation like this.

What’s most frustrating is this: Microsoft can clearly see backend activity — login locations, alias changes, security changes — all the signals that show a legitimate user has been locked out and replaced. This isn’t a subtle issue. It’s obvious account takeover behaviour.

Yet there is no system in place to:

  • Flag suspicious alias changes
  • Temporarily lock accounts during drastic security updates
  • Allow identity-based recovery when the login email is changed

Another concern I have — and something I haven’t been able to get an answer to — is this:

Once the hacker has changed all account details (alias, password, recovery info), how do I know the account is now permanently tied to them? At what point does Microsoft consider that account to belong to the new details instead of the original owner?

Right now, it feels like once those changes are made, the original user is completely removed from the system with no visibility or protection.

This type of attack seems to be happening more and more, and right now there’s a massive gap in how it’s handled.

If someone changes your alias, you’re essentially erased from your own account.

That’s a serious flaw.

At minimum, there should be:

  • A recovery path based on identity or historical account data
  • A way to escalate these cases to a real person
  • A delay or verification step before critical changes like alias replacement

Right now, it feels like once the attacker gets in, they win.

If anyone has successfully recovered an account after an alias change, I’d genuinely like to know how.

This is becoming far too common — and it’s a major problem.

Outlook | Web | Outlook.com | Account management, security, and privacy

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.