My account under the full control of hackers

Cozma Valeriu 5 Reputation points
2026-05-15T15:31:39.22+00:00

My Microsoft account was hijacked after I was tricked into giving a Microsoft verification code to a Discord bot. The attacker changed the account email to ******@itzcrih.it and enabled their own authenticator/two-step verification. The automated recovery form no longer works because the attacker controls the current security methods. I still have the original payment information and ownership details for the account. What is the correct escalation path for this situation?

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-15T15:31:59.12+00:00

    For a personal Microsoft account that is fully taken over (sign‑in email changed, attacker’s own security info and Authenticator added, and recovery form failing), escalation options are limited and follow these paths:

    1. Use the official hacked/compromised account flow
      • Start with the compromised-account helper, which is the front door for all such cases:
      • This tool will either guide through self‑service steps or offer a path to contact an agent, depending on what is detected for the account.
    2. Submit the account recovery form with maximum detail
      • If sign‑in and normal reset both fail, the supported escalation is the automated recovery form:
      • Use a different working email (not the compromised one) so Microsoft can contact about the request.
      • Provide every accurate detail available (old passwords, exact subject lines of emails sent/received, Xbox/Minecraft usage if applicable, billing details, etc.). Payment information and ownership details are useful here, but the system still requires enough matching signals to approve recovery.
      • If the form is rejected, it can be retried from a different device/browser/network as suggested in the Q&A guidance, but decisions are automated; if it continues to fail, the account is treated as unrecoverable.
    3. If security info was recently changed, use the “pending change” flow (if visible)
      • If at any point the sign‑in page shows a “security info change is still pending” message, use the built‑in links on that screen:
        • “Let us know” if the change was unauthorized (routes through the unauthorized‑change flow).
        • “Cancel this request” if there is still access to the old security info.
      • This is the only supported escalation when the attacker has replaced security info but the 30‑day pending window is still active.
    4. Contact Microsoft Support only through the official support entry point
      • For personal Microsoft accounts, there is no direct manual override by support if the recovery system does not validate ownership. However, if the helper and recovery form are not resolving the issue, the supported path is:
        • Go to the general support entry page referenced in the Q&A: “Contact - Microsoft Support”.
        • Sign in with a different Microsoft account (one that is still under control).
        • Under Products & Services, choose “Other Products”; under Categories, choose “Manage account security”.
        • Use “Chat with a support agent in your web browser” when available and explain that the account is fully taken over and the attacker controls all current security methods.
      • Support can only guide through the same official flows (compromised-account helper and recovery form) and cannot bypass two‑step verification or manually reset the account if the system does not confirm ownership.
    5. If recovery ultimately fails
      • As reflected in the Q&A guidance, once a hacker has replaced the email/phone and the recovery form repeatedly fails, Microsoft treats the account as unrecoverable, even if payment details are available. In that case, the only option is to secure devices, create a new Microsoft account, and update credentials everywhere else.

    In summary, the correct escalation path is: compromised-account helper → detailed account recovery form (repeated with best data) → pending security‑info change flow if shown → “Contact - Microsoft Support” (Other Products → Manage account security → chat). If all of these fail and the form does not validate ownership, there is no higher manual escalation that can override the automated checks.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.