Managing personal Outlook.com account settings, security, and privacy
The account is still at risk until all attacker-added security info and aliases are removed and all sessions/devices are revoked. The sign-in from India and “Security info replacement started” show the attacker still has at least one working sign-in method (password, alias, or device/session).
Based on the provided activity, the next steps are:
- Secure devices first
- Run a full malware/antivirus scan on every device used to sign in (PC, phone, tablet). A compromised device can keep leaking new codes or passwords.
- Avoid signing in from untrusted or shared devices.
- Use the official hacked-account recovery path
- Follow the guidance in How to recover a hacked or compromised Microsoft account. Start from the sign-in helper: Start.
- If sign-in issues continue (blocks, errors), use the sign-in helper again until access is stable.
- Review and manage recent activity
- Go to the Recent activity page and review all sign-ins and security changes for the last 30 days. If any activity is not recognized, mark it as not yours and follow the “Secure your account” flow.
- From the Recent activity page, if suspicious events appear, select Secure your account so Microsoft can apply automated protections.
- Remove attacker security info and aliases (when allowed)
- Once signed in and past any “security info change pending” state, go to the Microsoft account Security settings and:
- Remove any email aliases or phone numbers that are not recognized.
- Remove any security info (alternate email, phone, authenticator) that does not belong to the legitimate owner.
- If the account shows “security info change is still pending” and a 30‑day wait, use the options on that screen:
- If the change was not initiated by the owner, select the option to report it (for unauthorized changes) so the replacement can be blocked.
- Change password and add new security info
- Change the password again from the Security basics page, using a strong, unique password not used on any other site.
- Add new, trusted security info (phone, alternate email, Microsoft Authenticator) that only the legitimate owner controls.
- Register for and keep two-step verification turned on.
- Revoke existing sessions and trusted devices
- From the Security settings page, remove all trusted devices so any previously remembered sessions are invalidated.
- Sign out of all sessions where possible, then sign in again only from clean devices.
- Monitor for further unusual activity
- Regularly check My sign-ins / Recent activity for new sign-ins from unknown locations or devices.
- If new suspicious activity appears, immediately change the password again and repeat the secure-your-account flow.
- Inform contacts and watch for abuse
- Inform important contacts that the account was compromised so they can ignore suspicious messages that may have been sent while the attacker had access.
The account is considered safe only when:
- No unrecognized aliases or security info remain.
- Two-step verification is enabled with only trusted methods.
- No new unusual sign-ins appear in Recent activity after these changes.
References:
- How to recover a hacked or compromised Microsoft account
- Check the recent sign-in activity for your Microsoft account
- What is the Recent activity page?
- What happens if there's an unusual sign-in to your account
- View your work or school account sign-in activity from My Sign-ins
- Troubleshoot Microsoft verification code issues
- Unblock my Outlook.com account
- My personal hotmail account hacked by hacker with authentication app enabled. - Microsoft Q&A
- My account got hacked. - Microsoft Q&A
- Can't sign in to my email - Microsoft Q&A
- My account got hacked - Microsoft Q&A
- How do I send an email to Microsoft about my account being hacked and taken over by <removed> ? - Microsoft Q&A