how to recover my outlook

ok 0 Reputation points
2026-05-26T18:54:31.1333333+00:00

long story short, they got the code from authenticator app,
this is what i saw from they activity:
1- hacker session#######

Session activity: Two-step verification turned off, Recovery code added
2- hacker session#########
Session activity: Successful password reset, Alias removed, Security info added, Primary alias changed, Security info replacement completed, Successful password reset, Passed security challenge for password reset
3- hacker session#######
Session activity: Resolved unusual activity
4- MY session
Session activity: Successful sign-in
5- my session
Session activity: Successful password reset, Alternate email address deleted (was the one the hacker added), Alternate email address added(mine, same as old backup if it matters), Successful password reset, Successful sign-in
6- my session
Two-step verification turned on, Security info added, Primary alias changed, Primary alias changed, Alias added
⚠️⚠️⚠️it could not change the alias they put (******@outlook.com) it is still there, i tried to change it and it said wait for next week, if this is the issue how they tried to sign in again please let me know how to solve it⚠️⚠️⚠️

ALL THE ABOVE 8H AGO, THEN 3H AGO THIS HAPPENED
they successfully singed in from india,
7- hacker session #######
"Security info replacement started"

i thought i recovered my account? how are they still signing in successfully?

8- my session
Session activity: Alias added, Security info deleted, Alternate email address added (new backup), Security info added ,Successful sign-in, Successful password reset, Security info replacement canceled(this is what they tried to do i think), Recovery code added.

what should i do next? am i still under threat? or am i safe?

Outlook | Web | Outlook.com | Account management, security, and privacy
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-05-26T18:55:27.11+00:00

    The account is still at risk until all attacker-added security info and aliases are removed and all sessions/devices are revoked. The sign-in from India and “Security info replacement started” show the attacker still has at least one working sign-in method (password, alias, or device/session).

    Based on the provided activity, the next steps are:

    1. Secure devices first
    • Run a full malware/antivirus scan on every device used to sign in (PC, phone, tablet). A compromised device can keep leaking new codes or passwords.
    • Avoid signing in from untrusted or shared devices.
    1. Use the official hacked-account recovery path
    • Follow the guidance in How to recover a hacked or compromised Microsoft account. Start from the sign-in helper: Start.
    • If sign-in issues continue (blocks, errors), use the sign-in helper again until access is stable.
    1. Review and manage recent activity
    • Go to the Recent activity page and review all sign-ins and security changes for the last 30 days. If any activity is not recognized, mark it as not yours and follow the “Secure your account” flow.
    • From the Recent activity page, if suspicious events appear, select Secure your account so Microsoft can apply automated protections.
    1. Remove attacker security info and aliases (when allowed)
    • Once signed in and past any “security info change pending” state, go to the Microsoft account Security settings and:
      • Remove any email aliases or phone numbers that are not recognized.
      • Remove any security info (alternate email, phone, authenticator) that does not belong to the legitimate owner.
    • If the account shows “security info change is still pending” and a 30‑day wait, use the options on that screen:
      • If the change was not initiated by the owner, select the option to report it (for unauthorized changes) so the replacement can be blocked.
    1. Change password and add new security info
    • Change the password again from the Security basics page, using a strong, unique password not used on any other site.
    • Add new, trusted security info (phone, alternate email, Microsoft Authenticator) that only the legitimate owner controls.
    • Register for and keep two-step verification turned on.
    1. Revoke existing sessions and trusted devices
    • From the Security settings page, remove all trusted devices so any previously remembered sessions are invalidated.
    • Sign out of all sessions where possible, then sign in again only from clean devices.
    1. Monitor for further unusual activity
    • Regularly check My sign-ins / Recent activity for new sign-ins from unknown locations or devices.
    • If new suspicious activity appears, immediately change the password again and repeat the secure-your-account flow.
    1. Inform contacts and watch for abuse
    • Inform important contacts that the account was compromised so they can ignore suspicious messages that may have been sent while the attacker had access.

    The account is considered safe only when:

    • No unrecognized aliases or security info remain.
    • Two-step verification is enabled with only trusted methods.
    • No new unusual sign-ins appear in Recent activity after these changes.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.