Sending, receiving, and organizing email in Outlook.com
This behavior indicates that the Outlook.com account, or a device used to access it, has likely been compromised and is being used to send phishing messages to contacts.
Take these steps in order:
- Secure all devices
- On every PC/phone/tablet used with this email account, run a full, up-to-date antivirus/malware scan.
- Do not click any links or open any attachments in suspicious emails. As described, spam and phishing emails can install malware that then abuses the account to send further messages.
- If malware is found, remove it; for severe infections, consider a factory reset after backing up important data.
- Protect and verify the Outlook.com account
- Since the password was already changed, also review and strengthen account security:
- Go to the Microsoft account security pages and check recent activity to see when and where the account has been accessed: https://account.live.com/activity. If sign-ins or locations look unfamiliar, this confirms compromise.
- Add or verify alternate email and mobile phone as security info so recovery is easier in the future.
- When signing in, always confirm the address bar shows a legitimate Microsoft sign-in URL (includes
login.live.com) to avoid entering the password on a phishing site.
- Check for ongoing abuse from the mailbox
- After regaining control, review:
- Sent items and Deleted items for messages not sent personally.
- Any forwarding rules, auto-replies, or linked accounts that may have been added by an attacker.
- Remove anything suspicious.
- Educate and warn contacts
- Inform family and other contacts (using a separate, trusted channel if possible) that the account was compromised and that they should:
- Delete any unexpected “party” invitations or other odd messages from this address.
- Not click links or open attachments from those messages.
- Recognize and handle phishing going forward
- Treat emails that:
- Promise rewards, threaten account closure, or demand urgent action.
- Come from mismatched or strange domains (for example, a supposed Amazon email traced to a hotel in another country).
- Contain suspicious links or attachments. as likely phishing.
- In Outlook/Outlook.com:
- Do not click suspicious links; instead, hover to see the real destination.
- Use junk/phishing reporting features and block obvious scam senders.
- Ongoing protection
- Keep operating systems and apps updated.
- Use reputable antivirus software and keep it current.
- Consider adding trusted senders to the safe list and blocking known scam addresses so legitimate mail is easier to distinguish from junk.
If there are signs that the attacker still has access after these steps (new suspicious emails continue to be sent, or unfamiliar sign-ins keep appearing in recent activity), repeat malware checks on all devices and go through the account security and recovery guidance for a potentially hacked Outlook.com account.
References: