My contacts have recieved two emails today from my email address containg a link to a "party" that I did not send

Mick Sharpe 20 Reputation points
2026-05-27T15:54:24.25+00:00

Hi,

So I was informed by a family member that I had sent them an invite to a a party (which I Had not). I checked and in my other email inbox there it was. I ran a Malware and Virus Check and changed my Microsoft password (8 hrs ago) I have just been informed by 2 family members that the same email was sent to them again, from my email address, in the last hour. I checked my other email inbox and no other "invites" have been received by me, meaning my other address's have been removed from the Phishers "send list" I also received another Phishing email, purportedly from Amazon this morning, and when I traced it back it was from a Hotel in Mexico!!

Outlook | Web | Outlook.com | Email
0 comments No comments

Answer accepted by question author

AI answer

2026-05-27T15:54:43.63+00:00

This behavior indicates that the Outlook.com account, or a device used to access it, has likely been compromised and is being used to send phishing messages to contacts.

Take these steps in order:

  1. Secure all devices
  • On every PC/phone/tablet used with this email account, run a full, up-to-date antivirus/malware scan.
  • Do not click any links or open any attachments in suspicious emails. As described, spam and phishing emails can install malware that then abuses the account to send further messages.
  • If malware is found, remove it; for severe infections, consider a factory reset after backing up important data.
  1. Protect and verify the Outlook.com account
  • Since the password was already changed, also review and strengthen account security:
    • Go to the Microsoft account security pages and check recent activity to see when and where the account has been accessed: https://account.live.com/activity. If sign-ins or locations look unfamiliar, this confirms compromise.
    • Add or verify alternate email and mobile phone as security info so recovery is easier in the future.
  • When signing in, always confirm the address bar shows a legitimate Microsoft sign-in URL (includes login.live.com) to avoid entering the password on a phishing site.
  1. Check for ongoing abuse from the mailbox
  • After regaining control, review:
    • Sent items and Deleted items for messages not sent personally.
    • Any forwarding rules, auto-replies, or linked accounts that may have been added by an attacker.
  • Remove anything suspicious.
  1. Educate and warn contacts
  • Inform family and other contacts (using a separate, trusted channel if possible) that the account was compromised and that they should:
    • Delete any unexpected “party” invitations or other odd messages from this address.
    • Not click links or open attachments from those messages.
  1. Recognize and handle phishing going forward
  • Treat emails that:
    • Promise rewards, threaten account closure, or demand urgent action.
    • Come from mismatched or strange domains (for example, a supposed Amazon email traced to a hotel in another country).
    • Contain suspicious links or attachments. as likely phishing.
  • In Outlook/Outlook.com:
    • Do not click suspicious links; instead, hover to see the real destination.
    • Use junk/phishing reporting features and block obvious scam senders.
  1. Ongoing protection
  • Keep operating systems and apps updated.
  • Use reputable antivirus software and keep it current.
  • Consider adding trusted senders to the safe list and blocking known scam addresses so legitimate mail is easier to distinguish from junk.

If there are signs that the attacker still has access after these steps (new suspicious emails continue to be sent, or unfamiliar sign-ins keep appearing in recent activity), repeat malware checks on all devices and go through the account security and recovery guidance for a potentially hacked Outlook.com account.


References:

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. EmilyS726 270.5K Reputation points Independent Advisor
    2026-05-27T16:55:23.81+00:00

    Can you ask the people who received the email from you to check the email header, and specifically look for any references of

    SPF
    DKIM
    DMARC

    And see if any of them fails?

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.