Managing personal Outlook.com account settings, security, and privacy
Based on the provided information, the account is in a typical “fully taken over” state where the attacker has changed the sign-in and security info. In this situation, only the official automated recovery and security flows can be used; support agents cannot override them or manually lock or reset the account.
Use these steps in order:
- Follow the hacked/compromised account guide
Go through the official steps for a compromised Microsoft account, including:
- Scanning all devices for malware.
- Attempting to change or reset the password.
- Checking and correcting account settings (forwarding, connected accounts, automatic replies) if access is regained. See: How to recover a hacked or compromised Microsoft account.
- Use the account recovery form again with maximum detail
Since the first recovery attempt failed, it is still possible to retry:
- Review the guidance on how to fill out the recovery form carefully.
- Include every piece of information available: Xbox console hardware ID, Xbox gamertag, old passwords, exact subject lines of emails, old phone number, purchase receipt details (last 4 digits, date), aliases, and any other historical data.
- Submit from a device and location previously used with the account, if possible.
- The form can be tried as many times as needed, up to two times per day. Guidance and form: Help with the Microsoft account recovery form and Account recovery unsuccessful.
- If security info was replaced and recovery keeps failing
The referenced guidance and moderator answers make clear:
- If the attacker has replaced the security info (email/phone, verification methods) and the automated recovery form cannot verify ownership, there is no additional manual method for support to restore or lock the account.
- Support agents are not allowed to send password reset links, access, change account details, or bypass the automated checks.
- In that case, the account is effectively unrecoverable.
- If the account is in “security info change pending” state
If at any point a “security info change is still pending” message appears when trying to sign in:
- Use the built-in options on that screen:
- “Cancel this request” if the change was initiated and old security info is still accessible.
- “Let us know” if the change was not made by the account owner, to route through the unauthorized-change flow. This is only possible if that pending screen is visible and some original proofs are still usable.
- Use the built-in options on that screen:
- If password is known but security info is partially lost
If sign-in to the account becomes possible again and at least one security method still belongs to the owner:
- Go to Advanced security options.
- Add a new way to sign in or verify.
- Remove any attacker-added security info or aliases. See: Troubleshoot Microsoft verification code issues.
- If recovery is ultimately impossible
If repeated, carefully completed recovery form submissions continue to fail, and the attacker’s security info fully replaced the original details, the documentation and moderator guidance indicate:
- The account cannot be recovered.
- There is no supported way to force a permanent lock or manual closure via support.
- The practical next steps are to protect other services and identity (email, banking, other logins) and treat this as an identity-theft incident if personal data was exposed. For broader identity protection steps, see: Protecting yourself from identity theft online.
- If there is still some access (e.g., Microsoft Store session)
If at any point full account access is restored (beyond a limited Store session):
- Immediately change the password.
- Remove any unknown aliases and security info.
- Add strong, trusted security methods (e.g., Microsoft Authenticator, trusted phone/email).
- Review recent activity and mark unfamiliar sign-ins as “This wasn’t me” or use “Secure your account” from the Recent activity page. See: What happens if there's an unusual sign-in to your account.
In summary, the only available paths are: repeatedly using the official recovery form with all possible details from known devices/locations, using any pending security-info-change options if visible, and then, if those fail, treating the account as unrecoverable and focusing on protecting other accounts and identity.
References:
- How to recover a hacked or compromised Microsoft account
- Help with the Microsoft account recovery form
- Troubleshoot Microsoft verification code issues
- Account recovery unsuccessful
- What happens if there's an unusual sign-in to your account
- Protecting yourself from identity theft online
- My account got hacked. - Microsoft Q&A
- Need help with hacked microsoft account - Microsoft Q&A
- How do I send an email to Microsoft about my account being hacked and taken over by <removed> ? - Microsoft Q&A
- my microsoft account has been compromised - Microsoft Q&A
- My account got hacked - Microsoft Q&A