Managing personal Outlook.com account settings, security, and privacy
Follow these steps immediately to protect the shared email and any Microsoft/Xbox data tied to it:
- Check for unusual sign-ins and secure the Microsoft account
- Go to the Security basics page and sign in with the shared email account.
- Select Review activity and check the Recent activity page for any sign-ins, password changes, or security info changes that are not recognized.
- For any activity that is not yours, expand it and choose:
- This wasn't me (if it appears under Unusual activity), or
- Secure your account (if it appears under Recent activity).
- Return to Security basics and select Change password. Set a strong, unique password that is not used on any other site and do not share it.
- Verify and update security information
- While still on the Security basics page, confirm that the phone number and alternate email listed as security info belong to you or your mum.
- Remove any phone numbers or email addresses that are not recognized.
- Turn on and strengthen multi-factor authentication (MFA)
- Ensure multi-factor authentication is enabled on the Microsoft account. MFA blocks most password-based attacks and is described as defeating 99% of password attacks.
- If any sign-in method (like an authenticator app or phone) was added that is not recognized, remove it and reconfigure MFA with trusted devices only.
- Harden all accounts that use this email as a username
- For every service where this shared email is used as the sign-in ID (bank, socials, Xbox, Epic Games, etc.), change the password to a strong, unique one and enable multi-factor authentication where available.
- Do not reuse passwords across sites. If any password is weak or reused, change it immediately.
- Monitor for identity theft and breaches
- Consider using Microsoft Defender’s identity theft monitoring to see if the email or other personal data has appeared in a breach and to get restoration help. See Getting started with identity theft monitoring in Microsoft Defender from the linked article.
- If Defender reports an “Unknown” breach with your data, treat it seriously and change any recognized passwords anywhere they are used.
- If there are signs of financial or identity fraud
- If bank or identity information may have been misused, follow the guidance in Protecting yourself from identity theft online:
- Contact banks and card issuers, close or secure affected accounts, and use new PINs.
- Consider placing a fraud alert on credit reports (if applicable in your country).
- Keep records of all emails, letters, and calls related to the incident.
- If bank or identity information may have been misused, follow the guidance in Protecting yourself from identity theft online:
- Work with Xbox/Epic support for game/account issues
- For the Fortnite ban and Xbox/Epic account linkage, contact Xbox Support and Epic Games support through their official channels and explain that the account was compromised and linked to a rambler.ru address.
- Be prepared to provide proof of ownership (purchase history, gamertag, etc.).
- Improve ongoing email safety
- Use spam and phishing reporting in the email service to tune filters.
- Be extra cautious with messages that ask to click links, open attachments, or act urgently, as these are common phishing tactics.
- Consider separating accounts: one email for personal/family, another for logins to online services, and optionally a third “throwaway” address for sites that may send lots of marketing mail.
If at any point it appears that full identity theft has occurred (not just a game account compromise), follow the detailed steps in the identity theft guidance, including contacting local law enforcement and relevant consumer protection agencies.
References: