how to keep hackers out of outlook that have already compromised my account

Scott Simon 20 Reputation points
2026-08-12T20:10:41.3966667+00:00

how to keep hackers out of outlook that have already compromised my account

Outlook | Web | Outlook.com | Account management, security, and privacy

Answer accepted by question author
John Jefferson Doyon 87,500 Reputation points Independent Advisor
2026-08-12T21:53:46.1733333+00:00

John: Another party entered rules forwarding my email to an alternate location. Additionally, spam was sent to dozens/hundreds of my contacts with an attachment requesting them to open the RFP. I have removed the rules, but realize someone still has access to my microsoft account.

Yes, those are clear signs the account was compromised.

Since you have already removed the forwarding rules, please do these next:

  • Change your Microsoft account password to a completely new one.
  • Go to your Microsoft account security page and use "Sign out everywhere."
  • Check your security information and remove any email address, phone number, or sign-in method you do not recognize.
  • Turn on two-step verification if it is not already enabled.
  • Check Outlook again for any new rules or forwarding settings.

To help narrow down the issue:

  1. Have you already changed the password since this happened?
  2. Do you see any unfamiliar successful sign-ins in your Microsoft account "Recent activity"?
  3. Is there any unknown email address, phone number, or alias listed under your account security information?

Click "Add comment" to let me know.

Thanks!

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-08-12T20:11:04.7733333+00:00

    If Outlook.com or a Microsoft account has already been compromised, the priority is to cut off access, remove persistence, and harden sign-in.

    1. Change the password immediately.
    • Use a strong, unique password.
    • Do not reuse an old password.
    • Do not send the new password by email.
    1. Sign out everywhere.
    • Use the Microsoft account security options to sign out of all active sessions.
    • This can take up to 24 hours to fully take effect.
    1. Remove anything the attacker may be using to get back in.
    • Review app access and remove anything not recognized.
    • Remove any existing app passwords and create new ones only if needed.
    • Check that all security contact information belongs to the account owner.
    • Remove devices that are not recognized.
    1. Check Outlook.com mailbox settings for persistence. In Outlook.com, review these areas and remove anything suspicious:
    • Settings > Mail > Rules
    • Settings > Mail > Forwarding
    • Settings > Mail > Junk email
    • Conditional formatting
    • POP and IMAP settings if they were enabled unexpectedly
    1. Check recent account activity.
    • Review recent sign-ins and unusual activity on the recent activity page.
    • Look for unfamiliar locations, successful sign-ins, or security challenges.
    1. Turn on stronger sign-in protection.
    • Enable two-step verification or MFA.
    • Use Microsoft Authenticator.
    • Consider going passwordless for stronger protection.
    1. If suspicious behavior continues after the password change and global sign-out:
    • Wait up to 24 hours for sign-out everywhere to finish.
    • Change the password again.
    • Recheck rules, forwarding, junk settings, app access, aliases, and devices.
    1. If account recovery is still needed, use the Microsoft account recovery flow.
    • The sign-in helper can guide recovery steps or offer contact with an agent.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.