If the hacker changed the sign-in email, password, and recovery details, the supported recovery path is limited to Microsoft’s account recovery process.
- First, scan the PC for malware before attempting any more recovery steps:
- Open Windows Security
- Go to Virus and threat protection
- Select Scan options > Full scan > Scan now
- Use the Sign-in Helper first, because it is the recommended starting point for compromised accounts:
- Start
- If sign-in issues continue, use Sign-in Helper
- If the account recovery tool says the account does not exist, check the account spelling carefully. If the entry is correct, follow the guidance for that specific condition in My username and password have stopped working.
- If two-step verification was not turned on and the normal reset options do not work, submit the Account recovery form. Complete it from a device and location previously used with the account if possible, and provide a working contact email for the response.
- If two-step verification was turned on and none of the alternate verification methods are accessible, Microsoft states that support agents cannot reset the password or change account details.
- If an unusual sign-in alert was received and access is still possible on the security page, review recent activity and mark unauthorized activity:
- Go to Security basics
- Select Review activity
- For suspicious entries, select This wasn't me or Secure your account
- If access is regained, immediately change the password and then review account settings such as connected accounts, forwarding, and automatic replies, because those may have been changed after compromise.
If the hacker changed everything and the recovery form cannot verify ownership, the available next step is to use Microsoft support entry points, but support agents are still not allowed to send password reset links or directly change account details.
References: