My Microsoft Account Was Stolen Despite Two-Step Verification — How Was the Hacker Allowed to Change Everything?

Ernie Joseph Cledera 0 Reputation points
2026-08-31T12:29:54.39+00:00

I am beyond frustrated with Microsoft's account security and recovery process.

Recently, all of the major accounts that were logged into my PC were compromised. I was able to recover almost all of them.

Except for my Microsoft account.

My microsoft account "@hotmail.com" was unable to be identified in their system.
It was also changed to "
@bibimail.net" which is the hacker's email.

The attacker was somehow able to:

Change my primary email address

Remove my passkeys

Change or replace my Microsoft Authenticator/security information

Lock me out of my own account completely

And the most ridiculous part?

Two-Step Verification was enabled on my Microsoft account.

Microsoft Support is now telling me that because Two-Step Verification is enabled, they cannot help me recover the account or make changes to the security information.

So let me understand this correctly:

Two-Step Verification is apparently strong enough to permanently prevent the legitimate owner from recovering their account, but somehow it was not strong enough to prevent an attacker from taking over the account and changing all of the security methods.

How does that make sense?

If my account had:

Two-Step Verification enabled

An Authenticator app

Passkeys

A phone number

Secondary/recovery information

How was an attacker able to change these things without me approving the changes?

I did not knowingly approve a request to:

Remove my passkeys

Replace my Authenticator

Change my primary email

Hand over control of my entire Microsoft account

I also did not receive any meaningful warning or opportunity to stop the takeover through my phone number or secondary email before I was completely locked out.

These are not minor account changes. These are critical security changes that determine who owns the account.

So I want Microsoft to explain exactly what happened.

My questions:

1. How can an attacker change security information when Two-Step Verification is enabled?

2. How can an attacker replace or modify the Authenticator method that is supposed to protect the account?

3. Why can critical security methods such as passkeys and primary aliases be removed or changed without requiring confirmation from the existing recovery methods?

4. Why is Microsoft Support completely powerless to help after an account takeover simply because Two-Step Verification was enabled?

5. If Microsoft has already confirmed that unauthorized access occurred, why is there still no meaningful investigation or escalation path for the legitimate account owner?

This is where Microsoft's recovery system completely fails victims.

I understand that recovery protections exist to prevent attackers from impersonating account owners. That makes sense.

But Microsoft's current process seems to create a situation where an attacker who successfully gets through once can permanently weaponize Microsoft's own security policies against the legitimate owner.

The attacker changes the security information.

The legitimate owner gets locked out.

The legitimate owner contacts Microsoft.

Microsoft says:

It looks like you just used the Microsoft account recovery form (https://account.live.com/acsr?mkt=en-US) to request a password reset for ******@bibimail.net. Because you've turned on two-step verification for your account, we ignore these requests but wanted to let you know.

That is not a recovery process. That is a dead end.

What makes this even more frustrating is that I have seen many other people reporting identical situations. People lose access to their Microsoft accounts after attackers change their security information, and they end up trapped in the same recovery loop.

There have also been cases where people with a large public platform have received assistance after publicly escalating their account compromise. For example, people can look into the case involving streamer Joshua Kane discussed publicly on X.

So does someone need to be famous or have a large social media following before Microsoft takes a confirmed account takeover seriously?

Because ordinary users with important data, subscriptions, services, and accounts linked to their Microsoft account deserve a legitimate escalation process too.

I am not asking Microsoft to blindly hand over an account to anyone claiming ownership.

I am asking for:

A real investigation into how the attacker bypassed or satisfied Two-Step Verification

An explanation of how my Authenticator and security information were changed

A review of the unauthorized activity on my account

A legitimate escalation path for victims of confirmed account compromise

A recovery process that does not automatically become impossible simply because an attacker managed to change the account's security methods first

Microsoft's security system should not make it easier for an attacker to permanently lock out the legitimate account owner than it is for the legitimate owner to recover their own account.

Has anyone else experienced this and actually received a real explanation or successfully recovered their account?

Because right now, I am being told that the very security feature that was supposed to protect me is also the reason Microsoft refuses to help me get my account back.

Microsoft Security | Microsoft Authenticator
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.