This matches a common phishing takeover: the single-use code gave the attacker access, and changing the security info is a sign the account was compromised.
- Start with Microsoft’s account recovery flow immediately: Start. That tool asks for the email address or phone number and either gives self-help steps or offers the chance to talk to an agent.
- Before changing any password on the PC, run a full malware scan:
- Open Windows Security
- Go to Virus and threat protection
- Select Scan options > Full scan > Scan now
- If access is still possible, change the Microsoft account password right away. If sign-in fails, use the password reset option in the recovery flow.
- After regaining access, review account settings that attackers commonly change:
- Connected accounts
- Forwarding
- Automatic replies
- Check the Recent activity page and report any sign-ins that were not legitimate.
- Add another verification method on the Advanced security options page so recovery is easier if this happens again.
Important facts for this situation:
- Legitimate unusual sign-in emails from Microsoft can come from ******@accountprotection.microsoft.com.
- Emails from the Microsoft account team are trustworthy when the domain is @accountprotection.microsoft.com.
- Microsoft support agents are not allowed to send password reset links or directly change account details.
Because bank information was linked to the account, contact the bank immediately using the number on the bank card or official bank site and ask them to review the account for unauthorized activity.
If sign-in or recovery does not work, use Microsoft’s support entry point: Contact Microsoft Support.
References: