How to report a hacked MS account

Teo Kav 0 Reputation points
2026-09-17T14:29:16.35+00:00

Dear all,

Recently, a friend of mine was the victim of some kind of hack, which aimed to steal tokens stored on the client's side and use them to access their accounts. After a long battle to reset passwords and 2FA everything, the perpetrators managed to steal my friend's ms account, change the email address and password and even enable 2FA on this account.

My friend does not care about recovering said account, but for privacy concerns, it would be a good idea to be able to report this account so that it can be terminated. Is there some way to do that? The email address has been changed now, but maybe it's possible that Microsoft can find out which account recently used this email address and shut it down after investigating it for suspicious activity? We are at a dead end and we would appreciate some guidance. Thank you!

Windows for home | Windows 11 | Security and privacy
0 comments No comments

2 answers

Sort by: Most helpful
  1. Bulldog 4,645 Reputation points
    2026-09-17T15:50:56.69+00:00

    There is nothing that Microsoft can do to help your friend.

    Let's say that someone steals your wallet - I hope that never happens to you. Within the first few minutes of having your wallet in their possession, the thief will take out all the cash, all your cards, and all your identifying information, and then abandon your wallet. Because they don't need it any more - they already have everything about you that they need.

    Now let's say you fill out all kinds of online forms and respond to all kinds of robotic prompts, and the end result is that you have your wallet in your possession once again. Does that mean you are safe? Of course not. You won't get back the cash the thief took, but even more important: the attacker has all your information and can you use it just as if they were you.

    A Microsoft account is like a digital wallet. When someone steals your Microsoft account, within the first few minutes of having it in their possession, they will copy all the information about you that they need.

    Let's say you fill out all kinds of online forms and respond to all kinds of robotic prompts, and the end result is that you regain possession of your Microsoft account. Does that mean you are safe? Of course not. The thief still has all your information.

    This is why Microsoft can't help your friend. Even if they could, it wouldn't make any difference.

    Your friend can't afford to waste time. What they have to do now is to disconnect themselves from their former account as much as they possibly can, and then start over.

    Was this answer helpful?

    0 comments No comments

  2. John Jefferson Doyon 88,075 Reputation points Independent Advisor
    2026-09-17T15:18:27.2+00:00

    Hi, @Teo Kav

    Since your friend is not trying to recover the account and mainly wants Microsoft to investigate the compromised account, they can submit a report through Microsoft Digital Safety using the "Report a concern" form: Microsoft Digital Safety https://www.microsoft.com/digitalsafety/report-a-concern

    They can select the category that best matches what happened, such as "Fraud and Scams," "Virus, Spyware, or Malware," or "Other Terms of Use Violation," and explain that the Microsoft account was taken over, the sign-in email was changed, and the attacker enabled two-step verification. Microsoft reviews these reports and can take action if its policies were violated.

    If you haven’t tried it yet, first make sure the affected computer has also been fully scanned for malware. Microsoft recommends doing this when an account has been compromised, especially since you mentioned that authentication tokens may have been stolen.

    I really hope this information is helpful!

    Should you need further information, please let me know.

    Thanks!

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.