Microsoft/Outlook Account Hacked? How to Recover and Secure It

Recover a hacked Microsoft or Outlook account — step by step 2026

Your Microsoft account is rarely just an inbox. It is the login behind Outlook or Hotmail mail, OneDrive files, Teams, Xbox, the Microsoft Store, and — for a huge number of people — the sign-in for Windows itself. If it also runs a Microsoft 365 business tenant, it is the login your clients and suppliers trust when an email lands in their inbox from your name. A hacked Microsoft or Outlook account is rarely a minor inconvenience: it is often the first step in something much bigger, from identity theft to business email compromise (BEC) fraud. The good news is that Microsoft has a structured, effective recovery path, and if you work through it in the right order, most people get back in and close the door behind the attacker for good. Here is exactly how.

Move fast: While an attacker holds your Microsoft account they can reset passwords on every linked service, quietly plant inbox rules to keep reading your mail, and impersonate you to clients or coworkers. The sooner you recover and clean it up, the less damage spreads.

Signs Your Microsoft or Outlook Account Was Hacked

Currently locked out and can't sign in at all? If Microsoft is asking for identity verification you can't complete and you just need back in, see our Microsoft account recovery service for hands-on, same-day help. The rest of this guide focuses on what to do once you're back in — cleaning out what an attacker left behind and locking the account down for good.

Step 1 — Start the Official Microsoft Recovery Process

1

Go to account.live.com/acsr

This is Microsoft's official Account Compromised Sign-in Recovery form, built specifically for hacked accounts. Enter your email and follow the prompts. Do this from a device, browser, and location you normally use — familiar context is one of Microsoft's strongest trust signals and significantly improves your odds of a fast approval.

2

Use Microsoft Authenticator if it's still installed

If the Microsoft Authenticator app is still installed on a phone or tablet you trust, Microsoft can send an approval prompt there instantly — usually the fastest way back in, faster than a code sent by text or email.

3

No recovery options left? Use the no-code recovery form

If the attacker changed your recovery email and phone, account.live.com/acsr offers a detailed questionnaire: old passwords you remember, roughly when you created the account, frequently emailed contacts, and folder names you used. A human reviewer checks the submission, which can take anywhere from a few hours to a few days. Be as precise as possible, and don't give up after one rejected attempt — a more detailed second submission often succeeds.

Stuck in the recovery loop? Skip the trial-and-error.

Our certified bilingual tech remotes in, walks you through every recovery step, and secures the account on the spot — same day, from $119.99. No fix, no fee.

Step 2 — Clean Out What the Attacker Left Behind

This is the step almost everyone skips, and it's the one that matters most for email. Changing your password alone does not remove an attacker's access — sophisticated intruders plant ways to keep reading your mail even after you lock them out of the login screen. Once you're back in, work through every item below:

Cleanup order: New password → remove inbox rules and forwarding → revoke app permissions → sign out all sessions → restore recovery info → check Sent Items → enable two-step verification.

Need This Fixed Right Now?

IT Cares recovers locked and hijacked accounts remotely — usually in 30 minutes or less, from $119.99. No fix = no charge.

Step 3 — Lock It Down for Good

1

Turn on two-step verification — Authenticator app or a passkey

Use the Microsoft Authenticator app or a physical security key rather than SMS codes, which can be defeated by SIM-swap attacks. Microsoft also supports signing in with a passkey — the strongest option, since there is no password left for phishing to steal.

2

Review your sign-in activity

Visit account.microsoft.com/activity to see recent sign-ins by device, location, and browser — a fast way to confirm the attacker no longer has active access.

3

Use a unique password + a manager

Never reuse your Microsoft password anywhere else. A breach on an unrelated site is the #1 way Microsoft accounts get taken over through credential stuffing.

4

Check OneDrive, Teams, and Xbox individually

They share the same login. Review OneDrive's version history and recycle bin for files moved, deleted, or shared publicly without your knowledge; check Teams for messages sent in your name; and review Xbox/Microsoft Store billing history for unauthorized purchases.

Why a Microsoft/Outlook Account Is Such a Valuable Target

Understanding the motive explains the urgency. With your Microsoft account, an attacker can:

Personal Account vs. Microsoft 365 Business Account: Two Different Paths

This is the single most important distinction in Microsoft account recovery, and the one most people get wrong first. A personal account (@outlook.com, @hotmail.com, @live.com, or even a Gmail address linked to a Microsoft account) is recovered by you, directly, through account.live.com/acsr exactly as described above.

A work or school account (typically an address at your company's own domain, managed through Microsoft 365) works completely differently: it belongs to your organization's infrastructure, controlled through the Microsoft 365 admin center or Entra ID (formerly Azure Active Directory). You generally cannot recover it yourself. Contact your internal IT team or managed IT services provider immediately. An administrator can reset the password in minutes, force sign-out on every active session, and — critically — check whether the attacker created mail flow rules or attempted business email compromise fraud against a client or supplier. For a small business, this scenario is often the costliest version of the problem, because a single compromised mailbox can be used to intercept a real invoice and redirect a real payment.

Not sure which type of account you have? If your address ends in @outlook.com, @hotmail.com, or @live.com, it's personal — use account.live.com/acsr. If it ends in your company's or school's own domain, contact your IT administrator first; only they can act directly on an organizational account.

Recovery Paths Compared

Not every hacked account looks the same. Which recovery path applies to you depends on exactly what access, if any, you still have. Here's how the main options line up:

MethodWhen to use itTypical time
account.live.com/acsr with a security codeYour recovery email or phone still worksA few minutes
Microsoft Authenticator approvalThe app is still installed on a trusted deviceInstant
No-code recovery formRecovery email, phone, and every device are all lostA few hours to a few days
Admin reset (work/school account)Microsoft 365 business or education accountMinutes, once IT acts

Don't Forget the Linked Services

Because one Microsoft login opens the entire ecosystem, recovering the account doesn't end the moment Outlook is back under your control. Several services share the exact same credentials and deserve a separate look once you're back in.

Mistakes to Avoid After Recovering the Account

Stopping at the password change

This is the most common and most costly mistake. A new password without a review of inbox rules, connected apps, and active sessions often leaves the attacker with residual access — invisible until they use it again, sometimes weeks later.

Ignoring the Sent Items folder

Most people check their inbox but skip what the attacker actually sent while they had control. That folder is the fastest way to know whether contacts, clients, or suppliers received a fraudulent message that needs an immediate follow-up warning.

Reconnecting an infected device without cleaning it first

If the password was captured by malware on your computer rather than stolen through phishing, changing the password and signing back in from the same infected device exposes the new password to the same malware immediately. A full antivirus scan — or a clean reinstall — should come before reconnecting if infection is even a possibility.

Skipping a check of related accounts for a business

For an organization, one compromised mailbox is rarely the endpoint — it's often a stepping stone to other accounts through the internal address book or shared files. Limiting your review to only the account that was hit, without checking accounts that recently exchanged mail or files with it, leaves a window open for a second wave.

When to Call IT Cares

IT Cares connects remotely, walks you through Microsoft's recovery process, strips out malicious inbox rules and forwarding, sets up two-step verification correctly, and secures your linked accounts — same day, anywhere in Canada.

Need This Fixed Right Now?

IT Cares recovers locked and hijacked accounts remotely — usually in 30 minutes or less, from $119.99. No fix = no charge.

Frequently Asked Questions

How do I recover a hacked Microsoft or Outlook account?

Go to account.live.com/acsr, Microsoft's official Account Compromised Sign-in Recovery form, and verify your identity with your recovery email or phone, a Microsoft Authenticator approval, or a detailed no-code questionnaire if you have lost every option. Do it from a device, browser, and location you normally use. Once back in, change your password, sign out every session, and remove any inbox rules or forwarding the attacker added.

What if the hacker changed my recovery email and phone number?

Use the no-code recovery form at account.live.com/acsr. Microsoft asks for verifiable details: old passwords you remember, roughly when you created the account, frequent contacts, and folder names you used. A human reviewer checks the submission, which typically takes a few hours to a few days. Answer as precisely as possible and try again with more detail if a first attempt is rejected.

The hacker added an inbox rule or forwarding in Outlook — how do I find and remove it?

In Outlook.com go to Settings → Mail → Rules and delete any rule you did not create that forwards, copies, marks as read, or deletes incoming mail. Then check Settings → Mail → Forwarding and remove any forwarding address that is not yours. Attackers use these to keep reading your password-reset emails even after you change your password, which is the classic setup for business email compromise (BEC) fraud.

Will changing my Microsoft password kick the hacker out?

A new password signs out most active sessions, but you must also review account.microsoft.com/activity for sign-ins you do not recognize, revoke third-party app permissions, delete any malicious inbox rules or forwarding, and confirm your recovery email and phone are your own. If malware captured the original password, run a full antivirus scan before reconnecting or it can be stolen again.

My work or school Microsoft 365 account was hacked — what's different?

A work or school account is managed by your organization through the Microsoft 365 admin center or Entra ID, so you generally cannot self-recover it through account.live.com. Contact your internal IT team or managed services provider immediately — an administrator can force a password reset, sign out every session, check mail flow rules for BEC fraud, and audit connected apps across the whole tenant, not just one mailbox.

How do I stop my Microsoft account from being hacked again?

Turn on two-step verification using Microsoft Authenticator or a physical security key rather than SMS, which can be defeated by SIM-swap attacks. Consider switching to a passkey, which removes the password entirely as an attack surface. Use a unique password from a password manager, review your sign-in activity and app permissions every few months, and never reuse your Microsoft password on another site.

Someone accessed my Microsoft account and sent scam emails to my contacts — what should I do?

Check your Sent Items folder to see exactly what was sent and to whom, then notify those contacts directly that the messages were not from you and to ignore any links, invoices, or payment requests in them. This step matters most for businesses, where an attacker may have targeted a client or supplier with a fraudulent invoice — a fast warning can prevent real financial loss.

Comments

DR
David R. — Laval, QC
August 14, 2026

Got the "your security info was changed" email from Microsoft at 11pm and my password stopped working an hour later. account.live.com/acsr got me back in the next morning using my old phone that still had Authenticator installed. The inbox rule tip is what really mattered though — the hacker had a rule silently forwarding anything with "invoice" in the subject to a Gmail address. Would never have found that on my own.

SM
Sophie M. — Sherbrooke, QC
August 14, 2026

Our office manager's Microsoft 365 account got hit and the attacker tried sending a fake banking-info-change request to one of our suppliers. Caught it fast because the supplier called to confirm. IT Cares reset it through our admin, checked mail flow rules across the whole tenant, and got Authenticator set up for everyone. Exactly the kind of thing you don't want to handle alone.

Leave a Comment