Your Microsoft account is rarely just an inbox. It is the login behind Outlook or Hotmail mail, OneDrive files, Teams, Xbox, the Microsoft Store, and — for a huge number of people — the sign-in for Windows itself. If it also runs a Microsoft 365 business tenant, it is the login your clients and suppliers trust when an email lands in their inbox from your name. A hacked Microsoft or Outlook account is rarely a minor inconvenience: it is often the first step in something much bigger, from identity theft to business email compromise (BEC) fraud. The good news is that Microsoft has a structured, effective recovery path, and if you work through it in the right order, most people get back in and close the door behind the attacker for good. Here is exactly how.
Signs Your Microsoft or Outlook Account Was Hacked
- You are signed out and your usual password no longer works.
- Microsoft sent an "unusual activity" or "your security info was changed" alert you did not trigger.
- Sent messages, or password-reset emails for other services, that you did not initiate — check your Sent Items folder.
- Your recovery email or phone number was changed without your consent.
- Sign-ins to OneDrive, Teams, or Xbox from a device or country you do not recognize.
- Contacts, clients, or suppliers report receiving spam, scam links, or suspicious payment requests from your address.
Step 1 — Start the Official Microsoft Recovery Process
Go to account.live.com/acsr
This is Microsoft's official Account Compromised Sign-in Recovery form, built specifically for hacked accounts. Enter your email and follow the prompts. Do this from a device, browser, and location you normally use — familiar context is one of Microsoft's strongest trust signals and significantly improves your odds of a fast approval.
Use Microsoft Authenticator if it's still installed
If the Microsoft Authenticator app is still installed on a phone or tablet you trust, Microsoft can send an approval prompt there instantly — usually the fastest way back in, faster than a code sent by text or email.
No recovery options left? Use the no-code recovery form
If the attacker changed your recovery email and phone, account.live.com/acsr offers a detailed questionnaire: old passwords you remember, roughly when you created the account, frequently emailed contacts, and folder names you used. A human reviewer checks the submission, which can take anywhere from a few hours to a few days. Be as precise as possible, and don't give up after one rejected attempt — a more detailed second submission often succeeds.
Stuck in the recovery loop? Skip the trial-and-error.
Our certified bilingual tech remotes in, walks you through every recovery step, and secures the account on the spot — same day, from $119.99. No fix, no fee.
Step 2 — Clean Out What the Attacker Left Behind
This is the step almost everyone skips, and it's the one that matters most for email. Changing your password alone does not remove an attacker's access — sophisticated intruders plant ways to keep reading your mail even after you lock them out of the login screen. Once you're back in, work through every item below:
- Inbox rules: Outlook.com Settings → Mail → Rules. Delete any rule you did not create that auto-forwards, copies, marks-as-read, or deletes incoming mail. This is the single most common technique attackers use for business email compromise — a silent rule that copies anything mentioning "invoice" or "payment" to an external address.
- Forwarding: Settings → Mail → Forwarding. Remove any forwarding address you did not add.
- Recovery email & phone: Security → restore your own and remove anything the attacker added.
- Connected apps and permissions: account.microsoft.com → Privacy → App permissions. Revoke anything you don't recognize.
- Sent Items folder: check exactly what the attacker sent while they had access — this tells you who needs a warning.
- Sign out everywhere: account.microsoft.com → Security → Sign-in activity → Sign out everywhere.
Need This Fixed Right Now?
IT Cares recovers locked and hijacked accounts remotely — usually in 30 minutes or less, from $119.99. No fix = no charge.
Step 3 — Lock It Down for Good
Turn on two-step verification — Authenticator app or a passkey
Use the Microsoft Authenticator app or a physical security key rather than SMS codes, which can be defeated by SIM-swap attacks. Microsoft also supports signing in with a passkey — the strongest option, since there is no password left for phishing to steal.
Review your sign-in activity
Visit account.microsoft.com/activity to see recent sign-ins by device, location, and browser — a fast way to confirm the attacker no longer has active access.
Use a unique password + a manager
Never reuse your Microsoft password anywhere else. A breach on an unrelated site is the #1 way Microsoft accounts get taken over through credential stuffing.
Check OneDrive, Teams, and Xbox individually
They share the same login. Review OneDrive's version history and recycle bin for files moved, deleted, or shared publicly without your knowledge; check Teams for messages sent in your name; and review Xbox/Microsoft Store billing history for unauthorized purchases.
Why a Microsoft/Outlook Account Is Such a Valuable Target
Understanding the motive explains the urgency. With your Microsoft account, an attacker can:
- Reset passwords everywhere — banking, PayPal, shopping, and social media accounts all send reset links to your inbox.
- Search years of mail and OneDrive files for tax documents, invoices, scanned IDs, and passwords sent in plain text.
- Launch business email compromise (BEC) fraud — impersonate you to clients or suppliers to redirect a real payment to a fraudulent bank account.
- Hijack linked services — OneDrive, Teams, Xbox, Skype, and any app using "Sign in with Microsoft."
- Lock you out entirely by changing recovery details, then hold the account or your data for ransom.
Personal Account vs. Microsoft 365 Business Account: Two Different Paths
This is the single most important distinction in Microsoft account recovery, and the one most people get wrong first. A personal account (@outlook.com, @hotmail.com, @live.com, or even a Gmail address linked to a Microsoft account) is recovered by you, directly, through account.live.com/acsr exactly as described above.
A work or school account (typically an address at your company's own domain, managed through Microsoft 365) works completely differently: it belongs to your organization's infrastructure, controlled through the Microsoft 365 admin center or Entra ID (formerly Azure Active Directory). You generally cannot recover it yourself. Contact your internal IT team or managed IT services provider immediately. An administrator can reset the password in minutes, force sign-out on every active session, and — critically — check whether the attacker created mail flow rules or attempted business email compromise fraud against a client or supplier. For a small business, this scenario is often the costliest version of the problem, because a single compromised mailbox can be used to intercept a real invoice and redirect a real payment.
Recovery Paths Compared
Not every hacked account looks the same. Which recovery path applies to you depends on exactly what access, if any, you still have. Here's how the main options line up:
Don't Forget the Linked Services
Because one Microsoft login opens the entire ecosystem, recovering the account doesn't end the moment Outlook is back under your control. Several services share the exact same credentials and deserve a separate look once you're back in.
- OneDrive: check version history and the recycle bin for files that were deleted, moved, or shared publicly without your knowledge. An attacker with even a few hours of access can copy sensitive documents before you ever notice the intrusion.
- Microsoft Teams: for a work account, review channels and direct messages for anything sent in your name — especially unusual requests directed at colleagues in accounting or HR, a common precursor to internal-fraud attempts.
- Xbox and Microsoft Store: an attacker on a personal account can make unauthorized purchases against a saved card. Check the billing history at account.microsoft.com/billing.
- "Sign in with Microsoft": many third-party apps — games, productivity tools, forums — use this login. Review the full list under Privacy → App permissions and remove anything you no longer use or don't recognize.
- Windows itself: if your computer signs in with the same Microsoft account, a compromised password potentially exposes the full Windows session, including passwords saved in Edge. Changing the password typically forces a fresh sign-in on every linked Windows device — treat that as expected, not as a new problem.
Mistakes to Avoid After Recovering the Account
Stopping at the password change
This is the most common and most costly mistake. A new password without a review of inbox rules, connected apps, and active sessions often leaves the attacker with residual access — invisible until they use it again, sometimes weeks later.
Ignoring the Sent Items folder
Most people check their inbox but skip what the attacker actually sent while they had control. That folder is the fastest way to know whether contacts, clients, or suppliers received a fraudulent message that needs an immediate follow-up warning.
Reconnecting an infected device without cleaning it first
If the password was captured by malware on your computer rather than stolen through phishing, changing the password and signing back in from the same infected device exposes the new password to the same malware immediately. A full antivirus scan — or a clean reinstall — should come before reconnecting if infection is even a possibility.
Skipping a check of related accounts for a business
For an organization, one compromised mailbox is rarely the endpoint — it's often a stepping stone to other accounts through the internal address book or shared files. Limiting your review to only the account that was hit, without checking accounts that recently exchanged mail or files with it, leaves a window open for a second wave.
When to Call IT Cares
- The hacked account is a Microsoft 365 business account and your internal IT support isn't available quickly.
- You cannot complete recovery through account.live.com/acsr and fear permanent loss of access.
- The attacker used your Outlook to attempt business email compromise fraud against a client or supplier.
- You want a full security audit of your devices, OneDrive, and every linked account after the incident.
IT Cares connects remotely, walks you through Microsoft's recovery process, strips out malicious inbox rules and forwarding, sets up two-step verification correctly, and secures your linked accounts — same day, anywhere in Canada.
Need This Fixed Right Now?
IT Cares recovers locked and hijacked accounts remotely — usually in 30 minutes or less, from $119.99. No fix = no charge.
Frequently Asked Questions
Go to account.live.com/acsr, Microsoft's official Account Compromised Sign-in Recovery form, and verify your identity with your recovery email or phone, a Microsoft Authenticator approval, or a detailed no-code questionnaire if you have lost every option. Do it from a device, browser, and location you normally use. Once back in, change your password, sign out every session, and remove any inbox rules or forwarding the attacker added.
Use the no-code recovery form at account.live.com/acsr. Microsoft asks for verifiable details: old passwords you remember, roughly when you created the account, frequent contacts, and folder names you used. A human reviewer checks the submission, which typically takes a few hours to a few days. Answer as precisely as possible and try again with more detail if a first attempt is rejected.
In Outlook.com go to Settings → Mail → Rules and delete any rule you did not create that forwards, copies, marks as read, or deletes incoming mail. Then check Settings → Mail → Forwarding and remove any forwarding address that is not yours. Attackers use these to keep reading your password-reset emails even after you change your password, which is the classic setup for business email compromise (BEC) fraud.
A new password signs out most active sessions, but you must also review account.microsoft.com/activity for sign-ins you do not recognize, revoke third-party app permissions, delete any malicious inbox rules or forwarding, and confirm your recovery email and phone are your own. If malware captured the original password, run a full antivirus scan before reconnecting or it can be stolen again.
A work or school account is managed by your organization through the Microsoft 365 admin center or Entra ID, so you generally cannot self-recover it through account.live.com. Contact your internal IT team or managed services provider immediately — an administrator can force a password reset, sign out every session, check mail flow rules for BEC fraud, and audit connected apps across the whole tenant, not just one mailbox.
Turn on two-step verification using Microsoft Authenticator or a physical security key rather than SMS, which can be defeated by SIM-swap attacks. Consider switching to a passkey, which removes the password entirely as an attack surface. Use a unique password from a password manager, review your sign-in activity and app permissions every few months, and never reuse your Microsoft password on another site.
Check your Sent Items folder to see exactly what was sent and to whom, then notify those contacts directly that the messages were not from you and to ignore any links, invoices, or payment requests in them. This step matters most for businesses, where an attacker may have targeted a client or supplier with a fraudulent invoice — a fast warning can prevent real financial loss.

Comments
Got the "your security info was changed" email from Microsoft at 11pm and my password stopped working an hour later. account.live.com/acsr got me back in the next morning using my old phone that still had Authenticator installed. The inbox rule tip is what really mattered though — the hacker had a rule silently forwarding anything with "invoice" in the subject to a Gmail address. Would never have found that on my own.
Our office manager's Microsoft 365 account got hit and the attacker tried sending a fake banking-info-change request to one of our suppliers. Caught it fast because the supplier called to confirm. IT Cares reset it through our admin, checked mail flow rules across the whole tenant, and got Authenticator set up for everyone. Exactly the kind of thing you don't want to handle alone.
Leave a Comment