My Microsoft / Outlook account was hacked, how do I recover it?
Last reviewed: 2026-08-01 · Checked with Hunch’s on-device engine, the same one inside the extension. How Hunch checks →
Part of our guide: What to do if you got scammed →
Yes, you can recover a compromised Microsoft account, and doing it promptly protects your Outlook mail, OneDrive, and Xbox or Office logins. The intrusion usually comes from a fake "unusual sign-in" email linking to a lookalike host like microsoft-verify-login.example instead of microsoft.com. Use Microsoft's official recover-a-hacked-account page, reset your password, and review recent activity.
Got a message like this? Paste it here →
Microsoft accounts appeal to attackers because one login can span work email, cloud files, and gaming or Office subscriptions with saved payment cards. The fake sign-in alert works by copying Microsoft's genuine security notices and demanding fast verification, steering users onto a lookalike domain where their password is captured.
Illustrative example of the pattern, not a real message someone received.
How to verify it yourself
- Inspect the link and sender, Microsoft uses microsoft.com and account.microsoft.com, never microsoft-verify-login.example.
- Type account.microsoft.com yourself and open Security > Recent activity to spot foreign sign-ins.
- If you're locked out, start Microsoft's official account-recovery form rather than any link from the email.
- Check Outlook rules and forwarding for anything that secretly copies your mail elsewhere.
Common questions
They locked me out completely, what now?
Use Microsoft's account-recovery form, which verifies ownership through past passwords, contacts, and billing details, and can restore access even when the attacker changed your security info.
Is my OneDrive and email exposed?
Treat it as possibly accessed. After recovery, review OneDrive sharing links and Outlook forwarding rules, and remove anything you didn't set up.
Why did my sign-in look normal to Microsoft?
Because the attacker used your real password, harvested from a lookalike page, to Microsoft it looked like you until unusual activity triggered a flag.
How do I harden it against another attempt?
Turn on two-step verification, add the Microsoft Authenticator app, and consider a passkey so a stolen password alone can't sign in.
If you already responded
- Open Microsoft's official "How to recover a hacked or compromised account" page by typing support.microsoft.com yourself.
- Reset your password and sign out everywhere from the Security section of your account.
- Restore your correct recovery email and phone, and delete any Outlook forwarding or rules you didn't create.
- Enable two-step verification and set up the Authenticator app.
- No legitimate recovery service cold-calls you or charges a fee, a caller claiming to be "Microsoft" asking for payment or remote access is a scam.
If you were already hit, expect a follow-up
One more thing to expect: after a scam, your details often land on lists that get reused, so you may be contacted again, sometimes by people posing as investigators, your bank's "fraud team," or "recovery agents" who promise to get your money back for an upfront fee. That follow-up is a second scam. No legitimate service charges a fee to recover funds.
Source: Microsoft, Recover a hacked account
Hunch is not affiliated with Microsoft. Microsoft is named only to describe a scam that impersonates it; the real Microsoft does not send these messages.