How to Recover Hacked Outlook Account: Step-by-Step Recovery, Cleanup, and Protection

Written by: Abigail Ivy
Published on:

What to Do First When Outlook Is Hacked

If you suspect compromise, act immediately.

The fastest way to limit damage is to regain control of the Microsoft account, stop unauthorized access, and check whether the attacker changed recovery details or sent messages from your inbox.

Outlook is tied to your Microsoft account, so a hack can affect email, OneDrive, Microsoft 365, Xbox, and other connected services.

The recovery process starts with account access, then moves to cleanup, verification, and hardening.

How to Recover Hacked Outlook Access

The most important step in how to recover hacked Outlook is restoring control of the account itself.

Start with the official Microsoft sign-in flow and use every legitimate recovery path available.

  1. Try signing in immediately. Go to the Microsoft sign-in page and enter your Outlook address.

    If the password still works, change it right away.

  2. Use the “Forgot password” option. If you cannot sign in, request a password reset and complete identity verification through your recovery email, phone, or authenticator app.
  3. Try the Microsoft account recovery form. If the attacker changed your password or recovery details, use the account recovery form and provide accurate information such as previous passwords, subject lines of sent emails, contact names, and billing details.
  4. Check for lockout messages. Microsoft may place a temporary hold or security block on suspicious accounts.

    Follow every prompt carefully.

If you regain access, do not stop at the password reset.

Attackers often add their own phone number, alternate email, or app password so they can return later.

How to Check Whether the Account Was Changed

Once you can sign in, inspect the account for signs of tampering.

Microsoft account settings may reveal unauthorized changes that explain the intrusion.

  • Review the security info section for unfamiliar phone numbers or backup email addresses.
  • Check the recent activity page for logins from unknown devices, countries, or IP ranges.
  • Look for newly created forwarding rules that send your mail to another address.
  • Review connected devices and remove any that you do not recognize.
  • Inspect the sent and deleted folders for spam, phishing, or fraud messages.

Attackers commonly create persistence by altering sign-in methods, enabling email forwarding, or adding OAuth app permissions.

These changes can keep access alive even after a password reset.

Secure the Microsoft Account Right Away

After restoring access, strengthen the account before reviewing the inbox in depth.

The goal is to remove the attacker’s access path and create a new trusted baseline.

  1. Change the password to a unique, long passphrase. Avoid reusing any password from other sites.
  2. Enable two-step verification. Use Microsoft Authenticator, a security key, or another strong second factor.
  3. Remove unknown security info. Delete any phone number or email address the attacker added.
  4. Sign out everywhere. End all active sessions so unauthorized devices are forced out.
  5. Review app passwords and third-party access. Revoke anything you do not recognize.

If you use the same Microsoft account for Windows, Xbox, or OneDrive, expect password changes to affect those services as well.

That is normal and helps reduce the chance of reinfection.

How to Clean Up Outlook After a Hack

A hacked mailbox often contains hidden changes that continue to cause damage.

Cleaning Outlook means looking beyond incoming email and checking the rules, permissions, and folder structure.

Check Mail Forwarding and Inbox Rules

Forwarding is one of the most common tactics used after a mailbox compromise.

Review all automatic forwarding settings and delete any rule that sends mail to an address you do not control.

Also inspect inbox rules that move, delete, or mark messages as read.

Review Sent Mail and Deleted Items

Attackers may use your account to send phishing emails to contacts, coworkers, and customers.

Look through sent items for suspicious messages, then delete anything unauthorized.

If mail was removed, review the deleted and recoverable items folders.

Inspect Calendar, Contacts, and Email Signatures

Compromise does not always stop at the inbox.

Check your calendar for fake meetings, your contacts list for tampered entries, and your email signature for malicious links or altered phone numbers.

Remove Suspicious Apps and Permissions

In Microsoft account and Outlook settings, review connected apps, add-ins, and delegated access.

Malicious or unnecessary permissions can allow repeated access to messages and profile data.

Notify Contacts and Limit Further Damage

If attackers used your Outlook account to send messages, warn your contacts quickly.

A short alert helps prevent them from clicking malicious links or sharing sensitive information.

  • Tell recipients not to open links or attachments from recent messages that looked unusual.
  • Ask key contacts to verify any payment or password-reset requests by phone or another trusted channel.
  • Notify your employer or IT team if the account is used for business communication.

If financial information, tax documents, or personal records were exposed, treat the incident as more than an email problem.

Compromised mailboxes are often used for identity theft, wire fraud, and account takeover attempts on other services.

What If You Cannot Recover the Account?

Sometimes the attacker changes every recovery option before you notice the compromise.

If that happens, keep trying the Microsoft recovery form and provide the most accurate evidence you can.

Repeated, consistent submissions can help verify ownership.

If recovery fails, protect related accounts immediately.

Change passwords for your banking, shopping, social media, and cloud storage accounts if they used the same or a similar password.

Also alert your bank if you believe the attacker accessed financial emails or identity documents.

If the account is tied to a business domain or Microsoft 365 tenant, contact your administrator or hosting provider.

Admin-level tools may reveal sign-in logs, forwarding settings, or mailbox audit data that are not visible in a personal account.

How to Prevent Outlook From Being Hacked Again

Once the account is stable, prevention becomes the priority.

Most Outlook compromises are caused by phishing, credential reuse, malware, or weak recovery settings.

  • Use a password manager to create unique passwords for every account.
  • Turn on multifactor authentication for Microsoft and other critical services.
  • Keep recovery options current so you can regain access if sign-in details change.
  • Avoid logging in on shared or public devices unless absolutely necessary.
  • Watch for phishing emails that imitate Microsoft login pages, invoice notices, or password alerts.
  • Run malware scans on the devices you use for Outlook.

For Microsoft 365 users, security features such as conditional access, alert policies, and sign-in risk detection can add another layer of defense.

On personal accounts, the biggest gains usually come from unique passwords, strong recovery info, and two-step verification.

Signs Your Outlook Account Was Compromised

Not every hack is obvious.

Watch for these common warning signs, especially if you are trying to confirm whether Outlook was actually breached.

  • Password reset emails you did not request
  • Messages in sent mail that you do not recognize
  • Contacts reporting strange emails from your address
  • Missing messages or unexpected folder changes
  • Login alerts from unfamiliar locations or devices
  • Security info changes you did not approve

These indicators often appear together.

If you notice even one, treat the account as compromised and begin recovery steps immediately.

When to Get Extra Help

Seek additional help if the account is linked to business operations, legal records, or sensitive personal data.

Security teams, IT administrators, and fraud departments can help preserve logs, confirm the scope of access, and reduce downstream risk.

If the compromise involved identity theft, unauthorized payments, or blackmail, preserve screenshots, timestamps, and suspicious email headers.

That evidence can be useful for platform support, law enforcement, or internal incident response.