How to Recover a Microsoft Account After a Phishing Attack

Written by: Abigail Ivy
Published on:

How to Recover a Microsoft Account After a Phishing Attack

If you clicked a fake Microsoft sign-in page or shared credentials with a scammer, fast action can limit damage.

This guide explains how to recover Microsoft account after phishing attack and restore control of Outlook, OneDrive, Xbox, and related services.

Phishing can change passwords, add recovery methods, forward email, or create persistent access that survives a simple password reset.

The recovery process is part account repair, part security cleanup, and part identity verification.

What a phishing attack can do to a Microsoft account

Attackers often use fake Microsoft login pages, malicious links in email or SMS, or browser pop-ups that imitate Microsoft 365, Outlook, or OneDrive.

Once they get in, they may change sign-in details or use the account for spam, fraud, or further phishing.

  • Change your password and recovery email or phone number
  • Add their own authenticator app or security info
  • Read or forward emails from Outlook.com or Microsoft 365
  • Access files in OneDrive and photos synced from devices
  • Use the account to reset passwords on other services

What to do immediately after you realize you were phished

Time matters.

Start with containment, then move to recovery.

If you still have access to the account, act immediately; if you do not, begin the official recovery process right away.

  1. Disconnect compromised devices from the internet if you suspect active session theft.
  2. Change the Microsoft account password from a trusted device.
  3. Sign out of all sessions and connected devices.
  4. Review account security info for unknown email addresses, phone numbers, or authenticator changes.
  5. Check Outlook rules, inbox forwarding, and aliases for suspicious activity.
  6. Scan your device for malware using Microsoft Defender or another trusted anti-malware tool.

How to recover Microsoft account after phishing attack if you still have access

If the attacker has not locked you out, recovery is usually faster.

The goal is to remove their access before they can re-enter through an old session, a forwarding rule, or a newly added recovery option.

1. Change your password immediately

Go to the Microsoft account security page and set a strong, unique password.

Use a password manager to generate a random password that you do not reuse anywhere else.

2. Review security info

Check whether the attacker added a new phone number, alternate email, or authenticator method.

Remove anything you do not recognize and keep only trusted recovery methods.

3. Sign out everywhere

Microsoft lets you sign out of sessions on devices and browsers.

This step helps invalidate stolen cookies and reduces the chance that the attacker stays logged in after the password change.

4. Check email settings

In Outlook, look for forwarding rules, inbox rules, and blocked senders that were created without your knowledge.

Attackers often hide messages from Microsoft security alerts or banking emails to avoid detection.

5. Secure linked accounts

If you reuse the same password on other services, change those passwords too.

Focus first on banking, social media, Apple ID or Google account recovery options, and any service that uses your Microsoft email for password resets.

How to recover Microsoft account after phishing attack when you are locked out

If the attacker changed the password, recovery depends on Microsoft’s account verification process.

Use the official Account Recovery Form and provide accurate information from a trusted device and location.

Use the Microsoft account recovery form

Visit Microsoft’s recovery page and complete the form with as much detail as possible.

Microsoft uses the information you submit to compare your request against account history, device data, and recent activity patterns.

Helpful details can include:

  • Previous passwords you remember
  • Subject lines of recent sent emails
  • Contacts you emailed frequently
  • Approximate account creation date
  • Billing or Xbox purchase history

Verify identity through existing recovery methods

If you still control a backup email or phone number, use it to receive verification codes.

If the attacker removed those options, the account recovery form becomes the main path back in.

Be prepared to repeat the process

Recovery may not be instant.

Microsoft may require multiple attempts or a waiting period if the evidence is insufficient.

Submit accurate information rather than guessing, because inconsistent answers can reduce your chances.

How to check for deeper compromise

Recovering the password is only part of the job.

A phishing attack can leave behind hidden persistence, especially if the attacker accessed Outlook, OneDrive, Microsoft 365, or a work account managed by Entra ID.

  • Review recent sign-in activity for unfamiliar locations, IPs, or devices
  • Check for suspicious app passwords or third-party app access
  • Inspect OneDrive sharing links and recently shared files
  • Look for unauthorized purchases in Microsoft account billing
  • For work accounts, ask your IT administrator to review conditional access, audit logs, and mailbox rules

What to do if the account was used for fraud or spam

If criminals used your Microsoft account to send phishing messages, notify contacts quickly so they do not trust malicious email from your address.

Use a short, clear warning from a different channel if possible.

You should also report the incident to Microsoft and, if personal or financial data was exposed, consider filing a report with local law enforcement or a consumer fraud agency.

For business accounts, follow your organization’s incident response process and preserve logs or screenshots.

How to strengthen the account after recovery

Once access is restored, harden the account so the same attack does not work again.

The best defense is layered: stronger authentication, cleaner recovery options, and better detection of suspicious activity.

Enable phishing-resistant authentication

Use Microsoft Authenticator and, when available, passkeys or FIDO2 security keys.

These options are more resistant to credential theft than SMS codes alone.

Turn on sign-in alerts

Microsoft security notifications help you spot unfamiliar logins early.

Make sure alerts go to a trusted email address or phone number you actually monitor.

Audit recovery methods regularly

Remove old phone numbers, abandoned email addresses, and outdated authenticators.

Recovery options should always belong to you and be reachable if your primary device is lost.

Use a password manager

A password manager reduces password reuse and helps you recognize fake login pages by showing saved credentials only on the correct domain.

How to avoid another phishing attack

Most Microsoft phishing attempts rely on urgency, fear, or fake service notices.

Slowing down long enough to check the sender, domain, and URL can stop many attacks before they start.

  • Type microsoft.com or outlook.com manually instead of clicking login links
  • Watch for lookalike domains and misspellings
  • Never share verification codes with anyone
  • Confirm unusual password reset prompts before approving them
  • Use the Microsoft Authenticator app for push-based approvals

When to contact Microsoft support directly

Contact Microsoft support if the recovery form fails, your billing information was changed, a work account is affected, or you suspect ongoing unauthorized access.

For Microsoft 365 business accounts, your administrator can often move faster through tenant-level security tools.

Keep records of timestamps, suspicious emails, phone numbers used by the attacker, and any successful login alerts.

These details can help support teams validate your case and trace the compromise.