I thinkI have been HACKED

Stephanie Askew 0 Reputation points
2026-06-12T15:34:45.15+00:00

I stopped getting emails yesterday and got calls from Several people that sent a proposal email to them and they needed to click the link and put in a code. Obviously this was a hacked email I reset all my passwords on my phone on my laptop everywhere. I was able to get back into my email late last night after taking my email off the block list On our master account with my boss. My sent emails are gone again every time I send out emails since about 9:30 this morning which is what happened yesterday things are gone it's like account has been taken over again. How do I fix this ASAP!!

Outlook | Web | Outlook on the web for business | Security
0 comments No comments

3 answers

Sort by: Most helpful
  1. Alexis-NG 18,070 Reputation points Microsoft External Staff Moderator
    2026-06-12T16:04:18.2533333+00:00

    Hi Stephanie Askew,

    Based on the behavior you described, your email account appears to be experiencing signs of a potential compromise. This includes suspicious outbound messages and unexpected mailbox behavior (such as sent items being removed).

    Please note that forum moderators do not have access to user account settings and cannot assist with logging in, resetting passwords, or changing access rights. While we do not have access to internal systems or administrative tools required to resolve account-specific or backend-related issues but we’ll continue doing our best to support you within the scope of our responsibilities.

    To ensure your account is fully secured and to prevent further impact, I strongly recommend involving your IT administrator, as some of the required actions must be performed at the admin/tenant level.

    Please ask your IT admin to perform the following checks and remediation steps as soon as possible:

    • Force sign-out of all active sessions for your account (to immediately stop any unauthorized access still in progress)
    • Reset your password again and confirm that Multi-Factor Authentication (MFA) is enabled and enforced
    • Review mailbox access and permissions and verify no unauthorized users or delegates have access
    • Check for suspicious inbox rules or forwarding settings by looking for any rules that automatically delete, move, or forward messages (including hidden rules)
    • Check for unauthorized email forwarding or redirection
    • Review recent sign-in activity and audit logs
    • Verify whether the account has been flagged for outbound spam. This can happen when a compromised account sends phishing emails
    • Check whether any of your important emails have been quarantined.
    • If suspicious activity continues, temporarily blocking the account may help contain the issue while investigation is ongoing

    Additionally, please refrain from sending emails from this account until your IT admin confirms that the issue has been fully resolved, as continued activity may indicate the account is still being accessed by an unauthorized party.

    I hope this provides enough clarity and helps you stay inform with your current situation.

    Thank you for your patience and your understanding. If you have any questions or need further assistance, please feel free to share them in the comments on this post so I can continue to support you.   


    Note: Follow the steps in this documentation to enable email notifications if you want to receive email notifications related to this topic.

    Was this answer helpful?

    0 comments No comments

  2. Kyle McGlone 0 Reputation points
    2026-06-12T15:59:22.5233333+00:00

    Was hoping I’d be contacted about my email being hacked.

    Was this answer helpful?


  3. AI answer

    2026-06-12T15:35:13.87+00:00

    Follow these steps immediately to regain control of the mailbox and stop the malicious behavior:

    1. Secure the account credentials
    • Change the account password again from a trusted device and network.
    • Ensure the new password is strong and unique and not reused on any other site.
    • Turn on multi-factor authentication (MFA) for the account if not already enabled. MFA blocks most password-based attacks.
    1. Sign out attackers and remove their access
    • From the Microsoft account security page, use the option to sign out of all active sessions so any attacker sessions are terminated.
    • Review and remove any unknown or suspicious app permissions or connected apps that might be maintaining access.
    1. Clean up malicious mailbox rules and forwarding Compromised Microsoft 365 mailboxes often show exactly what is being described: missing or deleted mail, suspicious sent items, and rules that hide or move messages.

    In Outlook on the web for business:

    • Go to Settings → Mail → Rules and delete any rules that:
      • Automatically forward email to unknown addresses.
      • Move messages to Notes, Junk Email, RSS Subscriptions, or other unexpected folders.
    • Go to Mail → Forwarding and remove any external forwarding addresses that were not configured.
    • Check Automatic replies and signatures for any suspicious content that might be sending links or instructions to recipients.
    1. Check folders for evidence of compromise
    • Review Sent Items and Deleted Items for suspicious messages (for example, messages asking others to click a link and enter a code, or “proposal” emails that were not sent).
    • If messages are disappearing, verify that no rules are deleting or moving them as described above.
    1. Coordinate with the Microsoft 365 admin (master account / boss) Since the account was previously blocked and unblocked by the master account:
    • Ask the admin to:
      • Review sign-in logs and security alerts for the account.
      • Check for any external forwarding configured at the tenant level.
      • Use Microsoft Defender for Office 365 tools (if available) to detect and remediate malicious rules and forms in the mailbox.
    1. Inform contacts and limit damage
    • Notify the people who received the fraudulent “proposal” emails that the account was compromised and that they should:
      • Not click any links.
      • Not enter codes or credentials.
    • If they already clicked, advise them to change their passwords and enable MFA on their own accounts.
    1. Monitor for recurring compromise
    • After cleanup, continue to monitor:
      • For new suspicious rules or forwarding.
      • For unusual sign-ins, password changes, or account lockouts.
      • For new suspicious messages in Sent Items.

    If the symptoms listed in the Microsoft guidance for compromised accounts (blocked sending, suspicious rules, missing mail, external forwarding, etc.) continue after these steps, follow the full remediation guidance for compromised cloud email accounts and, if necessary, escalate through the organization’s security or IT team.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.