Managing personal Outlook.com account settings, security, and privacy
The screenshots show sign-in blocked (account compromised). That means suspicious sign-in attempts were detected and blocked, and the activity was already reported as unauthorized. Microsoft account activity pages can show location, device/OS, browser/app, and IP address, but mobile routing and IP-based geolocation can sometimes make locations appear inaccurate.
Recommended actions:
- Review Recent activity again Open the Recent activity page and expand each event. Check the device/OS, browser/app, IP address, and location. For anything not recognized, keep it marked as unauthorized and use Secure your account if shown.
- Scan the device for malware before changing anything else
If the email claims a RAT was used, run a full antivirus scan first:
- Open Windows Security
- Go to Virus and threat protection
- Select Scan options > Full scan > Scan now
- Change the password after the scan After the malware scan completes, change the Microsoft account password to a strong, unique password.
- Update security info Go to Security info and review the sign-in and verification methods. Remove anything unfamiliar and update security settings if needed.
- Check account settings that attackers commonly change
Review these areas for unauthorized changes:
- Connected accounts
- Forwarding
- Automatic replies
- Treat the “RAT hacked your account” email as suspicious Do not reply, click links, open attachments, or send payment. If the account activity page shows blocked sign-ins and no recognized unauthorized changes remain after the checks above, the email itself may be a scam attempt.
- If access problems continue or the account cannot be trusted Use the Microsoft account recovery flow for a hacked or compromised account. The sign-in helper can provide self-help steps or offer contact with an agent.
What can be confirmed from the available account tools:
- Recent activity can show whether there were unusual sign-ins and whether they were blocked.
- The account owner can review suspicious events and report This wasn't me.
- Security settings and account settings such as forwarding and connected accounts should be reviewed manually.
What is not supported here:
- No direct investigation of the account backend can be performed here.
- No direct confirmation of active sessions, connected apps, or recovery changes beyond what is visible in the account security pages.
References: