Microsoft account compromised: primary alias changed and 2FA added by attacker

Diego Muciño 0 Reputation points
2026-09-09T16:25:47.6733333+00:00

Hello,

My personal Microsoft account was compromised, and I am trying to determine whether there is any remaining recovery path.

My original Microsoft account alias was:

[email address removed due to PII]

I received security notifications from Microsoft confirming that changes were made to my account without my authorization:

  1. Microsoft notified me that a passkey had recently been removed from the account.

I then received a notification stating that my primary alias had been changed from [email address removed due to PII] to:

[email address removed due to PII]

I did not make either of these changes.

When I try to sign in using the new alias, Microsoft asks for verification through:

Microsoft Authenticator

an alternate email address that I do not control

I do not have access to either verification method.

I selected the option indicating that I do not have any of these methods and was directed to the Microsoft account recovery form. However, I received a response stating that the recovery request is ignored because two-step verification is enabled on the account.

I also contacted Xbox/Microsoft Support through the account recovery process. That service request was closed because support said they could not locate an account or subscription associated with the email address I provided.

I still have the original Microsoft security notification emails documenting the unauthorized alias and security changes.

My question is:

Is there any legitimate recovery path remaining for an account where the attacker changed the primary alias and security information and enabled/controls the current two-step verification methods?

I understand that Microsoft Support cannot simply bypass 2FA. I am not asking for a security bypass. I am asking whether there is any official process available for verifying ownership in this specific situation, given that Microsoft itself notified me of the unauthorized alias change.

Thank you.

Windows for home | Windows 11 | Accounts, profiles, and login
0 comments No comments

1 answer

Sort by: Oldest
  1. Bulldog 4,315 Reputation points
    2026-09-09T22:52:43.2733333+00:00

    If the attacker changed the email address, password, multifactor authentication and account recovery code - as any smart attacker will do within minutes of gaining access to an account - I'm genuinely sorry to tell you that there is no chance of getting the account back. There is nothing that Microsoft can do to help you, which is why they don't have anyone to talk to.

    You might not want that account back, even if you could get it, because the attacker can use it to send spam and attack other computers, in your name. That account could be poison to your reputation.

    What you must do now, and the sooner the better, is to take steps to prevent your identity from being misused on the internet. For example: Change all your passwords, tell your contacts not to open messages from your old address and cancel payment cards used with the account. The attacker knows everything about you that is in your account and will try to make use of it. Be on the lookout for signs that your identity has been stolen.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.