Unauthorized Access, Email Change, and Inadequate Security Alerts

Kaan Kara 0 Reputation points
2025-12-02T17:22:03.83+00:00

Regards, [Your Name]Hello,

I am writing to report a serious security issue with my Microsoft account.

For some reason, emails from Microsoft are consistently being delivered to my spam folder. Because of this, I did not see important security alerts in time. In addition, when someone logs in from a location completely unrelated to my actual region, I am not receiving any strong warnings or verification prompts. Despite years of using this account with a stable location and no unusual activity, my primary email address was changed without my consent — and now I cannot even access my account.

I do not understand how someone logging in from Russia can access my account and add a completely unrelated email address without Microsoft blocking or verifying such an attempt. When I try to add an email to my own other account, I receive two clear options:

If you did not request this, use this link to cancel it

If you added this email, use this link to verify

However, when suspicious activity occurs on my account, the only instructions I receive are:

If you didn’t make this change, please follow these steps: Go to https://account.live.com/password/Reset to reset your password Go to https://account.live.com/ to change your primary alias

But clicking those links asks me for my password — which I no longer have because it was changed by the unauthorized user. If I knew the password, I wouldn’t be asking for help. This makes no sense as a security process.

Is this truly the level of protection Microsoft provides? Even small, unknown apps offer stronger security systems, yet one of the biggest technology companies in the world is allowing accounts to be compromised so easily — by attackers from foreign countries.

This situation is unacceptable. I request immediate support to recover my account, restore my original email, and ensure that stronger protection is applied moving forward.

Here are the details of my account:

  • Original email address: ******@gmail.com
  • Unauthorized new email currently on the account: ******@endomeml.ru

Please respond urgently.

Regards,
Kaan Kara

Microsoft Security | Microsoft Defender | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Nathan Roberts (SN) 8,216 Reputation points Volunteer Moderator
    2025-12-07T11:32:39.7966667+00:00

    Hey there, Kaan Kara

    For some reason, emails from Microsoft are consistently being delivered to my spam folder. Because of this, I did not see important security alerts in time.

    Are these security emails going to your alternative account, or to your main Microsoft account?

    If they are going to your alternative account, if the account is a Gmail account, or another email provider, the email provider's SPAM filter may have thought these were SPAM and moved them to the SPAM folder.

    If these were sent to your Microsoft email account, then they shouldn't have gone to your SPAM filter.

    However, when suspicious activity occurs on my account, the only instructions I receive are:

    If you didn’t make this change, please follow these steps: Go to https://account.live.com/password/Reset to reset your password Go to https://account.live.com/ to change your primary alias

    But clicking those links asks me for my password — which I no longer have because it was changed by the unauthorized user.

    This is by design. If there was a change made on your account, you should be able to sign into your Microsoft account using your security information to log in and change your password.

    I suspect you don't have security proofs on your account such as:

    1. Microsoft Authenticator,
    2. Alternative Phone Number,
    3. Alternative Email,
    4. Windows Hello,
    5. Account Recovery Code.

    Is this truly the level of protection Microsoft provides? Even small, unknown apps offer stronger security systems, yet one of the biggest technology companies in the world is allowing accounts to be compromised so easily — by attackers from foreign countries.

    There a a few security measures people can implement for their accounts to prevent unauthorised access. These are as follows:

    1. The Microsoft Authenticator app,
    2. Two step verification,
    3. Passwordless accounts,
    4. Account recovery codes,
    5. Security proofs

    You can view an article on how to keep your Microsoft account safe here: https://v4.hkg1.meaqua.org/en-gb/answers/questions/2339062/(article)-keeping-your-microsoft-account-secure

    This situation is unacceptable. I request immediate support to recover my account, restore my original email, and ensure that stronger protection is applied moving forward.

    As you have had your account has been taken over, please can you reach out to Microsoft support using this link here: https://support.microsoft.com/en-gb/home/contact?SourceApp=smc2&ContactUsExperienceEntryPointAssetId=login.live.com

    You will need to search "Microsoft account hacked"

    Once you click search, it will display articles that may help you. Please click onto "Contact Support" at the bottom of the page.

    This will allow you to reach out to Microsoft support and tell them what has happened. They should be able to collect as much information as possible and share this with the right team for them to investigate.

    Hope this helps,
    Nathan

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.