This article explains how you can recognise if your Microsoft 365 account may have been hacked, which signs are suspicious, and what you should do immediately if you suspect someone has accessed your account.
A hacked Microsoft 365 account is not always immediately obvious. Attackers often try to maintain unnoticed access to your mailbox, files, or other Microsoft 365 services for as long as possible.
Then do not wait. Change your password immediately if possible and contact your IT administrator.
Signs that your Microsoft 365 account may be hacked
A single sign does not automatically mean your account has been hacked. However, a combination of the symptoms below deserves immediate attention.
- you receive unexpected MFA or Microsoft Authenticator requests;
- you see sign-ins from unknown locations or devices;
- there are emails in Sent Items that you did not send yourself;
- emails disappear, are automatically moved, or strangely end up in other folders;
- inbox rules have been created that you do not recognise;
- email is automatically forwarded to an unknown address;
- your contacts receive strange messages from your email address;
- your account is unexpectedly locked;
- your password suddenly no longer works;
- you see unknown authentication methods or devices on your account;
- your email signature or other account details have been changed without your doing.
1. Unexpected MFA requests
Do you get a notification in Microsoft Authenticator while you are not trying to sign in yourself?
Do not approve that request.
An unexpected MFA request can mean someone already knows your username and password and is only trying to bypass the second security step.
2. Check your recent sign-ins
Microsoft shows you from which locations and devices your work or school account was recently signed into.
Open:
Check under Recent activity if you recognise the sign-ins.
Pay attention to, for example:
- countries or locations you have not visited;
- devices you do not recognise;
- sign-ins at times when you were not working;
- many failed sign-in attempts;
- activities that do not match your normal usage.
3. Check your sent emails
In Outlook, open the Sent Items folder and check if there are messages you did not send yourself.
Attackers often use hacked mailboxes to send phishing emails to colleagues, customers, or suppliers.
Also check your Deleted Items folder. An attacker may try to delete sent messages afterwards.
Treat your account as possibly compromised and contact your IT administrator immediately.
4. Check your inbox rules
Attackers regularly create Outlook rules to hide certain emails.
A malicious rule can, for example:
- automatically delete emails;
- move messages to Junk Email;
- send messages to an unexpected folder;
- hide specific replies from customers or suppliers.
In Outlook, open the settings for Rules and check if you recognise all rules.
5. Check automatic forwarding
An attacker may try to automatically forward a copy of your email to an external address.
This is particularly dangerous because the attacker can continue to monitor your incoming communication even if you do not notice anything unusual yourself.
Therefore, check that there is no unknown forwarding or forwarding rule active.
Contact your IT administrator immediately.
6. Check your security info
Check which authentication methods are linked to your Microsoft account.
Open:
Check if you recognise all registered methods, for example:
- Microsoft Authenticator;
- phone numbers;
- security keys;
- passkeys;
- other authentication methods available for your organisation.
Contact your IT administrator immediately. An attacker may register their own MFA method to maintain access to your account.
What should you do immediately?
Do you suspect someone has accessed your account? Act as quickly as possible.
- Do not approve unexpected MFA requests.
- Change your Microsoft 365 password if you still have access to your account.
- Check your recent sign-ins.
- Check your security info and MFA methods.
- Check Outlook for strange inbox rules and automatic forwarding.
- Check your Sent Items for messages you did not send yourself.
- Contact your IT administrator as soon as possible.
You can change your password via:
Why changing your password alone is not always enough
If an attacker already had access to your Microsoft 365 account, they may have made additional changes during the attack.
An IT administrator may therefore also need to:
- revoke active Microsoft 365 sessions;
- remove suspicious MFA methods;
- check for malicious inbox rules and forwarding;
- review suspicious applications or permissions;
- check which emails have been sent from your mailbox;
- investigate which sign-ins and actions have taken place.
Have you clicked on a phishing link?
Clicking on a link alone does not necessarily mean your account has been hacked.
However, if you then entered or confirmed your:
- Microsoft 365 password;
- MFA code;
- Authenticator approval;
- other sign-in details
treat the account as possibly compromised.
If you entered your sign-in details on a suspicious website, contact your IT administrator immediately.
Not sure if your account is secure?
It is not always easy to determine yourself if an account has actually been compromised.
Do you think someone has accessed your Microsoft 365 account, have you received a suspicious MFA request, or have you entered your details on a suspicious website?
Then contact FLEXAMIT via:
support@flexamit.com
Provide as clearly as possible what you have noticed and when it happened.
Summary
- Never approve an unexpected MFA request.
- Check recent Microsoft sign-ins.
- Check Sent Items and Deleted Items.
- Check inbox rules and automatic forwarding.
- Check your registered security methods.
- Change your password if in doubt.
- Always report a suspected account compromise to your IT administrator.
Comments
0 comments
Please sign in to leave a comment.