How to Recover a Hacked Microsoft Account

Windows 11SecurityPasswordOnline Safety

The Problem

A Microsoft account is not just an email login. It is the key to your Windows sign-in, your OneDrive files, your Xbox library and payment method, your Office subscription, and — critically — your BitLocker recovery key. Losing control of it is one of the highest-impact account compromises there is.

Attackers who get in typically do three things fast: change the recovery email and phone so you cannot get back, add their own authentication method, and either drain the payment method or hold the account for resale. The sooner you start recovery, the better the outcome.

If you can still sign in, you are in a much stronger position. Do Step 1 immediately and do not wait.

The PC was remotely accessed by a "support agent"? Do what to do after a remote access scam alongside this.

The Fix: Step-by-Step

Step 1: If You Can Still Sign In, Lock It Down Now

Go to account.microsoft.com from a device you trust and, in this order:

  1. SecurityChange my password. Use a long, unique password from your password manager.
  2. SecurityAdvanced security optionsSign me out — this terminates every active session everywhere.
  3. Review Ways to prove who you are. Delete any email address, phone number, or authenticator you do not recognise.
  4. Turn on Two-step verification if it is off, using the Microsoft Authenticator app rather than SMS.
  5. Save the recovery code shown, offline.

Do not skip the sign-out. Changing the password alone can leave an attacker's existing session live.

Step 2: If You Cannot Sign In, Try Password Reset First

Go to account.live.com/password/reset. If your recovery email or phone is still yours, you will get a code and be back in within minutes. Then do Step 1 immediately.

If the recovery options shown belong to the attacker — an unfamiliar masked address or phone — stop and go to Step 3. Do not keep retrying; repeated failures do not help and can lock the account further.

Step 3: Use the Account Recovery Form Properly

When automated reset is impossible, account.live.com/acsr is the manual review route. It is judged on how much you can prove, so preparation matters.

Before you start, gather:

  • Old passwords you have used on the account — even from years ago.
  • Subject lines of recent emails you sent, and addresses you email often.
  • The date the account was created, roughly.
  • Skype names, Xbox gamertags, and any linked service names.
  • The last four digits and type of any card on file.
  • Names of folders in your OneDrive.

Then:

  1. Submit the form from a device and network you have used with the account before — a familiar IP address and browser materially improve your odds.
  2. Give an alternate contact email you control for the response.
  3. Answer everything you can. Blanks are what usually cause rejection.
  4. Wait up to 24 hours for the emailed decision.

If it is rejected, you can submit again with more detail. Each attempt should add information rather than repeat the last one.

Step 4: Check What Happened While They Were In

Once you are back in, at account.microsoft.comSecuritySign-in activity, review every entry. Note unfamiliar locations, devices, and app types — and whether any show as "successful".

Then check:

  • PrivacyRecent activity for changes to your profile.
  • Devices — remove any device you do not own. Note that removing a device also removes its BitLocker recovery keys from the account, so check Step 6 first.
  • Payment options — remove unfamiliar cards, and check Order history and Subscriptions for purchases you did not make.
  • Family — remove any account added to your family group.

Step 5: Clean Out the Mailbox Rules

If your account uses Outlook.com, check for the classic persistence tricks. In Outlook on the web: SettingsMailForwarding, and SettingsMailRules.

Remove any forwarding address you did not add, and any rule that deletes, moves, or forwards messages — especially rules keyed on words like "security", "password", "bank", or "Microsoft". These exist so you never see the alerts.

Also check Sync email for connected accounts you did not add, and Aliases under Your info for an alias added to receive resets.

Step 6: Recover Your BitLocker Key Before Removing Devices

This is the step that catches people out. If your Windows PC has BitLocker enabled — which is default on many Windows 11 machines — the recovery key is stored in this account, and removing the device from the account removes the key with it.

Go to account.microsoft.com/devices/recoverykey, and save every key shown somewhere offline before you touch the device list. If you have already lost access to the key and the PC asks for it, see BitLocker recovery key loop.

Step 7: Check the PC Itself

An account compromise and a compromised PC often travel together — infostealer malware on the machine is one of the most common ways the credentials were taken in the first place.

Run a Full scan then a Microsoft Defender Offline scan: remove virus and malware. Then check for persistence with remove malicious scheduled tasks and startup persistence, and review browser extensions with remove malicious browser extensions.

If you skip this, whatever took your password takes the new one too.

Step 8: Fix Windows Sign-In on Your PC

After a password change, the PC may keep asking for the old one, or refuse the new one until it can reach Microsoft.

Sign in with your Windows Hello PIN, which is device-local and unaffected, then connect to the internet so the account state syncs. If sign-in problems persist, see Microsoft account sign-in problems.

Step 9: Harden It So It Does Not Repeat

  1. Add a passkey: Advanced security optionsAdd a new way to sign in — see set up passkeys.
  2. Turn on passwordless account once you have two passkeys and a recovery code saved.
  3. Set recovery email and phone to addresses you actually monitor: set up account recovery options.
  4. Check whether the old password is in circulation: check if your email was in a data breach.
  5. Never reuse this password anywhere. It is the master key to your PC.

What Not to Do

  • Do not create a new Microsoft account and abandon the old one before recovering it. You would lose OneDrive files, Office and Xbox licences, and any BitLocker keys — and the attacker keeps a working account with your name on it.
  • Do not pay anyone offering account recovery. Microsoft's form is the only route; paid "recovery specialists" cannot do anything you cannot.
  • Do not remove devices from the account before saving BitLocker keys.
  • Do not use the same recovery email you use as a login for another compromised service.

FAQ

How long does Microsoft account recovery take?

The automated reset is immediate if your recovery email or phone still works. The manual recovery form is typically answered within 24 hours. Repeated submissions do not speed it up — a more complete submission does.

The recovery form keeps rejecting me. What else can I try?

Submit again from a device, browser, and network you have previously used with the account, and add more verifiable detail: older passwords, exact email subject lines you sent, folder names in OneDrive, card last-four digits, and linked Xbox or Skype identifiers. Partial answers to many questions beat perfect answers to a few.

Will I lose my OneDrive files?

Not if you recover the account. Files stay in place while it is locked. If the attacker deleted them, OneDrive keeps deleted items in the Recycle Bin for 30 days and supports Files Restore to roll the whole drive back to a point in time — use it as soon as you are back in.

Can I still use my Windows PC while locked out?

Usually yes — your Windows Hello PIN is local to the device and keeps working. What breaks is Store, OneDrive sync, and settings sync. Do not remove the account from Windows while locked out; that can make things considerably harder.

They changed my recovery phone and email. Is the account gone?

No. That is precisely what the manual recovery form exists for. It is judged on knowledge only the real owner would have, not on the current recovery settings.

Should I turn on two-step verification even though it is inconvenient?

Yes — it is the single change that most reliably prevents this happening again. Use the Microsoft Authenticator app rather than SMS, since SMS can be intercepted through a SIM swap.

Still Not Working?

If recovery is repeatedly refused, contact Microsoft support through support.microsoft.com from a working account and explain the account is compromised rather than merely forgotten — that routes it differently. If money was taken, report it to your bank and to your national fraud reporting service in parallel.

Related: recover a hacked email account, review and revoke app access and active sessions, set up two-factor authentication.