Jump to content

So last weekend I recieved multiple notifications regarding my Microsoft account. This is an account I've had since the OG days of Xbox 360... Somehow.. I'm not sure how but someone had gained access and spent 500+ dollars. As soon as I seen the notifications, I got access and changed password and enabled 2FA along with removing all logins/devices associated.. They continued to try to gain access (no longer able too) which then in turn locked my microsoft account. I then appealed to Microsoft about the charges and locking of my account. Come the next night I recieved an email from Microsoft stating that due to 2FA being active my account is locked for good. Years gone.. Thousands of Hours gaming gone... Thousands of dollars spent gone... I'm aware that I should've had my account more secure well before this but due to normal life and being a father I never pushed to take the time to do it. I learned after that through the linked accounts they were able to get access too my Epic games account and they completely took it over, changed email, password and display name..My recommendation is secure properly.. hoping someone can learn from my experience.. on a side note during securing my other accounts I lost access to my PS account due to 2FA (also mister on my part). But luckily PS had a program to solve this and within 5 minutes I was back in. So once again SECURE YOUR ACCOUNT... Thanks for listening.

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/
Share on other sites

Link to post
Share on other sites

Sorry for your loss, but yeah lesson learned.

Expensive lesson :<

There is approximately 99% chance I edited my post

Refresh before you reply

__________________________________________

ENGLISH IS NOT MY NATIVE LANGUAGE, NOT EVEN 2ND LANGUAGE. PLEASE FORGIVE ME FOR ANY CONFUSION AND/OR MISUNDERSTANDING THAT MAY HAPPEN BECAUSE OF IT.

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16648869
Share on other sites

Link to post
Share on other sites

That sucks man. I don't even run torrent on my computers anymore. Shit I don't even look at porn on my computers anymore haha. Not because of my wife, but I have zero trust in the intertoobz.

AMD R9 9900X | Thermalright FW Pro Black, 3x TL-B12E | Asus Strix X670E -F | 64GB G.Skill 6000C26
Zotac 4070 Ti Trinity OC | WD SN850, SN850X, 2x SN770 | Seasonic Vertex GX-1000 | ProArt PA602
Adcom GFP-345, Adcom GFA-555, S.M.S.L D1+PS100, Cerwin-Vega! CLSC-15, Monster HDP-1800
Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16648891
Share on other sites

Link to post
Share on other sites

2 hours ago, Asams452 said:

Come the next night I recieved an email from Microsoft stating that due to 2FA being active my account is locked for good. 

This doesn't make sense to me. You enabled 2FA and that made your account irrecoverable when someone tried, unsuccessfully, to log in? 🤨

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16648929
Share on other sites

Link to post
Share on other sites

Sounds like u got a remote desktop trojan It's the only way to bypass 2fa like this,  uninstall remote desktop on your computer.  I would take this very seriously. 
a Remote Desktop Trojan lets a user have full access to your pc like they were standing in front of it but it doesnt show what theyre doing.  They can buy things and auto fill out your info. 
You should also change all your passwords something to at least 20 characters with numbers and symbols.  If someone advanced in pc's gets remote desktop access they can install malware into ur CPU, GPU, BIOS, they can turn malwarebytes into a killbot.  

UserBenchmarks: Game 417%, Desk 121%, Work 464%
CPU: Intel Core i5-13600K - 123.4%
GPU: Nvidia RTX 5080 - 354.6%
SSD: WD Blue SN570 NVMe PCIe M.2 1TB - 298.3%
RAM: Corsair Vengeance LPX DDR4 3200 C16 2x16GB - 109.7%
MBD: MSI PRO Z690-A DDR4
Monitor: X32 4k 480hz OLED

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16648946
Share on other sites

Link to post
Share on other sites

3 hours ago, Asams452 said:

So last weekend I recieved multiple notifications regarding my Microsoft account. This is an account I've had since the OG days of Xbox 360... Somehow.. I'm not sure how but someone had gained access and spent 500+ dollars. As soon as I seen the notifications, I got access and changed password and enabled 2FA along with removing all logins/devices associated.. They continued to try to gain access (no longer able too) which then in turn locked my microsoft account. I then appealed to Microsoft about the charges and locking of my account. Come the next night I recieved an email from Microsoft stating that due to 2FA being active my account is locked for good. Years gone.. Thousands of Hours gaming gone... .

I'm a bit confused, so 2FA was still active on a method you had control over (i.e. Phone number, Microsoft Authenticator)? Doesn't make sense to me how your "locked out" account is gone for good if you are still in control of the 2FA methods. It should just be a matter of waiting for the lockout to clear.

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 18.3) | iPhone 15 (iOS 18.3.1) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16648949
Share on other sites

Link to post
Share on other sites

6 minutes ago, Chree said:

Sounds like u got a remote desktop trojan It's the only way to bypass 2fa like this,  uninstall remote desktop on your computer.  I would take this very seriously. 
a Remote Desktop Trojan lets a user have full access to your pc like they were standing in front of it but it doesnt show what theyre doing.  They can buy things and auto fill out your info. 
You should also change all your passwords something to at least 20 characters with numbers and symbols.  If someone advanced in pc's gets remote desktop access they can install malware into ur CPU, GPU, BIOS, they can turn malwarebytes into a killbot.  

Was done while PC was off. I don't get an excessive amount of gaiming time lately. Plus sorry if it was clear before.. activated 2FA after to make sure no one else could access again no matter if they had password or not.

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16648950
Share on other sites

Link to post
Share on other sites

3 minutes ago, BlueChinchillaEatingDorito said:

I'm a bit confused, so 2FA was still active on a method you had control over (i.e. Phone number, Microsoft Authenticator)? Doesn't make sense to me how your "locked out" account is gone for good if you are still in control of the 2FA methods. It should just be a matter of waiting for the lockout to clear.

Yes I have full control but Microsoft themselves locked the account or "suspended" in their terms. Indefinitely 

Screenshot_20250207_212119_Gmail.jpg

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16648951
Share on other sites

Link to post
Share on other sites

Check your  email sign in activity I am an actual pro gamer and have brute force bots trying to crack all my passwords all the time. 

image.thumb.png.8ae2a13e7d3972c074221f37d9036c0f.png

4 minutes ago, Asams452 said:

Was done while PC was off. I don't get an excessive amount of gaiming time lately. Plus sorry if it was clear before.. activated 2FA after to make sure no one else could access again no matter if they had password or not.

 

UserBenchmarks: Game 417%, Desk 121%, Work 464%
CPU: Intel Core i5-13600K - 123.4%
GPU: Nvidia RTX 5080 - 354.6%
SSD: WD Blue SN570 NVMe PCIe M.2 1TB - 298.3%
RAM: Corsair Vengeance LPX DDR4 3200 C16 2x16GB - 109.7%
MBD: MSI PRO Z690-A DDR4
Monitor: X32 4k 480hz OLED

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16648953
Share on other sites

Link to post
Share on other sites

48 minutes ago, SpaceGhostC2C said:

This doesn't make sense to me. You enabled 2FA and that made your account irrecoverable when someone tried, unsuccessfully, to log in? 🤨

Correct cause to this day there are attempts to log in. I'm assuming it flagged a "suspicious" activity (way too late) which in turn caused them to lock account

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16648955
Share on other sites

Link to post
Share on other sites

Just now, Chree said:

Check your  email sign in activity I am an actual pro gamer and have brute force bots trying to crack all my passwords all the time. 

image.thumb.png.8ae2a13e7d3972c074221f37d9036c0f.png

 

Can get email notifications on my phone but can't see full emails due to that email being permanently "suspended". 

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16648958
Share on other sites

Link to post
Share on other sites

8 minutes ago, Asams452 said:

Yes I have full control but Microsoft themselves locked the account or "suspended" in their terms. Indefinitely 

Screenshot_20250207_212119_Gmail.jpg

I'm surprised they have such a weird policy. Even if you've resecured your account and the unauthorized access is forced out, Microsoft doesn't trust the account enough to allow it to continue existing. That being said, it's a suspension not a deletion so your data based on their wording, still exists on their servers. It's just not accessible to you, or anyone else.

 

I feel like if this happened in Europe, the EU would like to have a word since GDPR is really strict on stuff like this. 

 

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 18.3) | iPhone 15 (iOS 18.3.1) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16648963
Share on other sites

Link to post
Share on other sites

1 minute ago, Asams452 said:

Can get email notifications on my phone but can't see full emails due to that email being permanently "suspended". 

I would keep trying to recover the email with tickets.   You'll need a crazy amount of proof it was yours though. 

 

UserBenchmarks: Game 417%, Desk 121%, Work 464%
CPU: Intel Core i5-13600K - 123.4%
GPU: Nvidia RTX 5080 - 354.6%
SSD: WD Blue SN570 NVMe PCIe M.2 1TB - 298.3%
RAM: Corsair Vengeance LPX DDR4 3200 C16 2x16GB - 109.7%
MBD: MSI PRO Z690-A DDR4
Monitor: X32 4k 480hz OLED

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16648964
Share on other sites

Link to post
Share on other sites

On 2/8/2025 at 3:28 AM, BlueChinchillaEatingDorito said:

I'm surprised they have such a weird policy. Even if you've resecured your account and the unauthorized access is forced out, Microsoft doesn't trust the account enough to allow it to continue existing. That being said, it's a suspension not a deletion so your data based on their wording, still exists on their servers. It's just not accessible to you, or anyone else.

 

I feel like if this happened in Europe, the EU would like to have a word since GDPR is really strict on stuff like this. 

 

imagine someone breaking in your car, then BMW just "suspends it permanently" for "security reasons" xD

 

this seems indeed very strange (and yes i know Microsoft accounts are god awful regarding security etc, that's why i don't have one lol) 

The direction tells you... the direction

-Scott Manley, 2021

 

 

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16650602
Share on other sites

Link to post
Share on other sites

5 minutes ago, Mark Kaine said:

imagine someone breaking in your car, then BMW just "suspends it permanently" for "security reasons" xD

 

this seems indeed very strange (and yes i know Microsoft accounts are god awful regarding security etc, that's why i don't have one lol) 

BMW: Yes sir, I understand you recovered your car after it was stolen, but for security reasons both your heated seats and iDrive will no longer function. Be grateful we managed the validate the airbags. 

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 18.3) | iPhone 15 (iOS 18.3.1) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16650605
Share on other sites

Link to post
Share on other sites

If you have banking statement, you can easily prove you own the account.

Problem with Microsoft, is it's all outsourced to AI and 3rd World countries.

You'll need to get someone actually talk to you, which comes handy with Twitter. For some reason, most people have better luck there.

Tag Xbox, Microsoft and Phil Spencer. Post your tweet here and some people will probably upvote/like it

Link to comment
https://linustechtips.com/topic/1600638-i-was-hacked/#findComment-16652637
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×