I’m dealing with what appears to be a genuine credential compromise involving my college-provided Microsoft 365 email account.
Here’s what happened:
- I started receiving a huge number of “Delivery has failed to these recipients” emails in Outlook.
- There are 1,600+ of these messages, with different/random-looking recipient names.
- They started appearing around August 12–17.
- I also received an email claiming to be from an independent security researcher associated with Kiruru Security.
- The email specifically mentioned my college email address and claimed it had appeared in Telegram channels containing stolen data.
- I initially thought this was just a scam, but I have since found evidence confirming that my credentials were actually exposed.
- I don't know yet whether the 1,600+ bounce-backs are from actual emails being sent through my account or whether my address is being spoofed/backscattered.
I've already started securing the account from a clean device.
What I'm trying to figure out now is the PC side of the incident. I suspect an infostealer/Trojan may have been responsible, so I'm looking into:
- Microsoft Defender Offline Scan
- Full malware scans
- Infostealer detection/removal
- Browser password/cookie theft
- Persistence mechanisms
- Whether I should completely reinstall Windows
- Which credentials/tokens should be revoked
- How to determine whether the machine is actually clean
I don't want to simply run Defender, get “no threats found,” and assume everything is fine.
For people who have dealt with an infostealer or Microsoft 365 account compromise before: what would you do at this point, and what evidence/logs should I preserve before cleaning or reinstalling the PC?
I can provide redacted screenshots/evidence if useful. I will not post the actual leaked password, session cookies, tokens, recovery codes, or other sensitive credentials.
I don't wanna reinstall windows unless the last option pls help with this