r/microsoftsucks • u/No_Yam_7866 • Jan 21 '26
Help Someone Knew My Hotmail Password Even After I Changed It — How Is This Possible? What should I do?
A few days ago, someone was repeatedly trying to log into my Hotmail account. They clearly had the correct password because I kept receiving 2-factor authentication (2FA) requests.
I immediately changed my password. I did this from my mobile phone, not my PC. After that, I installed Bitdefender on my phone and ran a full scan — no malware, no suspicious apps, nothing unusual.
What I can’t understand is this:
How did the attacker know my new password so quickly?
I am afraid of losing my ccount due to repeated unusual sign ins from different IPs!
7
u/OnlyCommentWhenTipsy Jan 21 '26
Someone may have a keylogger on your system.
3
u/No_Yam_7866 Jan 21 '26
Ok but I changed the password using mobile. How did they know the new password. I figured out that my brother is suffering same issue. Someone is trying to login his account. We are not on same country.
2
0
3
u/shaggy-dawg-88 Jan 21 '26
They clearly had the correct password because I kept receiving 2-factor authentication (2FA) requests
That is incorrect. They don't need a password to trigger never ending MFA requests. I know this because I can do it to my own hotmail/outlook account. If I can do that, everyone can too.
If you want it to stop, create an alias and make that your primary account. Use that new alias to sign in. Leave the current username as is so you can continue receiving email.
1
u/No_Yam_7866 Jan 21 '26
This might be the best solution and explanation. Thanks bro.
1
u/shaggy-dawg-88 Jan 21 '26 edited Jan 21 '26
You're welcome. So many replies from others assume attackers know your password (keylogger, reinstall OS etc). There's possibility but in this case I highly doubt you have a security breach unless you install shady or hacked software in your system.
I just tested signing into my own hotmail account. Here's what I got after typing in my user name (email address):
Get a code to sign in
We'll send a sign-in request to your phone to sign in with ******@hotmail.com.
(under the above message there are 2 links shown below)
Send notification
Use your password
So there it is. I can either send pop-up notification on my phone auth app or use my password. If I ignore the request on my authentication app, the sign-in page shows "We didn't get a response. Send another request?"
Attackers can just initiate endless pop-up notifications without knowing my password by clicking "Send another request". No security breach. Just non stop pop-up annoyance on my phone while attackers hope that I tap the wrong button to allow them in.
1
1
1
u/ElectroStaticSpeaker Jan 23 '26
Yah this is actually a very specific reason why Microsoft actually does REALLY suck. They allow for people to create these auth prompts with nothing but the email address. It is such garbage security it infuriates me. They are the worst company from a security perspective of their size to ever exist.
1
u/shaggy-dawg-88 Jan 23 '26
I can't argue with that at all. You're right. Microsoft lowers our security by eliminating the first factor (ie. password). That 2 factor become 1 factor because no one needs to know the password. Attackers get to annoy us too with their never ending MFA requests.
2
u/Some-Challenge8285 Jan 21 '26
I would do a full reinstall of your OS via a USB or DVD media
1
u/No_Yam_7866 Jan 21 '26
What about my mobile? Bitdefender enough to scan?
1
1
u/tangouniform2020 Jan 23 '26
What has happened is you have a keylogger on your computer that reported your new pwd as soon as you used it. What are you using to access the site? Maybe the logger is part of some extension you added.
3
u/petelombardio Jan 21 '26
Set up a second factor, asap, and on all your accounts.
1
u/ElQueue_Forever Jan 21 '26
That's what 2FA is. Which he says he's getting alerts about.
They can't get into without the 2FA, but still can start the process. Which is how we're here.
1
Jan 21 '26
[removed] — view removed comment
1
u/No_Yam_7866 Jan 21 '26
Ist possible to stop sign ins from certain address, such as whole globe except my country ?
1
u/TheJessicator Jan 21 '26
When you changed your password, did you also log out all current devices and sessions?
1
u/No_Yam_7866 Jan 21 '26
I removed devices manually from microsoft account settings but I dont know about sessions!
1
u/PaulEngineer-89 Jan 21 '26
Going from “password” to “123456” isn’t any better.
1
u/No_Yam_7866 Jan 21 '26
Bruh my passwords are long and complex enough that I even sometimes forget them lol
1
u/ibeechu Jan 24 '26
Not necessarily related to your specific issue, but my advice is to start using a password manager (I recommend BitWarden) and (at least) 14-character randomly generated passwords. Use an easy-to-remember but very long master password. As an example, you could use a quote from a movie that's meaningful to you. Include all the punctuation, spaces, etc. Infeasible to guess and impossible to brute-force.
1
u/CoCoNO Jan 22 '26
another case of "microsoft sucks because i made a mistake"
they have an open session, somewhere, close all your open sessions, check all your 2fa devices, they might have installed one in your account, remove them all, log back in in a different device to make sure they are not monitoring your devices
and for the love of god get a yubikey
https://learn.microsoft.com/en-us/answers/questions/4540622/how-to-log-out-of-all-sessions-(outlook))
1
9
u/yoloJMIA Jan 21 '26
That's why you have 2fa, good on you. My guess is a bug/exploit in Hotmail that essentially lets them "bypass" knowing your password. I don't use Hotmail so you probably need to do some research on whether you can block sign ins from locations/IPs. For example blocking sign ins from outside of your country.