How to Recover Your Outlook / Hotmail Account After Being Hacked

    Step-by-step instructions for regaining access to your Outlook or Hotmail account using Microsoft's recovery tools, verifying your identity, and securing your account.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 11 min read

    Losing access to your Outlook or Hotmail — or spotting someone else inside it — is unsettling, but a Microsoft account is usually recoverable. How you get back in depends on whether you're still signed in anywhere, so this guide is built around that. Find your situation, get back in, then lock it down.
    Affiliate disclosure: if you sign up for a paid Proton plan through links on this page, CyberSecurityGuides may earn a commission at no extra cost to you. We only recommend tools we use and trust.

    Act quickly

    The sooner you start, the better your chances. Every hour gives an attacker more time to change your security info and dig in — so begin the moment you can, ideally from a device you've signed in on before.

    Start here: where can you still get in?

    Your strongest route is a Windows PC set up with this account — Windows Hello or a passkey can get you in even if the password was changed. If you don't have that, you'll recover through Microsoft. Try Path 1 first, then fall back to Path 2.

    Don't assume you're locked out

    It's natural to assume the worst — but you may have more of a foothold than you think. If you've got a Windows PC set up with this account, it's very often still signed in — and if it uses Windows Hello or a passkey, you can frequently get back in even if the attacker changed your password. Check that before starting full recovery.

    Path 1 — Recover from your Windows PC (your best hope)

    If you have a Windows laptop or PC set up with this Microsoft account, that's your strongest route back in — and here's the good news: if you unlock Windows with a PIN, fingerprint or face, you've already set up Windows Hello. Most Windows users have, often without realising it. Hello (and passkeys) are tied to the device itself, so they let you sign in and reset your password even if the attacker changed it — something they can't do from afar. That could be exactly what gets you back in.
    1

    Sign in with Windows Hello or a passkey

    Open a browser on your PC and go straight to account.microsoft.com. When it asks you to sign in, choose Windows Hello (or a passkey) and verify with your PIN, face or fingerprint. Because Hello is tied to this device, it signs you in without the password — even if the attacker changed it.

    If your PC's already signed in, even better — you're in. If you can't get in on the PC at all, use Path 2.

    login.microsoftonline.com
    Microsoft

    Sign in

    No account? Create one!

    Can't access your account?

    Next

    Microsoft sign-in: enter your email, choose "Use your face, fingerprint, PIN or security key", enter your Windows Hello PIN, then the signed-in account.microsoft.com dashboard

    Can't get in on your PC?

    No Windows PC set up with this account, Windows Hello isn't an option, or you simply can't sign in here? Don't keep trying — skip straight to Path 2 and recover through Microsoft's account recovery instead. Bear in mind, too, that a more capable attacker may have removed your passkey or Windows Hello from the account to close this route off — if that's happened, Path 2 is your way back.
    Recover through Microsoft (Path 2)
    2

    Change your password

    You're already in your account — now reset your password:

    1. Open the Security tab, then Manage how I sign in
    2. Under Ways to prove who you are → Enter password, choose Change password
    3. Because Windows Hello already verified you, it won't ask for your old password — just enter a strong new one, reenter it, and Save

    Changing it stops the attacker signing in with the old password.

    Microsoft accountY
    Y

    Your name

    View my benefits

    Account
    Your info
    Subscriptions
    Devices
    Security
    Privacy

    Account

    Security

    Update your password and sign-in options

    Devices

    See where you're signed in

    account.microsoft.com: Security tab, Manage how I sign in, Ways to prove who you are, Change password, then a New password and Reenter password form with Save

    3

    Remove any sign-in methods you don't recognise

    While they were in, the attacker may have quietly added their own email, phone or app under Ways to prove who you are — a backdoor to reset your password all over again later. Clear it out:

    1. On the Ways to prove who you are list, read every entry carefully
    2. For anything you don't recognise — an unfamiliar email, phone number, authenticator or passkey — choose Remove

    Leave only the methods you set up yourself. This shuts the door the attacker propped open.

    Security

    Change password

    Change ›

    Two-step verification

    Manage ›

    Ways to prove who you are

    Check this list carefully and remove anything you don't recognise.

    Enter passwordUp to date
    Email a codey•••@outlook.com
    Text a code••• ••• ••••
    Email a code attacker@mail.ru Added today — not you?
    View activity
    Remove

    Ways to prove who you are: an unrecognised attacker-added email method flagged and removed

    4

    Sign out everywhere

    Changing your password doesn't always end the attacker's existing sessions, so force everyone out:

    1. On the Security page, scroll down to the Sign out everywhere section
    2. Click Sign out everywhere and confirm

    This signs you out of every browser, app and device your account is used on, where possible, within 24 hours — you'll just sign back in on yours. While you're there, glance over your recent sign-in activity for anything unfamiliar.

    Additional security

    To increase the security of your account, remove your password or require two steps to sign in.

    Passwordless account

    OFF

    Turn on

    Two-step verification

    ON

    Turn off

    App passwords

    Create a new app password

    Sign out everywhere

    If you think someone might have unauthorized access to your account, we can protect you by signing you out from your trusted devices. You'll be signed out of browsers, apps and anywhere else your account is used to sign in, where possible, within 24 hours.

    Sign out everywhere

    Windows Hello lets you sign in to your device apps, online services and networks using your face, fingerprint or a PIN.

    Reset Windows Hello on all of my Windows devices

    account.live.com security page scrolled to the Sign out everywhere section, then a confirm dialog

    You're not out of the woods yet

    Locking the attacker out is only half the job. While they were in, they may have set up quiet ways back — mail forwarding, inbox rules that hide replies, connected apps, or changed security info. Before you move on, check exactly what they touched and undo it.
    See the signs your Outlook is compromised

    Path 2 — Recover through Microsoft

    No device has your account, or the attacker changed the password? You'll recover through Microsoft's account recovery, which weighs lots of signals to confirm it's really you. The more familiar the device and the more details you can provide, the better your odds.
    1

    Start on a device you've used before

    Before you go near the recovery page, pick up a device and browser you've signed in with before — ideally on your home network. Microsoft trusts familiar devices, browsers and networks far more, and that can be the single biggest factor in getting back in.

    2

    Recover your account and verify it's you

    Now recover the account and prove it's you. Microsoft will offer whatever verification options are on the account — try any of them you can still access:

    1. Go to account.live.com/password/reset and enter your Outlook, Hotmail or Live address
    2. On Verify your identity, Microsoft asks for a code from your authenticator app first — if you have it, enter it and continue
    3. If not, choose Use a different verification option, then pick Email a code or Text a code, confirm the address or number and select Get code
    4. Enter the code Microsoft sends you and select Next

    If you ever generated and saved your 25-character recovery code (Microsoft offers one when you turn on extra security), that's another way in — choose Use a different verification option and enter it. An authenticator app, passkey or recovery code is the fastest and strongest; use whichever you still control.

    account.live.com/password/reset
    Microsoft

    Recover your account

    Enter your email, phone, or Skype name to recover your account.

    Next

    account.live.com password reset: enter your email, choose a verification method, enter the security code, then verified

    If you can't pass any of these

    This is the last resort, and it doubles as your only support channel. If you keep choosing I don't have any of these on the verification screens — and answer no when asked for your 25-character recovery code — Microsoft eventually drops you onto its account recovery form, shown below.

    On the first page you enter the account you've lost, a contact email Microsoft can reply to (use your new inbox) and a captcha. Microsoft emails a code to that contact address to confirm it, then walks you through a few pages of identity questions — your name and birth date, old passwords, which Microsoft products you've used, and the contacts and subject lines of emails you've recently sent. Fill in as much as you can, even rough guesses, and submit it for a real person to review.

    account.live.com/acsr
    Microsoft|AccountSign in

    Recover your account

    What Microsoft account are you trying to get back into?

    Email, phone, or Skype name

    Note: If you've turned on two-step verification, you can't recover your account this way.

    Where should we contact you?

    Enter an email address that's different from the one you're trying to recover.

    Contact email address

    If you don't have another email address, create a new one with Outlook.com

    Enter the characters you see

    New | Audio

    RHX WDS4
    Next

    Microsoft's account recovery form (account.live.com/acsr): enter the lost account, a contact email and a captcha, then submit for manual review

    Important: two-step verification blocks this form

    If two-step (two-factor) verification was switched on for the account, this recovery form won't work — Microsoft says so on the form itself.

    If you still can't get in

    At this point you've genuinely exhausted every way back into the account — a still-signed-in device, every verification option, and the recovery form itself. You can resubmit the form once or twice with more detail (answer from a device and location you've used before), but recovery is never guaranteed, and once you truly can't prove ownership, Microsoft's decision is final. If it doesn't come through, don't get stuck here — the priority now is to limit the damage and rebuild on a fresh, secure inbox, and the next steps walk you through exactly that.

    If recovery isn't working

    Tried in earnest and still hitting a wall? Jump to the steps for limiting the damage and rebuilding on a more secure inbox.
    What to do if you can't recover it
    3

    Set a strong new password

    Recovery ends by having you set a new password — make it long (16+ characters), unique to this account, and saved in a password manager. To change it again at any time, go to Security → Manage how I sign in (shown below):

    1. Open the Security tab, then Manage how I sign in
    2. Under Ways to prove who you are → Enter password, choose Change password
    3. Enter your new password, reenter it, and Save

    A fresh password the attacker doesn't know locks them out of the front door.

    Microsoft accountY
    Y

    Your name

    View my benefits

    Account
    Your info
    Subscriptions
    Devices
    Security
    Privacy

    Account

    Security

    Update your password and sign-in options

    Devices

    See where you're signed in

    account.microsoft.com Security to Manage how I sign in to Change password: enter and reenter a new password, then Save

    4

    Remove any sign-in methods you don't recognise

    While they had access, the attacker may have quietly added their own email, phone or app under Ways to prove who you are — a backdoor to reset your password all over again later. Clear it out:

    1. Open Security → Manage how I sign in and read every entry under Ways to prove who you are
    2. For anything you don't recognise — an unfamiliar email, phone number, authenticator or passkey — choose Remove

    Leave only the methods you set up yourself. This shuts the door the attacker propped open.

    Security

    Change password

    Change ›

    Two-step verification

    Manage ›

    Ways to prove who you are

    Check this list carefully and remove anything you don't recognise.

    Enter passwordUp to date
    Email a codey•••@outlook.com
    Text a code••• ••• ••••
    Email a code attacker@mail.ru Added today — not you?
    View activity
    Remove

    Ways to prove who you are list with an unfamiliar method being removed via a confirmation dialog

    5

    Sign out everywhere

    Resetting your password doesn't always end the attacker's existing sessions, so force everyone out:

    1. On the Security page, scroll down to the Sign out everywhere section
    2. Click Sign out everywhere and confirm

    This signs you out of every browser, app and device the account is used on, where possible, within 24 hours — you'll just sign back in on yours. While you're there, glance over your recent sign-in activity for anything unfamiliar.

    Additional security

    To increase the security of your account, remove your password or require two steps to sign in.

    Passwordless account

    OFF

    Turn on

    Two-step verification

    ON

    Turn off

    App passwords

    Create a new app password

    Sign out everywhere

    If you think someone might have unauthorized access to your account, we can protect you by signing you out from your trusted devices. You'll be signed out of browsers, apps and anywhere else your account is used to sign in, where possible, within 24 hours.

    Sign out everywhere

    Windows Hello lets you sign in to your device apps, online services and networks using your face, fingerprint or a PIN.

    Reset Windows Hello on all of my Windows devices

    Security page Sign out everywhere section with a confirmation dialog; signs out all devices within 24 hours

    Don't stop at the password

    Getting back in is a big first step — but it doesn't undo what the attacker set up while inside. Forwarding rules, hidden inbox rules, connected apps and tampered security info can all quietly let them back in. Take a moment to check what they changed.
    See the signs your Outlook is compromised

    Troubleshooting & FAQs

    Which path should I use?
    If Windows, the Outlook app or Outlook.com still has your account and you know your password, use Path 1 — it's fastest. If you're locked out or the password's been changed, use Path 2 to recover through Microsoft.
    The hacker changed my password — can I still get in from a signed-in session?
    Not with the password alone — Microsoft needs your current password to change it from a signed-in session, unless you verify with Windows Hello or a passkey (that's Path 1). Otherwise use Path 2 (account.live.com/password/reset); a device that's still signed in can still help you verify there.
    Microsoft won't verify me on the recovery page.
    Recover from a device, browser and network you normally use, and provide as much detail as you can. If it still fails, use the account recovery form and try again after a day or two — Microsoft weighs many signals, not just your current security info.
    The attacker changed my recovery phone and email — can I still recover?
    Sometimes, but it's an uphill battle. The account recovery form lets you prove ownership with other details — old passwords, email subjects, frequent contacts. If you can't satisfy Microsoft's checks, though, it may not be recoverable.
    How long does the account recovery form take?
    Microsoft usually emails a decision to the contact address you provide within 24 hours. If it's denied, you can resubmit with more detail.

    What to do next

    If you got back in ✅

    You've reset your password and signed the attacker's sessions out — now make sure they left nothing behind and can't walk straight back in.

    Find out what they touched

    See exactly what an intruder changes — rogue forwarding, hidden rules, connected apps and more — so you know what to undo.
    Spot the indicators of compromise

    Lock it down properly

    Turn on two-step verification, fix your security info and close every gap so this doesn't happen again.
    Secure your Outlook / Hotmail account

    If you couldn't recover it ⚠️

    If recovery genuinely isn't working, the account may be gone for good — and the attacker may still control it. Start by rebuilding on a fresh, secure inbox: you'll need a working email address in hand before you can move your other accounts off the lost one.
    So rebuild — somewhere this is far less likely to happen again. You've just seen how a free, big-tech inbox works: it's a giant target, and recovery is a black box that leaves you stranded the moment the attacker controls your security info. Proton Mail is built the opposite way. It's end-to-end encrypted and based in Switzerland under some of the world's strictest privacy laws, so not even Proton can read your mail. You hold the keys, recovery runs through methods you control, and there are no ads mining your messages — an inbox an attacker can't silently reset their way into.

    Why this keeps happening on free email

    The full case for moving to an encrypted, privacy-first inbox — and how its recovery and protections make a quiet takeover far harder.
    Why switch to Proton Mail
    Proton Unlimited

    Rebuild on an inbox that's private by default

    Proton Mail, VPN, Pass and Drive in one encrypted, Swiss-based plan — end-to-end encrypted, no ads, no tracking.

    • End-to-end encrypted
    • Swiss-based, no ads
    • One plan, every app
    With your new inbox set up, now cut the lost account loose and contain the fallout:
    • Move your other accounts over. Anywhere you used the old address to sign in or to reset passwords — banking, shopping, social media — change that password and set your new Proton address as the account email and recovery contact, so the lost inbox can't be used to take them too.
    • Warn your contacts. Tell friends, family and colleagues that messages from the old account may not be you, and to ignore any requests for money, codes or links.
    • Watch for misuse. Turn on alerts where you can and keep an eye on anything that was tied to the old address.

    A different inbox affected?

    The recovery routes here work for any provider — see the universal walkthrough.
    Recover any email account

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Email Security