How to report an outlook.com email address being used for fraud

Carola 0 Reputation points
2026-05-12T08:35:55.3566667+00:00

My email address was hacked. The hacker set up a very similar looking email address on outlook.com.

They sent out emails from my account and responses were autforwarded to the fraudulent outlook.com email address.

They were then financially scammed.

How can I report and ensure the outlook.com email address is investigated?

Outlook | Web | Outlook.com | Email

Locked Question. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

Answer recommended by moderator
Ferdinand Nanalig 32,835 Reputation points Independent Advisor
2026-05-12T09:10:48.7+00:00

Hi! Let me help you.

Please click on this link.

https://reportfraud.microsoft.com/en-us

Was this answer helpful?

3 people found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. AI answer

    2026-05-12T08:36:11.64+00:00

    Use Outlook.com’s built‑in reporting and Microsoft’s abuse channels so the activity and the fraudulent address can be investigated, and then lock down the hacked account.

    1. Report the phishing/fraud messages in Outlook.com
      • In your Outlook.com mailbox, locate any of the scam or forwarding emails related to this incident.
      • In the message list, select the message.
      • Above the reading pane, select Report > Report phishing.
      • This reports the sender and message to Microsoft’s anti‑abuse systems so filters can be updated and the account can be investigated.
      • Note: Reporting as phishing does not automatically block the sender; to stop further mail from that address, add it to your blocked senders list.
    2. Block the fraudulent Outlook.com address
      • Add the scammer’s Outlook.com address to your blocked senders list so any future messages go straight to Junk.
      • You can also add your own legitimate addresses and trusted contacts to the safe senders list so their messages go directly to your Inbox and are easier to distinguish from look‑alikes.
    3. Report the scam to Microsoft as phishing/abuse
      • If the fraudulent address is sending phishing or scam emails, treat them as phishing:
        • In Outlook.com or Microsoft 365 Outlook, with the suspicious message selected, choose Report > Report phishing from the ribbon.
        • If anyone affected is using a non‑Outlook email client, they can attach the original phishing message (do not forward; attach as a file) and send it to the Microsoft abuse mailbox listed in the phishing guidance.
      • This helps Microsoft’s security team analyze the headers and content and take action on the abusive account.
    4. Secure the hacked Outlook.com/Microsoft account Follow Microsoft’s hacked‑account guidance to ensure the attacker no longer has access:
      • Change the account password to a strong, unique one.
      • Turn on multi‑factor authentication (for example, Microsoft Authenticator).
      • In Outlook.com settings, check:
        • Mail → Rules and delete any rules you don’t recognize (especially ones that forward or move mail).
        • Mail → Forwarding and remove any forwarding addresses you did not set.
      • In the Microsoft account security portal, sign out of all sessions and remove any unknown sign‑in aliases or app permissions.
    5. Advise the financially scammed party
      • The person who lost money should report the fraud to their bank/financial institution and local law‑enforcement, and preserve the scam emails as evidence.
      • They can also report phishing and suspicious behavior in Outlook using the same Report phishing mechanism.
    6. If identity theft is involved
      • If personal or financial information was misused, follow the identity‑theft guidance: file a police report, put a fraud alert on credit reports (where applicable), close or secure affected accounts, and report incidents to the relevant national authority.

    These steps ensure the fraudulent Outlook.com address and messages are reported into Microsoft’s abuse and anti‑phishing systems, while also securing the compromised account and helping victims of the scam.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?