Account recovery for a stolen Microsoft/Xbox account where the hacker has changed the recovery email and phone can only be done through Microsoft’s official self-service recovery tools. Support agents cannot override these processes or manually return access to the account.
Follow these steps:
- Try the Sign-in Helper first
- Go to the Sign-in Helper tool mentioned in the article: Sign-in Helper.
- Follow the prompts to see if any existing security options can still be used to verify identity.
- Use the Microsoft account recovery form If normal reset options do not work and there is no access to the old recovery email or phone:
- Carefully read the guidance in Help with the Microsoft account recovery form.
- Then submit the recovery request via the account recovery form: Recover account.
- Before filling the form, gather as much information as possible about the account, including:
- Old passwords used on the account.
- Exact subject lines of emails sent from the account (if Outlook/Hotmail was used).
- Names of contacts or Skype IDs if Skype was used.
- Xbox console hardware ID from a console that was frequently used with this account.
- Details of Microsoft Store purchases (like Sea of Thieves), such as approximate purchase date and payment method.
- Answer every question on the form as completely and accurately as possible. Wrong answers do not count against the request, but missing information reduces the chance of success.
- Provide a different, working email address (any current email that can be accessed) so Microsoft can send the result of the recovery attempt.
- After submitting the form
- Microsoft will review the request and send the result to the working email within 24 hours.
- If the account is verified, instructions to sign back in will be sent.
- If the account cannot be verified, it is allowed to try again up to two times per day, each time improving the information provided.
- Important limitations
- If two-step verification was enabled on the stolen account and there is no access to any of the verification methods, Microsoft support cannot help beyond the automated recovery form. They are not allowed to send password reset links or change account details.
- If the hacker has fully replaced the security info and the recovery form does not accept the evidence provided, there is no alternative manual recovery path.
If access is eventually restored, immediately:
- Review and update all security info (emails, phone numbers, sign-in methods).
- Follow the guidance in How to help keep your Microsoft account safe and secure to reduce the risk of future compromise.
References:
- Help with the Microsoft account recovery form
- Troubleshoot Microsoft verification code issues
- my microsoft account has been compromised - Microsoft Q&A
- How do I send an email to Microsoft about my account being hacked and taken over by <removed> ? - Microsoft Q&A
- Entraron a mi cuenta de microsoft y cambiaron el gmail y contraseña - Microsoft Q&A
- Me robaron una cuenta - Microsoft Q&A