Hi Muhammad,
I’m really sorry this happened to you. Getting locked out of your account like this, especially when it affects your Xbox access and the attacker has already changed the recovery details, must feel incredibly stressful. The AI has given a few recovery paths, but I want to be direct with you here:
If the attacker changed your account’s email/security information and turned on two-step verification, it's unlikely for you to successfully recover that personal Microsoft account.
As you can see, the recovery page itself says the standard account recovery form cannot be used when two-step verification is turned on, and Microsoft’s support guidance says that if you cannot access any of the alternate verification methods, support agents are not allowed to reset the password or change the account details for you.
I know that is a difficult answer to hear, but I want to give you a clear expectation on this. You can still attempt the recovery, but at the same time, assuming the account may be lost and focus on protecting your data.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.