A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
Title: Escalation Request: Verified Account Takeover – 2FA Hijacked – Recovery Blocked Despite Evidence
Hello,
I am requesting escalation of a Microsoft account takeover that has resulted in complete loss of access, despite clear evidence of unauthorised activity.
Summary of incident:
My Microsoft account was compromised following a social engineering incident involving a one-time verification code. Immediately after this, the attacker:
- Changed the password
- Added their own authenticator (2FA)
- Replaced the recovery email with: gh***@get-beamed.lol**
I now have no access to any verification methods.
Key issue:
Microsoft has acknowledged unusual or unauthorised access, yet recovery has been denied on the basis that security details have been changed — the very changes made by the attacker.
This creates a situation where:
- The compromise is recognised
- But remediation is not possible
- Leaving the legitimate account holder permanently locked out
Impact:
- Loss of primary email account
- Loss of OneDrive data (personal files and photos)
- Loss of Xbox account (Gamertag: Ghazi2007)
- Disruption to services linked to this identity
Actions taken:
- Multiple recovery attempts (blocked due to attacker-controlled 2FA)
- Contact with Microsoft support (no resolution)
- Formal report submitted to Action Fraud (UK) with crime reference
- Submission of locked account review form
Concern:
The current process appears unable to distinguish between:
- A legitimate user locked out due to malicious changes
- And an attacker controlling verification methods
In particular, the presence of a clearly unauthorised recovery email domain (get-beamed.lol) should reasonably trigger further scrutiny.
Request:
I am asking for:
- Manual review of this case by a specialist team
- Consideration of historical account ownership and usage patterns
- Guidance on any pathway where 2FA changes made under compromise can be reviewed
I fully appreciate the importance of strong security controls. However, in this instance, the process appears to prioritise system rigidity over resolution of a confirmed compromise.
I would be grateful for any meaningful escalation or direction beyond standard automated recovery responses.
Kind regards,
A Ali