Hi! If you can still access your emails, you should first eliminate the vulnerability the hacker found to break into your account, and then change your password and other security information.
I believe the hacker may be using your computer. When you have a hacked account, it's recommended to format your Windows, as it may contain malware that the hacker could use to break into your account again.
Even if you use an antivirus, some viruses may not be identified or eliminated because they can masquerade as system processes and services.
Go to Windows Settings > System > Recovery > Reset this PC > Choose the Cloud Restore option; if it gives an error, choose the other option.
When you reset your computer, you should be able to access your account on another device. Go to https://account.microsoft.com/account > Go to Security > Change:
- Password
- Authenticator
- Generate new backup codes
- Enable all security methods
- Remove all devices and leave only the current one at https://account.microsoft.com/devices