Follow these steps immediately to protect the Outlook/Microsoft account that is linked to Xbox and Minecraft:
- Scan the PC for malware
- Before changing anything else, run a full antivirus scan to remove any malware that may have stolen the sign-in info.
- On Windows 10/11, use Windows Defender:
- Select Start.
- Search for Windows Defender and open it.
- Follow the prompts and run a full scan.
- Make sure the antivirus is updated and set to scan regularly.
- Secure the Microsoft account (Outlook email)
- Go to the Microsoft account Security basics page: https://account.microsoft.com/security.
- Sign in with the Outlook.com address that belongs to the account.
- Select Change password and set a new, strong password that has never been used on any other site.
- If sign-in fails or the password was changed by the hacker, follow the hacked-account recovery steps:
- Use the sign-in helper: Start.
- Or follow the guide: How to recover a hacked or compromised Microsoft account.
- Review recent sign-in activity
- On the Security basics page, select Review activity.
- On the Recent activity page, look for sign-ins or actions that are not recognized.
- For anything in Unusual activity, expand it and choose This wasn’t me.
- For anything in Recent activity that is not recognized, expand it and choose Secure your account.
- If sign-in is not possible because the hacker changed the password, follow the steps in When you can’t sign in to your Microsoft account from the unusual-activity article.
- Sign out everywhere and remove hacker access
- From the Microsoft account security pages, use the option to sign out everywhere (see “How to sign out everywhere” in the security article) so the hacker is kicked off all devices.
- Check for:
- Connected accounts and remove anything that is not recognized.
- Forwarding and automatic replies in Outlook.com and remove any that were added by the hacker.
- If Outlook rules or forwarding were set up to steal mail, delete those rules and forwarding addresses.
- Add and update security info
- On Advanced security options for the Microsoft account:
- Select Add a new way to sign in or verify.
- Add a phone number or another email that is controlled.
- Make sure all security contact info (phone numbers, emails) is up to date so recovery is possible if this happens again.
- On Advanced security options for the Microsoft account:
- Treat the Discord/Minelink incident as a scam
- Any form or link from the Minecraft server or Discord that asked for Microsoft/Outlook/Xbox sign-in details was likely a phishing attempt.
- Do not reuse that link or form, and do not enter the Microsoft account password on non-Microsoft sites.
- Watch for more scams and phishing
- If strange emails appear asking to “upgrade mailbox,” “verify account,” or threatening deactivation in 24–48 hours, treat them as phishing.
- Legitimate Microsoft security emails about unusual sign-ins come from ******@accountprotection.microsoft.com.
- If the email is not from that domain or asks for payment or passwords, do not click links or reply.
If the account recovery form or hacked-account guide does not allow recovery and the security info has been fully replaced by the attacker, there may be no further technical way to get that Microsoft account back. In that case, follow the official hacked-account guide and, if needed, contact product-specific support (for example, Minecraft support) about game entitlements.
References:
- How to recover a hacked or compromised Microsoft account
- What happens if there's an unusual sign-in to your account
- Hello , welcome to Account help & learning
- How to help keep your Microsoft account secure
- Help protect your Outlook.com email account
- What to do if your email address is leaked
- Cannot Access Microsoft Account After Hacker Changed Email, Advice Needed - Microsoft Q&A
- hello my email was (Moderator note: PII removed)@icloud.com and now its (Moderator note: PII removed)@jerkoffmail.com can please someone help me and the team change it my username in xbox is (Moderator note: PII removed) please help me team and change it - Microsoft Q&A
- Hacker set up continuous draft ransomware email - Microsoft Q&A
- I think I'm being scammed, but I want to make sure. (Though I may be in the wrong place.) - Microsoft Q&A
- Is this legit email also? - Microsoft Q&A