Follow these steps in order:
- Secure the account
- Go to the Security basics page and sign in with the new password.
- Select Review activity and check the Recent activity and Unusual activity sections. For any sign-in that is not recognized, expand it and choose This wasn’t me or Secure your account so Microsoft can help lock out the attacker.
- Still on Security basics, select Change password and set a new, strong password that has not been used before.
- Confirm the account is still valid
- If any sign-in page or app shows messages like “We couldn’t find an account with that username” or “account doesn’t exist”, use the Sign-in Helper tool or the Recover your account flow described in the next step.
- Run the account recovery flow if sign-in keeps failing
- If the username and password are correct but sign-in still fails, use the Recover your account page: Recover your account.
- Enter the email address, phone number, or Skype name.
- Make sure the domain and spelling are correct (for example, .com vs .co.uk, and name spelling such as rachel vs rachael).
- If one alias is not recognized, try another alias or phone number that was ever added to the account.
- Follow the prompts to receive and enter a security code, then set a new password.
- If you still see “We couldn’t find an account with that username” after this, use the Contact support option on that page to reach a support advocate and explain that the username has stopped working.
- Check for hacked-account changes once signed in
- If sign-in succeeds but email is not coming through, treat the account as compromised:
- Follow the steps in How to recover a hacked or compromised Microsoft account:
- First, run a full antivirus scan on every device used with this account.
- Then change the password again using change your password.
- Check Outlook settings for:
- Suspicious inbox rules (for example, rules that move or delete mail automatically).
- Any unknown forwarding addresses.
- Automatic replies that were not set.
- Also review connected accounts, forwarding, and automatic replies using the links in the hacked-account article and remove anything not recognized.
- Follow the steps in How to recover a hacked or compromised Microsoft account:
- Verify email delivery
- After cleaning the account:
- Send a test email to the address from a different account and confirm it arrives.
- If messages still do not appear, re-check rules and forwarding, and confirm the account is not over its storage quota (if the mailbox is full, new mail will not arrive).
- Inform contacts and monitor
- Inform important contacts (from another email or channel) that the account may have been hacked so they can ignore suspicious messages.
- Periodically check the Recent activity page to ensure there are no new unusual sign-ins.
If any step fails (for example, recovery keeps failing or the account is reported as non-existent), use the Sign-in Helper or Contact support options in the recovery pages to escalate.
References: