That is a possibility. They may also check whether you have an active payment card linked to your account and use it to make unauthorized purchases.
If you have one associated with the account. You'll need to contact your financial institution/bank directly to dispute it, and they may process a refund, as this would be considered a fraudulent charge.
Also, I would recommend reaching out to Microsoft Support immediately as they can possibly "Suspend" the account permanently once they have confirmed that the account can no longer be recovered in order to prevent the hacker from using the account:
Type "Microsoft 365 sign-in problem" > Click "Get Help" > Scroll down and select the option "Sign in to contact Support" > Microsoft 365 and Office > Billing and Account Profile Questions > Confirm > then select "Chat with a support agent in your web browser"
Best regards,
Darhyl