Managing personal Outlook.com account settings, security, and privacy
Can you confirm -
Are these failed attempts? Or did it actually show that they have successfully signed into your account?
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I have two e-mail accounts connected to the same username, one with gmail handle, and one with Hotmail handle. Both with 2FA. One is my primary account and has my personal stuff and connections. The other one has NOTHING and is not in use on any site as far as i am aware. Today i got a warning on suspicious activity, the account without info was compromised and logged in Egypt, USA and Canada within a few minutes of each other.
My worry is: how did they get into my account when i have 2FA, did not approve any login, and the adress is not in use anywhere?
Managing personal Outlook.com account settings, security, and privacy
Can you confirm -
Are these failed attempts? Or did it actually show that they have successfully signed into your account?
AI answer
Two-factor authentication greatly reduces the chance of account compromise, but it does not make it impossible. Based on the context, several explanations are plausible even when 2FA is enabled and the address is rarely used:
What to do now
These steps align with the recommendation to use strong, unique passwords and multifactor authentication everywhere possible, and to treat unfamiliar successful sign-ins as potential compromise that requires immediate password change and security-info review.
References: