Using New Outlook on Windows for academic communication and scheduling
Dear @key,
I understand how alarming it is to discover that thousands of phishing emails have been sent from your account, and it is completely understandable to feel anxious when you continue to see delivery failure notices even after changing your password and setting up the Microsoft Authenticator app.
The core issue you are experiencing is that changing your password does not automatically terminate active sessions or delete hidden rules that hackers configure while they have access to your account.
The reason you are still seeing bounce-back failure messages (NDRs) without anything appearing in your "Sent" folder is due to two common post-compromise tactics:
- Malicious Inbox Rules: Attackers frequently create background rules that automatically send out emails and immediately delete the record from your Sent Items folder to hide their tracks.
- Delayed Mail Queues: The mail servers may still be processing and rejecting the massive backlog of spam messages that the hackers queued up before you changed your password.
To completely evict the hackers and ensure your account is 100% secure, please follow these concrete recovery steps:
Step 1: Force-Terminate All Active Sessions ("Sign Out Everywhere")
Even though you changed your password, the hacker may still hold an active browser cookie or an authorized "App Password" token that bypasses your new password and MFA.
- Go to your My Account
- Scroll down and click on Security info options.
- Look for the "Sign out everywhere" section and select it. This will forcefully invalidate all active login tokens worldwide within 24 hours, kicking the hacker out of Exchange Online entirely.
- On the same page, check the "Passwords" section and delete any unauthorized app passwords created by the attackers.
Step 2: Audit and Delete Malicious Inbox Rules
You must clear out the hidden automations the hacker left behind:
- Log into Outlook on the web (OWA) via your browser.
- Click the Settings (gear icon) in the top right corner > select Mail > click Rules.
- Thoroughly review the list. Delete any rules you did not create especially rules designed to delete messages or move items containing keywords like "phish," "spam," "undelivered," or "blocked."
- Next, go down to Mail > Forwarding and ensure that automatic forwarding hasn't been enabled to send your incoming emails to an external hacker address.
Because this is a school account managed under an enterprise tenant, your local IT administrators have tools that you do not access as a student.
- Contact your school's IT support team immediately and inform them that your account was compromised.
- Ask an Exchange Administrator to run the Exchange PowerShell command:
Get-InboxRule -Mailbox ******@school.edu -IncludeHidden. This is the official Microsoft administrative protocol to reveal and purge deeply hidden server rules that do not appear in your standard Outlook interface.
For additional structural steps on clearing out post-breach modifications, please refer to the official Responding to a Compromised Email Account - Microsoft Defender for Office 365 | Microsoft Learn
I hope these steps provide a clear path to resolving this issue. Please let me know if you have any further questions.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.