Hackers sending phishing emails through my account

key 0 Reputation points
2026-07-03T03:23:01.4733333+00:00

i recently noticed that 1000+ phishing emails were sent from my school outlook email (that weren't sent by me). i think i was hacked and i have now changed my password, set up microsoft authenticator, and checked recent activities. i noticed quite a lot of login attempts from overseas, the first ones dating back to june 13, a lot of them coming from the platform 365 exchange online in korea (although there were a few other locations).even after securing my account, my outlook is still receiving notices that my account failed to send emails containing the same phishing content, but nothing in the "sent" tab. how do i stop this sending and know that the hackers are out of my account?

Outlook | Windows | New Outlook for Windows | For education
0 comments No comments

1 answer

Sort by: Most helpful
  1. Sophie N 17,495 Reputation points Microsoft External Staff Moderator
    2026-07-03T04:31:29.09+00:00

    Dear @key,

    I understand how alarming it is to discover that thousands of phishing emails have been sent from your account, and it is completely understandable to feel anxious when you continue to see delivery failure notices even after changing your password and setting up the Microsoft Authenticator app.

    The core issue you are experiencing is that changing your password does not automatically terminate active sessions or delete hidden rules that hackers configure while they have access to your account.  

    The reason you are still seeing bounce-back failure messages (NDRs) without anything appearing in your "Sent" folder is due to two common post-compromise tactics:

    • Malicious Inbox Rules: Attackers frequently create background rules that automatically send out emails and immediately delete the record from your Sent Items folder to hide their tracks.  
    • Delayed Mail Queues: The mail servers may still be processing and rejecting the massive backlog of spam messages that the hackers queued up before you changed your password.

    To completely evict the hackers and ensure your account is 100% secure, please follow these concrete recovery steps:

    Step 1: Force-Terminate All Active Sessions ("Sign Out Everywhere")

    Even though you changed your password, the hacker may still hold an active browser cookie or an authorized "App Password" token that bypasses your new password and MFA.

    • Go to your My Account
    • Scroll down and click on Security info options.
    • Look for the "Sign out everywhere" section and select it. This will forcefully invalidate all active login tokens worldwide within 24 hours, kicking the hacker out of Exchange Online entirely.
    • On the same page, check the "Passwords" section and delete any unauthorized app passwords created by the attackers.

    User's image

    Step 2: Audit and Delete Malicious Inbox Rules

    You must clear out the hidden automations the hacker left behind:

    • Log into Outlook on the web (OWA) via your browser.
    • Click the Settings (gear icon) in the top right corner > select Mail > click Rules.
    • Thoroughly review the list. Delete any rules you did not create especially rules designed to delete messages or move items containing keywords like "phish," "spam," "undelivered," or "blocked."
    • Next, go down to Mail > Forwarding and ensure that automatic forwarding hasn't been enabled to send your incoming emails to an external hacker address.

    User's image

    Because this is a school account managed under an enterprise tenant, your local IT administrators have tools that you do not access as a student.

    • Contact your school's IT support team immediately and inform them that your account was compromised.
    • Ask an Exchange Administrator to run the Exchange PowerShell command: Get-InboxRule -Mailbox ******@school.edu -IncludeHidden. This is the official Microsoft administrative protocol to reveal and purge deeply hidden server rules that do not appear in your standard Outlook interface.

    For additional structural steps on clearing out post-breach modifications, please refer to the official Responding to a Compromised Email Account - Microsoft Defender for Office 365 | Microsoft Learn

    I hope these steps provide a clear path to resolving this issue. Please let me know if you have any further questions.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".   

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.