Microsoft confirmed my account was compromised, but Xbox recovery verification is not working

현석 장 0 Reputation points
2026-08-06T02:46:44.4533333+00:00

My Microsoft account was compromised, and Microsoft has already confirmed that unauthorized access occurred.

Microsoft also confirmed that the security information on the account was changed during the unauthorized access, and the account has now been suspended.

I have received multiple Service Request results from Microsoft.

The latest email states that if I have an Xbox profile associated with the account, I may submit my Xbox Gamertag and Xbox Network Device ID so that the Xbox profile information can be reviewed.

I followed those instructions.

My Xbox Gamertag is:

[PII removed by mod]

I also obtained the Xbox Network Device ID exactly according to Microsoft's instructions:

Windows Settings → Privacy & Security → Diagnostics & feedback → View diagnostic data → search for "xbl" → use the value labelled "did".

I submitted the Gamertag and the Xbox Network Device ID, but the resulting Service Request still states that the account cannot be restored.

My main question is:

Is the Xbox Network Device ID (xbl.did) actually used by Microsoft Account/Xbox Support to verify ownership of a compromised account?

If so, how can I determine whether the Gamertag and Device ID I provided were actually reviewed?

If the information did not match the account, I would like to understand what kind of mismatch could occur. The Device ID was obtained from a Windows PC that had previously been used with the compromised Microsoft account.

Microsoft has already confirmed that unauthorized access occurred, so I am having difficulty understanding what additional ownership verification is possible when the attacker changed the security information and I can no longer access the account.

I also have historical Microsoft/Xbox purchase records associated with the account and can provide order numbers and other billing information through an appropriate private support channel.

I am not asking for Microsoft's security policies to be bypassed. I am trying to understand what legitimate recovery or escalation process is available when:

  1. Microsoft has confirmed the account was compromised.
  2. The security information was changed by the unauthorized party.
  3. The legitimate owner no longer has access to the account.
  4. Microsoft specifically instructed the user to provide an Xbox Gamertag and Xbox Network Device ID.
  5. Those details have been provided, but the recovery request is still rejected without an explanation of whether those details were reviewed.

Any advice from Microsoft support staff, MVPs, or users who have experienced a similar situation would be greatly appreciated.

Thank you.

Microsoft Security | Microsoft Authenticator
0 comments No comments

1 answer

Sort by: Most helpful
  1. Pavel Poddubny 2,445 Reputation points Volunteer Moderator
    2026-08-06T03:13:55.87+00:00

    Hello,

    Is the Xbox Network Device ID (xbl.did) actually used by Microsoft Account/Xbox Support to verify ownership of a compromised account?

    Yes. However, it is not a recovery key and does not establish ownership by itself.

    If so, how can I determine whether the Gamertag and Device ID I provided were actually reviewed?

    A Service Request does not show whether every item was reviewed or not.

    I recommend replying in the same Service Request email thread to verify, but they usually respond just with scripts they have.

    If the information did not match the account, I would like to understand what kind of mismatch could occur. The Device ID was obtained from a Windows PC that had previously been used with the compromised Microsoft account.

    It's not only about the Device ID. If that's the form you're filling - https://account.live.com/acsr it does have many other questions.

    Microsoft has already confirmed that unauthorized access occurred, so I am having difficulty understanding what additional ownership verification is possible when the attacker changed the security information and I can no longer access the account.

    Confirmation of unauthorized access and verification of the person requesting recovery are two separate findings. Microsoft may be able to determine that an account was compromised from its activity history without being able to establish that the current claimant is the pre-compromise owner.

    Your historical purchases are still valuable supporting evidence. Offer order numbers, dates, amounts, billing name and address, payment type, and only the last four card digits through the existing private Microsoft case channel. Do not post the full Device ID, billing details, or order information publicly.

    Keep submitting new forms - you can do that twice per day.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.