Additional Microsoft Defender tools and services that provide security across various platforms and environments
Compromised account still sending mass spam despite password change, 2FA, and signing out everywhere — possible persistent OAuth token
Hi,
My Outlook/Hotmail account was compromised and is still sending mass spam/financial scam emails (Bitcoin, bank transfers, remittance themes) despite completing the full standard recovery process:
- Changed the password (multiple times)
- Enabled two-step verification (2FA)
- Used 'Sign out everywhere'
- Checked 'App access' — found no suspicious apps
- Checked and cleared App Passwords (none were active)
- Deleted suspicious inbox rules
- Confirmed forwarding, POP, and IMAP are all disabled
- Confirmed my security contact info (alternate email/phone) is genuinely mine
Despite all of this, my account keeps sending spam in such high volume that I hit Outlook.com's daily sending limit today ('Your message wasn't sent because there's a daily limit for how many messages can be sent'). My inbox is flooding with bounce-back messages (from ******@outlook.com, 'Delivery has failed to these recipients or groups') for financial scam emails I never sent.
I checked the 'Message source' of one of the sent emails and found:
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Exchange-Organization-AuthSource: BL02EPF00029929.namprd02.prod.outlook.com
This suggests the sending is not going through an interactive login, but through some kind of persistent application/API-level access that doesn't show up on the normal 'App access' page and isn't revoked by the standard recovery steps.
I also noticed my account language was changed to Vietnamese without my authorization.
Can someone from Microsoft (verified staff) help escalate this to a manual security review? I've exhausted the self-service options, and the automated support chat/assistant hasn't resolved the issue.
Thank you in advance.