Undeletable Inbox Rule placed by a Hacker

Anonymous
2025-06-09T10:33:58+00:00

My Outlook.com email account was compromised, and a malicious inbox rule labeled idtienphuoc1 keeps reappearing even after I delete it. The rule forwards emails to an external address ([email protected]) and stops further processing.

I have already:

  • Removed all rules via Outlook Web and Microsoft Graph API (Graph confirms successful deletion, albeit until the rule is replaced with a new ID)
  • Disabled all email forwarding, POP, IMAP
  • Revoked all app permissions via account.live.com/consent/manage
  • Changed my password and enabled 2FA
  • Used incognito and fresh Outlook installs (including new profile)
  • Signed out all sessions - this should mean the hacker no longer has access

Despite this, the malicious rule keeps being recreated automatically with a new internal ID, indicating some kind of server-side corruption or unauthorized persistence.

I have tried going through support but they aren't able to help, and I'm unable to get in contact with "tier 2" Microsoft support, who I think should be able to perform a backend purge of mailbox rules or inspection of delegated access not visible to user tools

Does anyone have experience in solving this?

Or can a Microsoft Moderator escalate this to the security or mailbox engineering team? It is clearly a backend persistence issue, not solvable through standard user-facing tools.

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

9 answers

Sort by: Newest
  1. Anonymous
    2025-06-24T09:37:41+00:00

    JamesAshdown, thank you very much for your instructions. I had the same problem and it helped me a lot!

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2025-06-18T21:09:18+00:00

    If you go > settings > mail > forwarding (or something similar to this) > there should be forwarding to xxx email as well as like POP and IMAP.

    Turn off POP and IMAP and make sure there are no Ali’s you don’t recognise

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2025-06-18T21:00:08+00:00

    Thank you very much for your reply.

    I have changed my password, but i cannot turn 2 factor authentication on because i cannot receive the email needed to complete the procedure.

    I guess is something with the damn rule.

    Still trying everything here, but i´m a little noob, so i dont understand most of what Bo said up there.

    Still tryin, though.

    Thank you for your help, really.

    Regards

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2025-06-18T20:19:19+00:00

    Hi mate, I just replied to another comment, follow the steps I did and you should be fine - essential thing is you use the desktop and not a phone as you get better settings

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2025-06-18T20:18:23+00:00

    If you’ve completely changed all passwords and 2factor etc then go onto settings and click mail (you need to be on desktop not phone) and when you go on ‘forwarding’, delete everything you don’t recognise - I think I had a delete filter and an auto forward to an email I didn’t recognise.

    Then keep deleting the rule in the ‘rules’ and after a while (I guess when the token or sessions expires) it won’t come back.

    I also did a load of deleting rules on Graph API but I don’t think it is this that got rid of it.

    Out of curiosity, did he order anything on your just eats? He ordered something to France on mine so perhaps we can find general area he’s located if so!!

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments