Undeletable Inbox Rule placed by a Hacker

Anonymous
2025-06-09T10:33:58+00:00

My Outlook.com email account was compromised, and a malicious inbox rule labeled idtienphuoc1 keeps reappearing even after I delete it. The rule forwards emails to an external address ([email protected]) and stops further processing.

I have already:

  • Removed all rules via Outlook Web and Microsoft Graph API (Graph confirms successful deletion, albeit until the rule is replaced with a new ID)
  • Disabled all email forwarding, POP, IMAP
  • Revoked all app permissions via account.live.com/consent/manage
  • Changed my password and enabled 2FA
  • Used incognito and fresh Outlook installs (including new profile)
  • Signed out all sessions - this should mean the hacker no longer has access

Despite this, the malicious rule keeps being recreated automatically with a new internal ID, indicating some kind of server-side corruption or unauthorized persistence.

I have tried going through support but they aren't able to help, and I'm unable to get in contact with "tier 2" Microsoft support, who I think should be able to perform a backend purge of mailbox rules or inspection of delegated access not visible to user tools

Does anyone have experience in solving this?

Or can a Microsoft Moderator escalate this to the security or mailbox engineering team? It is clearly a backend persistence issue, not solvable through standard user-facing tools.

Outlook | Web | Outlook.com | Account management, security, and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

9 answers

Sort by: Most helpful
  1. Anonymous
    2025-06-18T21:09:18+00:00

    If you go > settings > mail > forwarding (or something similar to this) > there should be forwarding to xxx email as well as like POP and IMAP.

    Turn off POP and IMAP and make sure there are no Ali’s you don’t recognise

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2025-06-18T20:18:23+00:00

    If you’ve completely changed all passwords and 2factor etc then go onto settings and click mail (you need to be on desktop not phone) and when you go on ‘forwarding’, delete everything you don’t recognise - I think I had a delete filter and an auto forward to an email I didn’t recognise.

    Then keep deleting the rule in the ‘rules’ and after a while (I guess when the token or sessions expires) it won’t come back.

    I also did a load of deleting rules on Graph API but I don’t think it is this that got rid of it.

    Out of curiosity, did he order anything on your just eats? He ordered something to France on mine so perhaps we can find general area he’s located if so!!

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2025-06-17T18:21:06+00:00

    Hi James ,

    I’ve got the exact same thing right now. Currently he’s managed to steal 2 instagram accounts , my just eat account , Etsy account , binance account and a few others and he’s tried to access my banking but got blocked. I can’t get rid of him and despite locking down the account I can’t remove the rule so currently he gets all of the reset password links so can continue hijacking my accounts.

    Did you find any other way of getting rid of it?

    I’d like to think he’s no longer actually on my account however he keeps deleting emails and archiving them , namely the ones where he’s requested a password reset link but I don’t understand how he can delete emails in my inbox without him being on there?

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2025-06-10T14:42:33+00:00

    Thanks Bo,

    After numerous deletion attempts, it finally doesn't re-add itself (took about 24 hours), my theory is that the token/ API or whatever was re-adding the rule's session must have finally timed out!

    Luckily he got away with just a Deliveroo order and a T-Shirt from my card before I blocked it (although the fact he got 10 chicken wings and a chicken burger is upsetting).

    Thanks again for your in-depth response, and hopefully this thread will give aid to future users.

    James

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2025-06-09T15:24:14+00:00

    Hi JamesAshdown,

    That sounds like an incredibly frustrating and serious situation you’ve clearly put in a ton of effort, and it must be unsettling to still see the malicious rule persist. You’re not alone in this, and it’s absolutely valid to feel concerned when even advanced tools and safeguards don’t seem to make a dent. Let’s walk through this together.

    Summary of Your Situation

    You’re dealing with a sophisticated and persistent compromise of your Outlook.com account, where an unauthorized inbox rule (forwarding to an external address and halting processing) keeps reappearing even after being deleted through legitimate channels like Outlook Web and Microsoft Graph API. You’ve taken all the right defensive steps—revoking permissions, changing your password, enabling 2FA, and more—but the rule seems to resurrect with a new internal ID each time, indicating it may be embedded deeper on Microsoft’s servers or triggered by a backdoor mechanism that’s not exposed to standard user management tools.

    This is not just a routine breach—it borders on a systemic backend persistence that warrants a closer look by specialized support teams.

    Recommended Actions & Escalation Strategies

    Here are some advanced steps you might not have tried—or might help you push for escalation more effectively:

    1. Check for Hidden or Delegated Access

    Sometimes attackers grant hidden delegate permissions or shared mailbox access:

    • Visit: https://account.live.com/activity and verify unfamiliar sign-ins.
    • Use Microsoft Graph Explorer to confirm there are no remaining delegate permissions:
      • Endpoint: GET https://graph.microsoft.com/v1.0/me/permissionGrants
      • Look for any app consents or delegated access not visible in the regular portal.
    1. Audit Compliance Mailbox Settings (if enabled)

    If your account is part of a Microsoft 365 Family or Business subscription:

    • Use PowerShell with the Exchange Online Management Module:

    powershell Get-InboxRule -Mailbox ******@outlook.com

    Get-MailboxPermission -Identity ******@outlook.com

    Get-RecipientPermission -Identity ******@outlook.com

    You might need help from Microsoft support for this one, especially if you're on a consumer-grade Outlook.com domain.

    1. Check for Non-Obvious Mail Flow Rules

    Especially on enterprise setups, “Transport Rules” (mail flow rules) can masquerade as inbox rules. Even if your setup isn’t business-class, it’s worth asking support to verify that no organization-wide rules are applying.

    1. Request Escalation with Detailed Case History

    When engaging with Microsoft Support again:

    • Clearly detail everything you’ve tried (as you outlined above).
    • Emphasize it's not a user-error or local-client issue—this appears to be backend persistence or mailbox-level compromise not addressable by user tools.
    • Request escalation to the Outlook Security Engineering or Exchange Online Protection teams.

    Use wording like: > “This issue seems to be related to backend persistence that survives full rule deletion via both client and API, as well as removal of access, apps, and sessions. I suspect a hidden permission or mailbox corruption and am requesting engineering-level review.”

    Best regards,

    Bo | Microsoft Community

    Was this answer helpful?

    0 comments No comments