Managing personal Outlook.com account settings, security, and privacy
The behavior indicates the account is still being acted on by a malicious rule or integration, even if the visible rules look clean. Use this sequence to stop the ransom drafts and restore normal mail view:
- Clean up Outlook rules and forwarding again
- Sign in to Outlook on the web.
- Go to Settings → Mail → Rules and delete any rule that is not clearly created by you (especially anything unfamiliar or oddly named, like the “Demon” rule mentioned in a similar case).
- Go to Settings → Mail → Forwarding and remove any forwarding address you do not recognize.
- Also check Sweep rules and delete anything suspicious.
- Sign out all active sessions
- Go to the Microsoft account security page and use the Sign out everywhere option so any attacker sessions are terminated. This prevents the rule or drafts from being recreated by an active hijacked session.
- Remove malicious apps and permissions
- In Microsoft account security, open Manage app permissions (or similar) and revoke any apps or services you do not recognize. Attackers often keep access through app permissions even after a password change.
- Re‑secure the account fully
- Since the account was hacked, follow the guidance in Help protect your Outlook.com email account and, if applicable, My Outlook.com account has been hacked:
- Ensure antivirus/anti‑malware scans are run on all devices used to access the account.
- Keep the new password strong and unique.
- Keep two‑factor authentication enabled.
- Since the account was hacked, follow the guidance in Help protect your Outlook.com email account and, if applicable, My Outlook.com account has been hacked:
- If rules keep re‑appearing
- In a similar case, the persistent malicious rule stopped only after multi‑factor authentication (MFA) was fully in place and enforced on the account. If the ransom drafts or rules keep coming back, verify that MFA is enabled and working on every sign‑in and that there are no legacy sign‑in methods or devices bypassing it.
Once all malicious rules, forwarding, and app permissions are removed and all attacker sessions are signed out, new ransom drafts should stop, and normal access to old emails should return. Continue to monitor rules, drafts, and sign‑in activity for a while to ensure nothing reappears.
References:
- Help protect your Outlook.com email account
- Respond to a compromised cloud email account
- Stop auto-forwarding emails in Office 365 Business Premium
- My personal hotmail account hacked by hacker with authentication app enabled. - Microsoft Q&A
- Hacker set up continuous draft ransomware email - Microsoft Q&A
- I have seen great advice for deleting the idtienphuoc1 Rule but none for stopping it from re-adding itself - Microsoft Q&A
- My account got hacked. - Microsoft Q&A
- How do I send an email to Microsoft about my account being hacked and taken over by <removed> ? - Microsoft Q&A
- Email is missing from your Outlook.com inbox