A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
I'm just gonna sue them
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
My microsoft account with email *@163.com has been hacked as a malicious verification code was entered, and now my account has been relocated to a email [no@mcfa.online]. When I tried to login again it says that my email does not exist, so I could not loging to my account and change my passcode
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
I'm just gonna sue them
Microsoft agents can only provide aid in using the automated tools that support account recovery, they haven't been able to make manual changes per the following section from the document link provided for at least a few years now.
Help with the Microsoft account recovery form | Microsoft Support
Important
Due to various wars, nation state and criminal gang attacks that have become common over the last several years, Microsoft has had to move to AI automated scripts and other non-human forms of recovery in order to ensure that human decisions aren't involved, since humans are fallible and thus can make mistakes. That's what's meant by the second sentence ion the first paragraph above, and so it's why support agents can no longer make direct changes, only you can by properly following the automated steps using first the Sign-in helper tool and then if 2FA hasn't been enabled (by you or possibly an attacker), filling out the account recovery form by carefully following the instructions provided including explanations in the video on that page.
If the attacker(s) have changed the account alias (email address) as well as all of the other verification methods, it's typically not possible to recover the account using these methods, so the best that cab=n happen is the account is locked, stopping both the attacker and anyone else including yourself from abusing the account services and contents in the future.
Yes, this is potentially a catch-22 situation, but once someone has fully taken over an account there's nothing even Microsoft can do to ensure that if they were to manually recover the account for you (which they can't due to policy) that the attackers wouldn't simply be able to regain control of the account again anyway, since they've effectively taken over and become the account owner now. That's why Microsoft was forced to make these decisions, since the complexity of the security along with other technical issues has made it impossible to ensure a safe recovery, so locking the account permanently is the only way to ensure the problems don't continue indefinitely.
This is why it's so important to properly secure your Microsoft account using multiple forms of 2FA, preferably using phishing resistant passkeys with Windows Hello Face, Fingerprint and/or PIN, since this performs the verification locally, since the attackers have learned how to trick gamers and other users into providing the security codes sent by SMS, Email and even the Microsoft and other TOTP authenticators via malware or phishing, including fake login screens (often via Discord or similar sites) and other tricks, making those forms of security relatively useless for those who don't fully understand the technical details required to recognize these attacks and avoid them.
Try the Sign-in Helper tool if you haven't already to learn your possible recovery path if any, then if whatever it offers isn't working and/or it becomes clear that the account verification items have all been changed, either try to contact support directly using the tool's suggested path to have the account locked to avoid credit card, gaming identity or other future abuse if desired.
Rob