A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
If the email address and password on the Microsoft account have been changed by an attacker, and the security info (alternate email/phone, verification methods) has been replaced, the only supported way to try to regain access is the standard hacked-account recovery flow and the Microsoft account recovery form. Payment information alone (such as a game purchase) does not guarantee recovery and cannot be used by support agents to manually restore access.
Use these steps:
- Run through the hacked-account guide
- Follow the guidance in How to recover a hacked or compromised Microsoft account. Start with the sign-in helper tool provided there: Start.
- If still able to sign in anywhere with that account (for example, if a session is still active on a device or in a browser), immediately change the password and review security info, forwarding, and automatic replies as described in the article.
- Submit the Microsoft account recovery form
- If sign-in is no longer possible because the email and password have been changed, use the account recovery form described in Help with the Microsoft account recovery form.
- Before filling it out, gather as much information as possible about the account (old passwords, exact email address/aliases, services used, approximate creation date, etc.) as described in Step 2: Gather required information for Microsoft account recovery.
- Then complete the form from a familiar device and location as described in Step 3: Fill out the Microsoft account recovery form. Provide all requested details as accurately as possible.
- Understand the limits
- The recovery process is automated and based on the information provided in the form. If the form does not grant recovery, and the attacker has fully replaced the security info, there is no other supported method to regain access; Microsoft Support cannot override this or use purchase/payment history to force account recovery.
- This is confirmed in multiple moderator answers: if the account recovery form fails and security info has been replaced, the account is considered unrecoverable.
- If security info change is pending
- If a “security info change is still pending” message appears when trying to manage the account, follow the guidance in What does “Security info change is still pending” mean?. Use the built-in options on that page (such as “Cancel this request” or “Let us know”) if available.
- For the purchased game
- If the Microsoft account cannot be recovered via the above methods, the game license tied to that account is also not recoverable through other channels. Moderator guidance in similar cases states there is no guarantee that game entitlements can be recovered if the underlying Microsoft account cannot be restored.
In summary, recovering payment information or proof of purchase alone cannot bypass the automated account recovery checks. The best chance to regain access is to thoroughly complete the Microsoft account recovery form using all available historical details about the account.
References:
- How to recover a hacked or compromised Microsoft account
- Help with the Microsoft account recovery form
- Step 2: Gather required information for Microsoft account recovery
- Step 3: Fill out the Microsoft account recovery form
- What does “Security info change is still pending” mean?
- My microsoft account has been compromised - Microsoft Q&A
- My account got hacked - Microsoft Q&A
- Need help with hacked microsoft account - Microsoft Q&A
- How do I send an email to Microsoft about my account being hacked and taken over by <removed> ? - Microsoft Q&A