Follow these steps immediately to try to secure and recover the hacked Microsoft/Xbox account that uses the Gmail address:
- Scan the PC for malware
- Before changing any passwords, run a full antivirus scan.
- On Windows 10/11, open Windows Defender (Windows Security) from Start and run a Full scan. Make sure protection and updates are turned on.
- Try to sign in and change the Microsoft account password
- Go to the Microsoft account sign-in page and sign in with the hacked Gmail-based Microsoft account.
- If sign-in works, immediately change the password to a strong, unique one.
- If sign-in fails, use the reset your password flow: select Forgot my password and follow the steps to reset your password.
- Use the hacked/compromised account recovery flow
- Because the account is hacked and security info may have been changed, use the official guide and troubleshooter for compromised accounts: How to recover a hacked or compromised Microsoft account.
- If the normal reset does not work, complete the account recovery form with as much accurate information as possible (old passwords, Xbox details, purchase info, etc.). This automated process is the only way to prove ownership if security info was changed.
- If security info was changed or is “pending”
- If the hacker replaced your email/phone and you see a message like “Your security info change is still pending”, use the options on that screen:
- Select Let us know if the change was not made by you, to start the unauthorized-change flow.
- If you initiated the change yourself and still have access to the old info, use Cancel this request.
- If the hacker replaced your email/phone and you see a message like “Your security info change is still pending”, use the options on that screen:
- After regaining access, secure the account
- Check and clean up account settings that an attacker might have modified:
- Review connected accounts, forwarding, and automatic replies settings for Outlook using the links in the hacked-account article.
- Remove any unknown aliases or email addresses from Manage how you sign in.
- Add additional verification methods on the Advanced security options page (for example, another email, phone, or Microsoft Authenticator) as described in How to help keep your Microsoft account secure.
- Check and clean up account settings that an attacker might have modified:
- Watch for unusual sign-in activity
- Go to the Security basics page and open Review activity.
- On the Recent activity page, mark any sign-ins that were not yours as This wasn’t me or Secure your account so Microsoft can help protect it.
- If recovery keeps failing
- If the recovery form and hacked-account process do not succeed and the hacker has fully replaced the security info, the account may not be recoverable. In that case, follow the guidance in the hacked-account article and consider creating a new Microsoft account for Xbox and future purchases.
For the unauthorized Minecraft/Xbox purchase shown in the email, securing the Microsoft account is the first step. Once access is restored, review purchase history in the Microsoft account/Xbox profile and then follow Microsoft Store/Xbox support guidance for unauthorized purchases.
References:
- How to recover a hacked or compromised Microsoft account
- How to help keep your Microsoft account secure
- What happens if there's an unusual sign-in to your account
- Account help & learning
- Hello , welcome to Account help & learning
- Prevent unauthorized purchases from Microsoft Store
- My account got hacked. - Microsoft Q&A
- Need help with hacked microsoft account - Microsoft Q&A
- My account got hacked - Microsoft Q&A
- my microsoft account has been compromised - Microsoft Q&A
- How do I send an email to Microsoft about my account being hacked and taken over by <removed> ? - Microsoft Q&A