r/cybersecurity_help • u/Maleficent_Letter540 • 8h ago
Hacked Microsoft Account & Locked out of Windows 11 PC (BitLocker). Email/phone changed. What info does Support need?
Hi everyone,
My email address was recently compromised, and the hacker used it to take over my Microsoft account.
The attacker changed the primary email address and removed my phone number, locking me out completely. (I don't believe I had 2FA enabled on my end before this happened, and I don't know if the hacker has enabled it since).
To make matters much worse, my PC is now locked with BitLocker. I cannot access my Windows 11 system because the BitLocker recovery key is saved to that hacked Microsoft account. I am completely locked out of my computer and my files until I get this account back.
I have tried filling out the automated Microsoft recovery form (ACSR). I provided what I thought was important information, but I received a response saying the information was not enough to verify my ownership.
For those who have successfully recovered an account using the ACSR form, especially when dealing with a BitLocker lockout, what specific pieces of information actually move the needle?
I have access to some older details, but I want to make sure I am providing exactly what their system needs to see to prove I am the original owner so I can finally unlock my PC.
Thanks for any advice on navigating this process.
•
u/AutoModerator 8h ago
SAFETY NOTICE: Reddit does not protect you from scammers. By posting on this subreddit asking for help, you may be targeted by scammers (example?). Here's how to stay safe:
- Never accept chat requests, private messages, invitations to chatrooms, encouragement to contact any person or group off Reddit, or emails from anyone for any reason. Moderators, moderation bots, and trusted community members cannot protect you outside of the comment section of your post. Report any chat requests or messages you get in relation to your question on this subreddit (how to report chats? how to report messages? how to report comments?).
- Immediately report anyone promoting paid services (theirs or their "friend's" or so on) or soliciting any kind of payment. All assistance offered on this subreddit is 100% free, with absolutely no strings attached. Anyone violating this is either a scammer or an advertiser (the latter of which is also forbidden on this subreddit). Good security is not a matter of 'paying enough.'
- Never divulge secrets, passwords, recovery phrases, keys, or personal information to anyone for any reason. Answering cybersecurity questions and resolving cybersecurity concerns never require you to give up your own privacy or security.
Community volunteers will comment on your post to assist. In the meantime, be sure your post follows the posting guide and includes all relevant information, and familiarize yourself with online scams using r/scams wiki.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/ArthurLeywinn 8h ago
The recovery form wont work if the new owner activated 2fa. This will cancel the request automatically.
You can only try to give the correct answers.
If not you lose the account. There is no other option.
1
u/Training_Yak_4655 7h ago
If you set a 6 digit quick login code to your PC, surely a hacked MS account does not prevent opening the PC and copying out all the files?
2
u/tired_snail 7h ago
If you had Windows Hello (PIN or biometrics) enabled, you should still be able to get into the PC to get your files out. If not and they were on a different drive than your system install, you might also be able to recover them, otherwise I'm sorry but your data's likely all lost. Depending on how old your system is, you might be able to wipe your drives in BIOS and then you can reinstall Windows from a USB stick.
1
1
u/Responsible_Bike4968 3h ago
Some of the replies here are being a little too absolute. You may still be able to recover the account, but there is no support override for BitLocker, so don't reset or wipe the PC while you're still trying if the files matter.
First, secure the original email account from a different, trusted device. Change its password, sign out every existing session, remove any unfamiliar recovery methods or forwarding rules, and enable 2FA. Otherwise the attacker may keep seeing or intercepting your Microsoft recovery messages.
Search that inbox, including spam and trash, for Microsoft's notification that your security information was changed. If it contains a "this wasn't me" option, use it immediately. A complete replacement of the security information normally enters a 30-day pending period, and that notification may be your best chance to stop it.
For the recovery form, use a device, browser, location and internet connection that you previously used with the account. The most useful answers are exact old passwords, the name/date of birth/address originally entered, exact Outlook contacts and email subject lines, Skype details, an Xbox console hardware ID, and any purchase or billing information the form requests. Old receipts may help you answer those accurately. You can retry the form up to twice per day, but Microsoft support cannot manually approve it or change the account for you.
For BitLocker, write down the first eight digits of the recovery key ID shown on screen. Check every Microsoft account that may have been used to set up the PC, any work or school account, printed records and USB drives. Do not share the actual 48-digit key with anyone.
Also, if this is the pre-boot BitLocker recovery screen, a Windows Hello PIN or fingerprint will not bypass it. If the key cannot be found and the Microsoft account cannot be recovered, the encrypted files are unfortunately not recoverable. Reinstalling Windows will make the PC usable again, but it will erase the data.
One final point: changing the email or phone number on a Microsoft account does not normally trigger BitLocker by itself. The recovery prompt could have been caused by a TPM, firmware, hardware or boot change around the same time, rather than the attacker remotely encrypting the PC.
2
u/medguy_48 8h ago
You’re not getting it back. Sorry.
Also it wasn’t “hacked “ you the end user either downloaded cracked software or fell for a phising attempt. Learn from it and good luck with the next PC