Forum Discussion

JasonAJWong's avatar
JasonAJWong
Copper Contributor
Jan 09, 2026

Unusual Sign-In Activity E-mail but I cannot identify the account!

Hi,

 

I'm experiencing something quite weird. This morning I got an alert to a personal e-mail address of mine (w********@gmail.com) that a Microsoft account of mine was accessed from an IP address in Brazil. I've attached that e-mail and it lists the account as "ja*****" with no domain name listed. I have two microsoft accounts that I know of that start with "ja". One is a hotmail account and one is registered with my university account. I figured this alert had to do with my university account because that could explain why it never listed a domain name. However, when I checked, neither account have any record of a sign in, successful or unsuccessful, from an IP address in Brazil today. Furthermore, the university account doesn't have the w*******@gmail.com listed as a primary or secondary e-mail account so even if that was the account that alert wouldn't have gone to that e-mail.

 

I contacted Microsoft support hoping that they could try to locate the alert e-mail and confirm what account the alert was about from their end but they told me they don't have the tools for that and they have limited access to their own system. A supervisor told me that at this point my best bet is to either post on the community forums or to go to the police and ask them to track the IP address. 

 

I have a vague memory that years ago when I tried to log into my university Microsoft account, it would let me log in as a personal account and as a work account separately but now I can only use it as a work account. I'm wondering if that might be related like maybe someone was able to access my personal account of my university Microsoft account which could explain both the lack of a domain name in the e-mail and the fact that there's no history of it in my work account. 

 

This is really bugging me because someone may have accessed an account belonging to me but I'm completely unable to actually confirm that or even the account this is happening to.

 

Thanks!

 

1 Reply

  • V-Peter-S's avatar
    V-Peter-S
    Copper Contributor

    We've observed a number of these as well. Most of them are blocked at our e-mail gateway, but occasionally one gets through. In a recent example, DMARC, DKIM and SPF are legitimate, identical sender and South America sign in from Android.

    The links appear legitimate, but I've reported to Microsoft for review from our Defender portal.

Resources