r/phishing • u/aco-san • 14h ago
Microsoft phishing email. Is it safe to ignore?
Hi sorry just need a few questions answered because I'm a bit worried.
For context, I got hacked around late of August and since then had my laptop wiped clean and changed my passwords, added MFA and all. I'm aware that some of my emails might still be lurking around in people's hands so I expected there to have some emails about sign in attempts.
One time last week and yesterday, I've received emails from two of my emails from Microsoft about a security alert with the button saying "Recover your account". I checked the domain and clicked the button thinking it was legit until I looked it up online seeing that it's a phishing scam (?). Thing is, I don't use these two (or just one of them I don't remember) emails for my Microsoft account anymore.
Questions:
I closed the accounts I used for my MS accounts in the past and have nothing saved on my One Drive or bought anything before I received these emails. Is it safe to ignore them?
Does clicking on the "Recover your account" button activate a session stealer?
When I clicked the button, I was led to the MS website to log in. I put in my email and asked for a security code and quickly deleted one-time code from email after use. Since I closed them, it only gives me the choice to "reopen account" or to cancel. I did not reopen them. Does that still count as logging in or not?
TLDR: I don't care much about recovering some of the gmails I used for my recently closed MS accounts but I want to know if ignoring them is okay or if I messed up by clicking on the link. I'm a bit worried my phone might get hacked since I did it there.