MMatt Senter
nowprojectsaboutconnectblog

← Blog

Microsoft Gave My Son’s Account Back. It Shouldn’t Have Taken 60,000 Views.

The account is back. The recovery process still needs to work when nobody important is watching.

September 8, 2026 · Matt Senter

Microsoft logo above the message: It should not take 60,000 views to recover an account. Same account. Different outcome.

A few weeks ago, I wrote about what happened after my son’s Microsoft account was taken over. The short version was ugly: an attacker gained control of the account, changed its recovery information, and Microsoft’s account-recovery process left me trying to prove that my own child’s account actually belonged to him. I provided extensive evidence, followed the instructions Microsoft gave me, and then the support process effectively disappeared.

I wrote about that experience in Microsoft’s Account Recovery Is Security Theater. That post ended up getting more than 60,000 views.

Then something interesting happened. Someone fairly high up at Microsoft viewed my LinkedIn profile. I noticed, and on September 1 I sent him a message and asked him directly: Are you looking at my profile because of my blog post? He said yes. That message changed everything.

The Timeline Tells the Story

I first contacted Microsoft about the account takeover on August 13, 2026.

On August 14, the original support team sent me this:

If you reply to this email within the next 7 days with additional information, I will be more than happy to continue my investigation.

So I did exactly that. On August 15, just one day later, I replied with a mountain of additional information and evidence. Then I heard nothing: no follow-up questions, no explanation, and no acknowledgement that the investigation had continued. The team simply stopped communicating with me.

That silence lasted until September 4, when I finally received this response:

This service request has already been resolved and closed. We are happy to assist you with your new request; however, I am not be able to re-open this closed service request. You need to create a new service request by contacting Microsoft Support, and someone would be happy to assist you further.

That was astonishing. I had been explicitly told that if I responded within seven days with more information, the investigation would continue. I responded within one day. Instead, the case was apparently closed without my knowledge, and I was ghosted for nearly three weeks before being told to start over.

I replied and pointed out the contradiction. Microsoft had asked me for more evidence, promised to continue investigating if I supplied it within seven days, received it within one day, and then quietly closed the ticket anyway. I asked why and never received a response.

That part of this story remains completely unacceptable. People dealing with account takeovers are already in a stressful position. Quietly closing an investigation after explicitly telling someone they have a window to submit more evidence, then failing to explain what happened, is not how a security or customer-support process should operate.

Meanwhile, LinkedIn Worked Better Than Microsoft Support

While the original support team was still silent, I noticed on September 1 that a Microsoft employee fairly high up in the organization had viewed my LinkedIn profile. Given the timing and the attention the original blog post had received, I had a pretty good guess why. I messaged him directly and asked whether he was looking at my profile because of the blog post. He responded that same day: yes.

We started communicating over LinkedIn, and he was extraordinarily helpful. He connected me with an escalation team inside Microsoft, and the recovery process started again. Structurally, the escalation process was not dramatically different from what I had already gone through. They asked questions, I provided evidence, and they reviewed account information to determine legitimate ownership.

But there was one enormous difference: this time, it felt like someone was actually evaluating the evidence I was giving them. They were responsive, communicated with me, asked follow-up questions, and appeared to consider the history of the account and the information I supplied instead of treating the case like a binary checklist.

And on September 7, 2026, the account was restored. Six days after I contacted the Microsoft employee on LinkedIn. Twenty-five days after I first contacted Microsoft support. Weee!

The Escalation Team Was Excellent

I want to be clear about this part, because it would be unfair to paint everyone at Microsoft with the same brush. The people who eventually helped me were great. The Microsoft employee I connected with through LinkedIn was kind, responsive, and genuinely interested in figuring out what had happened. The escalation team treated the situation seriously and ultimately reached the correct outcome.

We even spent time trying to understand how the account was compromised in the first place. That remains the biggest unanswered question. Because I am primarily a Mac user and do not spend nearly as much time administering Windows machines, the Microsoft contact gave me some suggestions for investigating my son’s computer. From there, I used ChatGPT to go considerably deeper: examining the Windows machine, reviewing security settings, looking for persistence mechanisms, checking for suspicious software, and searching for evidence that the computer itself had been compromised.

So far, I have found nothing: no obvious malware, no clear remote-access tool, no evidence that someone had persistent control of the machine, and nothing that neatly explains the takeover. That makes some form of social engineering increasingly likely, although I still cannot prove exactly what happened. My son does not remember doing anything that obviously explains it, and the available account data has not given me enough information to reconstruct the attack conclusively. I am still digging.

The Account Is Back. It Is Also Much Harder to Steal Now.

Once we regained access, I hardened the account considerably. More importantly, my son and I had a long and very direct conversation about modern scams. This is something I think parents of technically sophisticated kids can underestimate: knowing how to use computers is not the same thing as understanding adversarial behavior on the internet.

Kids spend enormous amounts of time in environments where strangers routinely ask them to:

  • Sign into websites.
  • Join Discord servers.
  • Install mods or utilities.
  • Scan QR codes.
  • Authenticate game accounts.
  • Enter verification codes.
  • Follow links sent through chats.
  • Connect Microsoft, Google, Steam, Xbox, Roblox, or other identities to third-party services.

Most of those interactions are perfectly legitimate. An attacker only needs one that is not. So we are changing how authentication works in our house. My son is now going to use a password manager exclusively for his credentials. If a password is not in the password manager, he should not be typing it. If the password manager does not recognize a site as belonging to the credential he expects to use, that should immediately be a warning that something is wrong.

That does not eliminate phishing or social engineering, but it dramatically reduces the amount of credential handling that happens manually and reduces our attack surface. We have also tightened recovery mechanisms and authentication wherever possible.

But There Is a Bigger Problem Here

I am obviously happy with the outcome. My son has his account back, the people on Microsoft’s escalation team were genuinely helpful, and someone inside Microsoft cared enough about the situation to personally get involved. But I keep coming back to an uncomfortable question: What would have happened if my blog post had received 60 views instead of 60,000?

The normal support process:

  • August 13: I contact Microsoft.
  • August 14: Microsoft asks me for more evidence and explicitly says it will continue investigating if I respond within seven days.
  • August 15: I provide extensive additional evidence.
  • August 15–September 4: Silence.
  • September 4: Microsoft tells me the case had already been closed and I need to start over.

The escalation process:

  • September 1: I notice a Microsoft employee viewed my LinkedIn profile and contact him.
  • September 1: He responds and begins connecting me with the right people.
  • September 7: Microsoft restores the account.

The escalation path fixed in six days what the ordinary support process failed to resolve in more than three weeks. That is the real story here. I happened to have a platform. The story spread. Someone inside Microsoft noticed it, looked at my LinkedIn profile, and I happened to notice that. I contacted him, he responded, he knew whom to contact internally, and eventually the account was restored.

That is a remarkably specific chain of events, and none of it should have been necessary. The evidence I gave the escalation team was not magically different because a Microsoft employee had seen my blog post. I was still the same parent. It was still the same account. The account history was still the same. The circumstances of the takeover were still the same. What changed was that someone inside Microsoft with the ability to navigate the organization became interested in the case.

That concerns me far more than whether my particular story had a happy ending. A security recovery system has to work for the person who does not have a blog, does not have 60,000 people reading their story, cannot find a Microsoft employee on LinkedIn, and is not technical enough to reconstruct login histories and security events. It has to work when nobody important is watching.

Account Recovery Is Part of the Security Model

My original criticism of Microsoft account recovery has not fundamentally changed. Account recovery is not merely customer support. It is a security system. Companies spend enormous amounts of engineering effort protecting the front door with passkeys, MFA, behavioral analysis, suspicious-login detection, device fingerprints, risk scoring, and increasingly sophisticated authentication systems. But eventually somebody loses access, and at that moment the account-recovery process effectively becomes the authentication system.

It has to answer one extraordinarily difficult question: Who should control this account? Getting that wrong in either direction is disastrous. Make recovery too easy and attackers can steal accounts through customer support. Make recovery too rigid and legitimate owners can permanently lose accounts that may contain years of purchases, emails, files, gaming history, identities, subscriptions, and family data.

That is a hard engineering problem. But “hard problem” cannot become an excuse for a system where the best path to successful recovery is generating enough public attention that someone senior inside the company notices you.

Microsoft Did Eventually Do the Right Thing

I want to end this update differently than the first one. Microsoft ultimately fixed the problem. The people who helped me were professional, empathetic, and effective. I appreciate the Microsoft employee who saw my post, responded to a stranger on LinkedIn, and personally helped route this through the company. I appreciate the escalation team that revisited the evidence and restored my son’s account. They deserve credit for that.

But the fact that the escalation worked also demonstrates something important: the account was recoverable. Microsoft had enough information to determine that my son was the legitimate owner. The problem was getting the case in front of a process capable of making that determination.

That is the part Microsoft still needs to fix, because the next parent may not have a viral blog post. And recovering your child’s account should not require one.

Matt Senter

Matt Senter

Founder, entrepreneur, and CEO based in Durham, NC, with 30 years building software and 11 companies founded. Currently Founder & CEO of Senternet and Co-Founder, COO, and CTO of BeeReady, and the builder behind Orgabot, Highwire, StockCar, Premail, Comoji, and Burly. More about Matt.

© 2026 Matt Senter · Created by Matt Senter of SenternetMade with OrgabotDurham, NCBuilt for buildersaboutblogToolsPrivacyTerms