Microsoft locked this person's photos and games—I've made sure it won't happen to me

Microsoft locked this person's photos and games—I've made sure it won't happen to me

Published Jul 31, 2026, 7:30 AM EDT Nick Lewis is an editor at How-To Geek. He has been using computers for 20 years --- tinkering with everything from the UI to the Windows registry to device firmware. Before How-To Geek, he used Python and C++ as a freelance programmer. In college, Nick made extensive use of Fortran while pursuing a physics degree. Nick's love of tinkering with computers extends beyond work. He has been running video game servers from home for more than 10 years using Windows, Ubuntu, or Raspberry Pi OS. He also uses Proxmox to self-host a variety of services, including a Jellyfin Media Server, an Airsonic music server, a handful of game servers, NextCloud, and two Windows virtual machines. He enjoys DIY projects, especially if they involve technology. He regularly repairs and repurposes old computers and hardware for whatever new project is at hand. He has designed crossovers for homemade speakers all the way from the basic design to the PCB. Nick enjoys the outdoors. When he isn't working on a computer or DIY project, he is most likely to be found camping, backpacking, or canoeing. Imagine waking up one day to discover that decades of your digital history have been erased. For one Twitch streamer, Joshua Khane, that nightmare scenario became a reality. His long-standing Microsoft account, which held thousands of dollars in Xbox games, along with Outlook emails and his son's baby photos, was unceremoniously deleted by Microsoft after a hacker gained access and changed the recovery email and phone number. Microsoft eventually reversed its decision and restored his access, but most people can't count on viral support to win back an account. You have to be proactive about protecting your accounts and your data. Harden the account Lockouts are often caused by a breach Credit: Josh Hendrickson / Review Geek Microsoft doesn't delete or revoke access to accounts out of pure malice; instead, it often does so because hackers gain access and manage to revoke all of the original owner's ability to access the account. As soon as they change the security information, you're in trouble. If you can prevent that from occurring in the first place, you're in a much stronger position. First, ditch SMS-based two-factor authentication if you can. You can switch to a passkey or an authenticator app; either is better than SMS. SMS is still vulnerable to sim swapping, which lets an attacker hijack your phone number, intercept the code, and bypass your other protections. You also need to pair that precaution with a password manager, which makes it trivial to implement strong, unique passwords for all of your accounts. That makes credential stuffing attacks—which are only viable if you're reusing login details—basically impossible. As a final measure, make sure you enable sign-in and security change alerts. If someone tries to access your account, you need to know about it immediately. The alerts can be a bit annoying if someone launches a determined attack against your account, but a few spammy notification emails beat losing the account to an attack you never noticed. Keep local copies of anything important One copy in the cloud is not a real backup It is common to treat "cloud storage" as "reliable backup," but in reality you cannot assume that a single cloud service is a reliable backup. Functionally speaking, you have to treat that as only a single backup and, correspondingly, a single point of failure. If your Microsoft account holds irreplaceable files—baby photos, say—make sure that they're backed up to multiple different services and that you have some kind of reliable local backup too, like an external hard drive stored in a cool, dry location. In general, the 3-2-1 rule is a good place to start. Keep three copies of your data on two different types of media, with one copy kept off-site or offline. You can automate this with a scheduled sync app, but make sure you actually open the files to confirm they aren't corrupted. A backup solution that you haven't tested isn't a backup solution at all. Don't put all of your eggs in one tech giant A second, independent cloud means no single company can wipe you out Credit: Adam Davidson / How-To Geek Account deletion is provider-specific. If your photos are hosted exclusively with Microsoft and Microsoft deletes your account, those photos are probably gone for good. However, if you copy that data to a second service—like Google Photos or Backblaze—a mishap with Microsoft doesn't matter all that much. You should set up a set-and-forget cloud backup that runs independently of your primary login. If you are dealing with sensitive data, encrypt the files with something like Cryptomator before uploading them to the second provider. A second cloud might mean paying for an extra subscription, but if that means you can keep irreplaceable memories, the price is probably worth it. Split your accounts up One hacked login shouldn't be able to take down your entire digital life You should break up your digital identity. Use a dedicated email address—one you don't use for anything else—for gaming logins, and avoid making your primary inbox the recovery address for every single service you own. Double-check which services are connected to ensure that if one account is compromised, it can't trigger a domino effect through the rest of them. Own games you can actually keep Digital purchases are licenses that live and die with your account It is important to remember that when you buy a digital game, you aren't buying the game—you are buying a license to access it. That license lives and dies with your account and can be revoked at any time. Where possible, buy physical media or use DRM-free storefronts like GOG, where you own the installer files permanently. The gaming industry is shifting towards a digital-only model—PlayStation plans to end physical production by 2028. That shift means buying DRM-free titles remains the best way to reduce your risk. Watch for trouble and keep your exits current Catching a breach early is the difference between a scare and a wipe Credit: Justin Duino / How-To Geek A breach becomes catastrophic only if the attacker also has the time to change all of your recovery methods. The faster you're informed about a breach, the better. You should turn on breach alerts through services like "Have I Been Pwned" and keep your recovery phone number and email address current. Your data matters more to you than it does to Microsoft Unfortunately, there are a lot of practical reasons why Microsoft or any other tech giant might refuse to help you if your account is compromised. You may get lucky with a viral campaign that turns the tide in your favor, but you probably won't. If you store anything important on any cloud service, you have to be proactive about your backups and your security. You can use a locally-hosted Nextcloud instance as one of your backup solutions, and it works with something as low power as a Raspberry Pi 4.

Original Source

Read the full article at Howtogeek →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.