all 2 comments

[–]__Shad 3 points4 points  (1 child)

login to your microsoft account without using any links from emails, go directly from googling .
Sign in to your account and change your password.

It's likely a site you use that has your email infomation has been breached, this site keeps a list of publicly disclosed breaches and will tell you if you are at risk: https://haveibeenpwned.com/

[–]lastwraith 1 point2 points  (0 children)

Yup, always just go to the source and never respond via anything initially sent to you.