The thread centers on an Outlook/Microsoft account being accessed despite repeated password resets, with the attacker allegedly installing a “Lenovo Data Share” app and continuing to receive security-code notifications. The main guidance is that Windows-level security won’t remove an attacker’s Microsoft/OAuth account permission; the user should revoke suspicious app permissions from the Microsoft account settings, sign out of all sessions, check and remove any Outlook forwarding/rules that hide/move security emails, and switch MFA to an authenticator app while cleaning recovery options. Overall sentiment is urgent and precautionary, emphasizing that the attacker likely still has an authorized app permission and/or an active trusted session rather than the attacker’s access being fully removed by password changes.