Discovering that your digital workspace has been compromised is a stressful experience, especially when critical documents are missing, modified, or held hostage by ransomware. When unauthorized users gain access to your Microsoft account, they often delete folders or overwrite files to cause disruption. Fortunately, Microsoft cloud services maintain a strict version history and deletion retention policy, allowing you to reverse these malicious actions. This troubleshooting guide provides the exact sequential steps to regain control and walks you through the recovery workflows to get your data back.
Securing Your Access Before Learning Restore OneDrive Files After an Account Is Hacked

Before executing any data recovery commands, you must definitively sever the hacker's connection to your account. If you restore your files while an unauthorized user still has active session tokens, they will simply delete or encrypt your files again.
- Navigate to account.microsoft.com and sign in with your credentials.
- Click on the Security tab in the top navigation bar, then select Advanced security options.
- Select Sign me out everywhere. This action forcefully terminates all active sessions across desktop applications, mobile apps, and web browsers within 24 hours.
- Immediately click Change password and generate a strong, unique credential that you have never used on any other website.
- Under the same security menu, verify your recovery email and phone number. Hackers often replace these with their own to facilitate a secondary breach. Delete any unrecognized contact methods.
- Toggle on Two-step verification using an authenticator app. This ensures that even if the attacker intercepts your new password, they cannot bypass the login screen.
Once you verify that your account settings reflect only your own devices and contact methods, you can safely proceed to the file restoration phase.
Restore OneDrive Files After an Account Is Hacked
If you have a Microsoft 365 subscription, your primary solution is the built-in "Restore your OneDrive" feature. This mechanism acts as a complete time machine for your cloud storage, allowing you to undo all actions—including mass deletions and ransomware encryptions—that occurred within the last 30 days.
- Log into your account at onedrive.live.com using a web browser. Do not attempt this through the Windows File Explorer desktop app.
- Click the Settings gear icon located in the top-right corner of the screen, then click Options from the dropdown menu.
- In the left-hand navigation pane, select Restore your OneDrive. If you are prompted to verify your identity via your authenticator app or email, complete the security challenge.
- On the restoration page, click the Select a date dropdown menu. You can choose preset intervals such as Yesterday or One week ago, but selecting Custom date and time offers the most precision.
- Examine the activity chart and the daily activity feed. This feed displays a chronological list of every file creation, modification, or deletion. Scroll down to identify the exact timestamp where the unauthorized user began altering your files.
- Check the box next to the earliest malicious activity. Selecting an activity automatically highlights all subsequent activities that occurred after it.
- Click the blue Restore button at the top of the page. The system will begin rolling back your entire cloud directory to the exact state it was in immediately prior to the selected event.
To verify the result, navigate back to your main files directory and open a document that was previously encrypted or deleted. Check its version history to ensure the original content is intact.
Using the Recycle Bin: Restore OneDrive Files After an Account Is Hacked
If you do not have a premium Microsoft 365 subscription, the full point-in-time rollback feature is unavailable. Instead, you must manually rescue your deleted files using the cloud recycle bins. Personal accounts retain deleted files in the bin for 30 days, while work or school accounts retain them for 93 days.
- Open your web browser and navigate to onedrive.live.com.
- Click on Recycle bin located in the left-hand navigation pane.
- Review the list of items. To recover everything the hacker removed, click the circle icon at the very top of the list to select all items, then click Restore in the top command bar.
- If the hacker manually emptied this primary bin, scroll to the absolute bottom of the page and click the link labeled Second-stage recycle bin. Microsoft maintains this hidden secondary tier precisely for administrative recovery after malicious purges.
- Select your files within the second-stage bin and click Restore. The items will return to their original directory paths.
Work on Local Copies in WPS Office While OneDrive Is Repaired

WPS Office cannot interface with Microsoft's servers to change your cloud account settings or directly trigger a OneDrive rollback. However, if your cloud-hosted files were wiped by an attacker and your local Windows sync folder subsequently deleted the local copies, WPS Office offers a powerful local recovery workflow. If you previously opened or edited the missing documents using WPS Office, the software's local caching and auto-backup tools may have preserved your drafts.
- Launch the main WPS Office application on your desktop.
- Click on Menu (the three horizontal lines) in the top-left corner, hover over Backup and Recovery, and select Auto Backup.
- A new dialog box will appear. Click on Local Backup to open the hidden directory on your hard drive where WPS automatically saves intermittent drafts of your work.
- Sort the folder contents by Date modified to quickly locate the versions of your documents saved immediately before the account breach occurred.
- Open the target document. If it contains the correct data, click File, select Save As, and save the document to a secure local folder entirely disconnected from your compromised cloud sync directory.
Once your immediate crisis is resolved, you can utilize the WPS Cloud infrastructure. By enabling WPS Document Roaming, your file history is saved independently of your operating system's default sync folders, providing an isolated, secure backup layer in the event of future Microsoft account vulnerabilities.
FAQs About Restoring OneDrive Files After an Account Is Hacked
Can I roll back my OneDrive if I do not have a Microsoft 365 subscription?
No, the specific "Restore your OneDrive" point-in-time rollback tool is exclusive to Microsoft 365 Personal, Family, and Business subscribers. If you operate on a free basic account, you must rely entirely on the first-stage and second-stage Recycle Bins or local hardware backups to retrieve files deleted during a hack.
How long do I have to recover deleted files after a security breach?
The recovery window depends strictly on your account type and the feature you are using. The rollback feature spans exactly 30 days for all users. For the Recycle Bin, standard personal accounts hold files for 30 days before permanent deletion, whereas enterprise or educational accounts extend this retention period to 93 days. Once these time limits expire, the server permanently purges the data.
What happens to my shared folders during a point-in-time restore?
Restoring your cloud directory only reverts the files and folders that physically reside in your personal storage quota. If you have files in a "Shared with me" folder that belong to another user, your rollback command will not affect them. Conversely, if an attacker modified a folder you own and share with others, the restore process will revert it for everyone who has access to that folder.
Will restoring my OneDrive remove legitimate files I created after the hack?
Yes. The restoration process is a comprehensive state reversal. Any new documents uploaded, edited, or created after the specific timestamp you selected for the restore will be undone. Before initiating the rollback, manually download any safe, newly created files to a local offline folder on your desktop so they are not erased by the time-machine effect.




