

“You fell for a phishing scam and hadn’t enabled two-factor authentication” is more likely, followed closely by “You used the same password for another service/platform that got compromised”.
Microsoft are being unhelpful here and deserve to be criticised, but the fault for the “hack” is almost certainly the responsibility of the user.






I eyeballed an edit, because the horizon line and lack of squareness bothered me: