A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation
I'm always disappointed when advisors in this forum send users down a rabbit hole of artificial intelligence bots and filling out forms when they know that the user will in all likelihood never be able to get their account back.
If an attacker has changed the username, password and security information of a Microsoft account, the original owner will never get it back and there isn't anything that Microsoft can do about it.
Microsoft doesn't know you personally, obviously. The only reason that you or any Microsoft account owner can access their account is because they submit the correct username and password, which was verified at the time the user created the account. Once a user has created their Microsoft account, they are free to change the username, password and the security information of that account, and Microsoft will allow the change because it's coming from an original username and password that Microsoft trusts.
If someone is able to steal your username and password, they can change that username and password, and the security information that protects it, which effectively locks you out of your own account.
Microsoft doesn't know who is sitting at the keyboard and typing on the keys - they only know that whoever is doing it is using a username and a password that they can trust.
So it's not that Microsoft 'can't be bothered' to give you your account back. They can't give your account back because it's not your account anymore - you're not able to provide the correct username and password. It's the same whether it's a Microsoft account or a Google account or an Apple account or any other account. Whoever enters the correct username and password is allowed to access the account.
It isn't Microsoft's responsibility to ascertain whether someone entering a valid username and password is entitled to enter that username and password.
For its part, Microsoft provides users with several tools that we can use to protect our account, including multi-factor authentication, passwordless account access, and account recovery codes. Each of these are very effective by themselves, and even more effective when used in combination with each other, but there is nothing in this world that can guarantee that someone's user account information can't be stolen. There's a well-known saying in the cybersecurity community: Attackers don't have to hack their way in, they log in.
Unfortunately, people waste time filling out forms and chatting with artificial intelligence - and insisting that they must speak with someone at Microsoft even though nobody at Microsoft can help them - when they should be changing their passwords, alerting their contacts not to accept messages from their old address, cancelling payment cards that they previously entered to the account and taking other steps to protect their identity.