For months, scammers have been benefiting from a loophole that enables them to ship spammy emails from an inside Microsoft e-mail handle usually used for sending reliable account alerts.
It’s not clear how the scammers are abusing the system, however they’ve been in a position to arrange new Microsoft accounts as if they’re new prospects, and use that entry to ship out emails purportedly from the tech large itself, doubtlessly tricking folks into considering that these emails could also be real.
Microsoft doesn’t but seem to have gotten a deal with on the difficulty.
Final week, I acquired a number of, equally structured emails containing topic strains and internet hyperlinks to scammy websites from Microsoft throughout completely different e-mail accounts. These crudely made emails have been despatched from msonlineservicesteam@microsoftonline.coman e-mail account that Microsoft makes use of to ship essential notifications to customers, reminiscent of two-factor authentication codes and different essential alerts about their on-line account.
A few of these emails’ topic strains resembled official emails that might alert customers to fraudulent transactions, whereas different emails claimed to have a personal messaging ready for the recipient at an online handle talked about within the e-mail physique.

In a social post on Tuesdayanti-spam non-profit, The Spamhaus Mission, stated it had additionally seen Microsoft’s account notification e-mail handle being abused to ship spam, and that the exercise dated again “a number of months.”
“Automated notification methods shouldn’t enable this stage of customization,” wrote Spamhaus. The non-profit added that it has notified Microsoft of the difficulty.
When contacted by TechCrunch earlier this week, a Microsoft spokesperson acknowledged our inquiry, however has not but commented or stated if the corporate has stopped the abuse of its account notification e-mail.
That is the most recent in a rash of incidents wherein hackers or scammers have abused firm methods to trick unsuspecting prospects in current months. Earlier this 12 months, hackers broke right into a platform utilized by fintech agency Betterment to send out fraudulent notifications that presupposed to triple the worth of any crypto customers ship in — a broadly identified rip-off used to steal folks’s cryptocurrency.
Again in 2023, hackers similarly abused access to an e-mail account run by Namecheap to ship out phishing emails geared toward stealing folks’s credentials.
Different customers commenting on social media say that different corporations’ e-mail addresses are additionally getting used to ship out spam, suggesting the difficulty shouldn’t be restricted to Microsoft.
If you buy by hyperlinks in our articles, we may earn a small commission. This doesn’t have an effect on our editorial independence.
