AUTO-UPDATED

Users report phishing emails coming from Microsoft’s system, and the company is digging in

Scammers are exploiting a legitimate Microsoft email address to send sophisticated phishing messages, prompting an active investigation by the tech giant to secure its automated notification systems.

Key Points

  • Attackers are utilizing the official "msonlineservicesteam@microsoftonline.com" address to send fraudulent emails to unsuspecting users.
  • The compromised account is typically used by Microsoft to deliver legitimate two-factor authentication codes and security alerts.
  • Evidence suggests scammers created new Microsoft accounts to bypass security filters rather than spoofing the sender's address.
  • Microsoft is currently investigating the breach and removing accounts that violate its terms of service to prevent further phishing attempts.
  • Users are advised to verify links and remain cautious of suspicious subject lines that mimic official transaction or security notifications.

Why it Matters

This incident highlights a significant vulnerability in automated communication systems that users have been trained to trust for security alerts. If left unaddressed, such exploits could undermine the reliability of two-factor authentication and lead to widespread credential theft across the Microsoft ecosystem.
Windows Central Published by kevinokemwa@outlook.com (Kevin Okemwa) , Kevin Okemwa
Read original