Scammers are abusing an internal Microsoft account to send spam links

Scammers are abusing an internal Microsoft account to send spam links

Scammers have recently exploited a vulnerability in Microsoft's internal email system, enabling them to distribute spam emails from a legitimate Microsoft account typically reserved for important user notifications. While the exact method of this abuse remains unclear, it appears that these fraudsters are creating new Microsoft accounts to masquerade as genuine customers, thereby gaining access to send misleading emails that could deceive recipients into believing they are authentic communications from the tech giant. Reports indicate that users have received multiple emails from the address msonlineservicesteam@microsoftonline.com, which is normally used for critical notifications such as two-factor authentication codes. The content of these fraudulent emails often mimics legitimate alerts, including subject lines that resemble warnings about suspicious transactions and messages claiming that private communications await the recipients at provided links. The Spamhaus Project, an anti-spam non-profit, confirmed on social media that they had observed the misuse of Microsoft’s email notifications for spam purposes for several months. They criticized the company’s automated systems, stating that such extensive customization should not be permitted, and indicated that they have informed Microsoft about the ongoing issue. When approached for comment, a Microsoft representative acknowledged the inquiry but did not provide further details on whether they have addressed the reported abuse. This incident is part of a larger trend in which hackers and scammers have been leveraging corporate systems to deceive unsuspecting users. Earlier this year, a fintech company faced a similar crisis when hackers infiltrated their platform, sending out fraudulent notifications that promised unrealistic returns on cryptocurrency investments. Additionally, there have been other instances where hackers took control of email accounts from companies like Namecheap, using them to distribute phishing emails aimed at stealing user credentials. With reports indicating that other companies' email addresses are also being misused for spam, it raises concerns about the security of corporate communication systems across the board.

Sources : TechCrunch

Published On : May 21, 2026, 12:10

Computing
Linux Creator Challenges Developers: Embrace AI or Fork Off!

In a recent discussion surrounding the use of AI in software development, Linus Torvalds, the founder of Linux, voiced h...

Business Insider | Jul 26, 2026, 13:10
Linux Creator Challenges Developers: Embrace AI or Fork Off!
Science
Finland Unveils World's Largest Sand Battery to Tackle Renewable Energy Challenges

In a groundbreaking move to address the critical issue of renewable energy intermittency, a small town in southern Finla...

CNBC | Jul 25, 2026, 05:35
Finland Unveils World's Largest Sand Battery to Tackle Renewable Energy Challenges
Gadgets
Navigating the Future: Are Wearable AI Gadgets Ready to Transform Our Lives?

Imagine a typical workday where you and your colleagues sport discreet recorders on your clothing, while smart glasses s...

CNN | Jul 26, 2026, 16:10
Navigating the Future: Are Wearable AI Gadgets Ready to Transform Our Lives?
AI
The Rise of AI Distillation: A Controversial Technique Sparks Debate in Tech and Government

In recent discussions, a once-obscure topic in artificial intelligence has surged to the forefront of debates among tech...

CNBC | Jul 25, 2026, 12:15
The Rise of AI Distillation: A Controversial Technique Sparks Debate in Tech and Government
Startups
The Future of Work: Executives Weigh In on AI's Impact on Gen Z Careers

As generative artificial intelligence continues to rise, uncertainty looms for the incoming Gen Z workforce. Leaders fro...

Business Insider | Jul 26, 2026, 10:15
The Future of Work: Executives Weigh In on AI's Impact on Gen Z Careers
View All News