惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
J
Java Code Geeks
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Engineering at Meta
Engineering at Meta
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
小众软件
小众软件
博客园 - 聂微东
酷 壳 – CoolShell
酷 壳 – CoolShell
月光博客
月光博客
Last Week in AI
Last Week in AI
博客园_首页
I
InfoQ
T
Tailwind CSS Blog
爱范儿
爱范儿
雷峰网
雷峰网
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
B
Blog
WordPress大学
WordPress大学
A
About on SuperTechFans
V
Visual Studio Blog
有赞技术团队
有赞技术团队
P
Proofpoint News Feed

Mashable

AdultFriendFinder 2016 data breach: Security improvements 5 AdultFriendFinder scams to avoid The best hookup apps of 2026: I swiped until my thumb hurt How to delete your AdultFriendFinder account Tax Day 2026 deals: Score free food from Burger King, Krispy Kreme, Popeyes, Wendy's, and more XChat to launch on iPhone and iPad The 9 best headphones and earbuds for working out in 2026 Health chatbots could pave the way for 'AI privilege' in court UFC 2026 livestream: How to watch UFC for free 'Mexodus' review: This live-looped musical is a theatrical miracle 'Zelda: Ocarina of Time' remake: 4 things I really, really want Boston Bruins vs. Tampa Bay Lightning 2026 livestream: How to watch NHL for free The DJI Mini 5 Pro drone is down to its record-low price at Amazon — save over $500 Best Hulu deals and bundles: Best streaming deals in April 2026 NYT Connections Sports Edition hints and answers for April 11: Tips to solve Connections #565 NYT Strands hints, answers for April 11, 2026 Today's Hurdle hints and answers for April 11, 2026 NYT Pips hints, answers for April 11, 2026 NYT Connections hints and answers for April 11. Tips to solve 'Connections' #1035. Wordle today: The answer and hints for April 11, 2026 Artemis 2 splashdown: Photos, videos of the astronauts' return Artemis II crew return to Earth with perfect splashdown All the streaming apps that raised prices in 2026 so far Artemis II: All the Apple, GoPro, and Microsoft gadgets on Orion 'Moon joy' takes off as NASA embraces a new space-age catchphrase The pros and cons of switching from Kindle to Kobo e-readers Apple will close its first unionized retail store 'The AI Doc' director: Cynicism is the only wrong answer to AI Artemis II return: How to livestream reentry and splashdown BTS 'Arirang' World Tour: How to watch it live in cinemas
Internal Microsoft account being used to send scams, phis...
2026-05-22 · via Mashable

If you've ever received an email from "[email protected]," you'll know that this is an official email address used by Microsoft.

However, users should be aware that emails from this official Microsoft address may be scam messages.

Scammers have figured out how to weaponize this legitimate Microsoft email address in order to send fraudulent emails to targets. And it appears that bad actors are ramping up their use of this method, too.


You May Also Like



Recently, multiple people on social media have shared that they received a scam email from a real Microsoft email address called [email protected]. The emails look like most emails from Microsoft, utilizing the template that the company frequently uses. However, the subject line of these emails are often about Bitcoin or a promoting a third-party website. The subject line also usually includes a phone number or website link that are not associated with Microsoft.

The reason these emails look like actual emails from Microsoft is because, technically, they are.

Normally, this Microsoft email is used by the company in order to send email notifications such as two-factor authentication codes or account notices. However, scammers have found that they can inject their fraudulent schemes into this legitimate email, bypassing any sort of scam or spam detection filters in users' email inbox.

Mashable Light Speed

As TechCrunch writes in its report, Microsoft doesn't appear to have addressed the issue or released any statement yet on the matter.

However, it appears that this issue has been around for quite some time now.

A January report from cybersecurity company Abnormal detailed how bad actors were abusing Microsoft's notification email system and tricking it into sending phishing emails.

"The attack begins with the bad actor spinning up a disposable Microsoft 365 tenant," reads Abnormal's report. "The core exploit lies in the Tenant Branding configuration within Microsoft Entra ID. The attacker navigates to Tenant Properties and modifies the 'Name' field to contain a fraudulent financial alert message."

With the name modified with the scammer's message, the bad actor then tricks Microsoft into sending a verification code email to the target's email address. The scammer does this by asking Microsoft to add the target's email address to the attacker's Microsoft account. When the email is sent to the target, Microsoft includes their name in the subject line. But, again, in this case, the scammer has input their message to the victim as the name.

Because this attack utilizes Microsoft's trusted email address and does not include any malicious hyperlinks or attachments, these scam emails are easily bypassing any sort of security measures.

As cybercriminals get craftier and more resourceful, internet users should remain vigilant and take a close look at emails they receive, even if the sender appears to check out.