{"id":241505,"date":"2026-05-21T11:42:57","date_gmt":"2026-05-21T11:42:57","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/05\/21\/scammers-are-abusing-an-internal-microsoft-account-to-send-spam-links-techcrunch\/"},"modified":"2026-05-21T11:42:57","modified_gmt":"2026-05-21T11:42:57","slug":"scammers-are-abusing-an-internal-microsoft-account-to-send-spam-links-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2026\/05\/21\/scammers-are-abusing-an-internal-microsoft-account-to-send-spam-links-techcrunch\/","title":{"rendered":"Scammers are abusing an internal Microsoft account to send spam links | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">For months, scammers have been taking advantage of a loophole that allows them to send spammy emails from an internal Microsoft email address typically used for sending legitimate account alerts.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s not clear how the scammers are abusing the system, but they have been able to set up new Microsoft accounts as if they are new customers, and use that access to send out emails purportedly from the tech giant itself, potentially tricking people into thinking that these emails may be genuine.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft doesn\u2019t yet appear to have gotten a handle on the issue.<\/p>\n<p class=\"wp-block-paragraph\">Last week, I received several, similarly structured emails containing subject lines and web links to scammy sites from Microsoft across different email accounts. These <a rel=\"nofollow noopener\" href=\"https:\/\/mastodon.social\/@zackwhittaker\/116562360000833298\" target=\"_blank\">crudely made<\/a> emails were sent from <code>msonlineservicesteam@microsoftonline.com<\/code>, an email account that Microsoft uses to send important notifications to users, such as two-factor authentication codes and other critical alerts about their online account.<\/p>\n<p class=\"wp-block-paragraph\">Some of these emails\u2019 subject lines resembled official emails that would alert users to fraudulent transactions, while other emails claimed to have a private messaging waiting for the recipient at a web address mentioned in the email body.<\/p>\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><figcaption class=\"wp-element-caption\"><span class=\"wp-block-image__credits\"><strong>Image Credits:<\/strong>TechCrunch (screenshot) \/<\/span><\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">In <a rel=\"nofollow noopener\" href=\"https:\/\/infosec.exchange\/@spamhaus\/116601270466207765\" target=\"_blank\">a social post on Tuesday<\/a>, anti-spam non-profit, The Spamhaus Project, said it had also seen Microsoft\u2019s account notification email address being abused to send spam, and that the activity dated back \u201cseveral months.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cAutomated notification systems should not allow this level of customization,\u201d wrote Spamhaus. The non-profit added that it has notified Microsoft of the issue.<\/p>\n<p class=\"wp-block-paragraph\">When contacted by TechCrunch earlier this week, a Microsoft spokesperson acknowledged our inquiry, but has not yet commented or said if the company has stopped the abuse of its account notification email.<\/p>\n<p class=\"wp-block-paragraph\">This is the latest in a rash of incidents in which hackers or scammers have abused company systems to trick unsuspecting customers in recent months. Earlier this year, hackers broke into a platform used by fintech firm Betterment to <a href=\"https:\/\/techcrunch.com\/2026\/01\/12\/fintech-firm-betterment-confirms-data-breach-after-hackers-send-fake-crypto-scam-notification-to-users\/\" target=\"_blank\" rel=\"noopener\">send out fraudulent notifications<\/a> that purported to triple the value of any crypto users send in \u2014 a widely known scam used to steal people\u2019s cryptocurrency. <\/p>\n<p class=\"wp-block-paragraph\">Back in 2023, hackers <a rel=\"nofollow noopener\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/namecheaps-email-hacked-to-send-metamask-dhl-phishing-emails\/\" target=\"_blank\">similarly abused access<\/a> to an email account run by Namecheap to send out phishing emails aimed at stealing people\u2019s credentials.<\/p>\n<p class=\"wp-block-paragraph\">Other users commenting on social media say that other companies\u2019 email addresses are also being used to send out spam, suggesting the issue is not limited to Microsoft.<\/p>\n<\/div>\n<p><em>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" target=\"_blank\" rel=\"noopener\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/em><\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/05\/21\/scammers-are-abusing-an-internal-microsoft-account-to-send-spam\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>For months, scammers have been taking advantage of a loophole that allows them to send spammy emails from an internal Microsoft email address typically used for sending legitimate account alerts. It\u2019s not clear how the scammers are abusing the system, but they have been able to set up new Microsoft accounts as if they are [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":241506,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-241505","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/241505","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=241505"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/241505\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/241506"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=241505"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=241505"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=241505"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}