Over 31,000 Scam Emails Abuse Microsoft Authentication System in Seven Weeks

Kaspersky says scammers are using real Microsoft links and notices to make fake emails look trustworthy.

ISLAMABAD – (Staff Reporter/Web Desk) – Cybersecurity experts at Kaspersky have found a new email scam that misuses the Microsoft authentication system. The emails carry real Microsoft links, so they look safe at first glance.

Between August 1 and September 18, Kaspersky tools blocked more than 31,000 emails of this kind. Earlier this year, the company spotted a similar campaign that abused the same technology.

This time, the scammers use a different bait. Their emails pretend to be official Microsoft messages. They ask users to update their account details or sign an electronic document.

How the Redirect Trick Works

The attackers first create their own Microsoft account. Then they log in to the Microsoft Entra admin center and register a new application.

During registration, the service asks for a redirect address. This is the page where a user lands after logging in. The scammers put the link to their harmful website in this field.

Next, they send emails with a real Microsoft link. The link contains the app’s ID and the redirect address they set.

When a user clicks it, they first see a genuine Microsoft page. Then they are quietly sent to the scammers’ website. That site may try to steal personal data or install harmful software.

Fake Messages Inside Real Notices

The scammers found a second trick. They place their own text inside genuine Microsoft notifications.

Experts believe the attackers buy the cheapest license or start a free trial. They then write a fake message in the name field on the Overview page.

After that, they create fake users with made-up email addresses, display names, and passwords.

Next, they log in to the Microsoft My Account portal as one of these fake users. There, they enter the victim’s real email address as the backup mailbox. This mailbox normally receives password reset messages.

As a result, the victim gets a verification code they never asked for. The scammers’ message appears in the subject line and signature of that email.

Why This Scam Is Hard to Spot

Most phishing emails come from a fake sender or a strange website. Here, the message is sent through an official service. That makes it look far more believable.

Andrey Kovtun, who manages the Email Threats Protection Group at Kaspersky, said this is not the first time attackers have used trusted services. He explained that the usual warning signs do not work well here, so users can rarely spot the scam alone.

How to Stay Safe

Be careful with any email that asks you to update credentials or sign a document, even if the link looks real.

Do not click right away. Open the official Microsoft website yourself and check your account from there.

If you get a verification code you did not request, do not ignore it. Someone may have added your email to a fake account. Never share the code with anyone.

Kaspersky also advises using a strong security tool with anti-phishing protection. It can block harmful links automatically, even when they are well hidden.

Companies can use Kaspersky Security for Mail Server to guard against advanced email threats. Home users can choose Kaspersky Premium for anti-phishing protection.

The key lesson is simple. A real link does not always mean a safe message. Always think before you click.

Comments are closed, but trackbacks and pingbacks are open.