Scammers are abusing an internal Microsoft account to send spam links
Scammers are sending spam and phishing emails from an internal Microsoft address used for account alerts. Microsoft says it is investigating and blocking accounts.
Intelligence analysis by GPT-5.4 Mini
TechCrunch reports that scammers have been exploiting a Microsoft account notification address to send convincing spam emails for months. The abuse appears to let messages look like official Microsoft alerts, raising the odds that users will click malicious links.
Some bad actors found a way to send scam emails from a Microsoft address that usually sends real warnings.
That is like a fake letter wearing a real company’s uniform. People are much more likely to open it because it looks official.
Microsoft says it is investigating and blocking the problem. The story shows that even trusted email systems can be turned into traps.
Analysis
How the scam works
TechCrunch says scammers have been using Microsoft’s msonlineservicesteam@microsoftonline.com address, which Microsoft normally uses for legitimate account alerts such as two-factor authentication codes and other critical notifications. The emails seen by the reporter contained scammy links and subject lines designed to look official, including messages about fraudulent transactions or supposed private messages waiting for the recipient.
What makes it concerning
The abuse appears to rely on a loophole that lets scammers set up new Microsoft accounts as if they were regular customers, then use that access to send emails that appear to come from Microsoft. The exact mechanism is not clear, but the impact is straightforward, because recipients may assume the mail is authentic when it comes from a known Microsoft notification address.
External confirmation
The Spamhaus Project said on social media that it had also seen the Microsoft account notification email address used for spam, and said the activity dated back several months. Spamhaus said automated notification systems should not allow that level of customization and said it had notified Microsoft.
Microsoft’s response
Microsoft initially did not comment by press time, then later said it was actively investigating the phishing reports and taking action to protect customers. The company said it was strengthening detection and blocking mechanisms and removing accounts that violate its terms of use.
Broader pattern
The article frames this as part of a wider problem in which attackers abuse trusted company systems to send phishing messages. It cites similar incidents involving Betterment and Namecheap, and notes that other companies’ addresses may also be in use for spam.
Key points
- Scammers have been sending phishing emails from a Microsoft notification address.
- The address is normally used for legitimate account alerts and 2FA codes.
- Spamhaus said the abuse has been going on for months and notified Microsoft.
- Microsoft says it is investigating, strengthening detection and blocking, and removing violating accounts.
- The article says similar abuse has hit other companies' email systems too.



