discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Scammers are abusing an internal Microsoft account to send spam links

Scammers are sending spam and phishing emails from an internal Microsoft address used for account alerts. Microsoft says it is investigating and blocking accounts.

By Zack Whittaker·May 24·techcrunch.com·2 min read

Intelligence analysis by GPT-5.4 Mini

TechCrunch reports that scammers have been exploiting a Microsoft account notification address to send convincing spam emails for months. The abuse appears to let messages look like official Microsoft alerts, raising the odds that users will click malicious links.

Why it matters

This is a trust-and-authentication problem at the heart of email security, since messages from a real vendor address can bypass user suspicion. It also shows how account systems themselves can be abused as delivery channels for phishing.

Some bad actors found a way to send scam emails from a Microsoft address that usually sends real warnings.

That is like a fake letter wearing a real company’s uniform. People are much more likely to open it because it looks official.

Microsoft says it is investigating and blocking the problem. The story shows that even trusted email systems can be turned into traps.

Analysis

How the scam works

TechCrunch says scammers have been using Microsoft’s msonlineservicesteam@microsoftonline.com address, which Microsoft normally uses for legitimate account alerts such as two-factor authentication codes and other critical notifications. The emails seen by the reporter contained scammy links and subject lines designed to look official, including messages about fraudulent transactions or supposed private messages waiting for the recipient.

What makes it concerning

The abuse appears to rely on a loophole that lets scammers set up new Microsoft accounts as if they were regular customers, then use that access to send emails that appear to come from Microsoft. The exact mechanism is not clear, but the impact is straightforward, because recipients may assume the mail is authentic when it comes from a known Microsoft notification address.

External confirmation

The Spamhaus Project said on social media that it had also seen the Microsoft account notification email address used for spam, and said the activity dated back several months. Spamhaus said automated notification systems should not allow that level of customization and said it had notified Microsoft.

Microsoft’s response

Microsoft initially did not comment by press time, then later said it was actively investigating the phishing reports and taking action to protect customers. The company said it was strengthening detection and blocking mechanisms and removing accounts that violate its terms of use.

Broader pattern

The article frames this as part of a wider problem in which attackers abuse trusted company systems to send phishing messages. It cites similar incidents involving Betterment and Namecheap, and notes that other companies’ addresses may also be in use for spam.

Key points

  • Scammers have been sending phishing emails from a Microsoft notification address.
  • The address is normally used for legitimate account alerts and 2FA codes.
  • Spamhaus said the abuse has been going on for months and notified Microsoft.
  • Microsoft says it is investigating, strengthening detection and blocking, and removing violating accounts.
  • The article says similar abuse has hit other companies' email systems too.

Originally reported at

techcrunch.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycybersecurityphishingmicrosoftemailscams

Author

Zack Whittaker

Intelligence analysis by

GPT-5.4 Mini

Published

May 24, 2026

Source

techcrunch.com

Share

Topics

securitycybersecurityphishingmicrosoftemailscams

Related

More from this desk

Jul 29·engadget.com

Pokémon Pokopia's First DLC Comes To Switch 2 On August 5

Pokémon Pokopia's first DLC, Bubbly Basin, arrives on August 5, introducing an underwater area to explore and a new Dive move. The update is part of the Pokémon Pokopia Expansion Pass, which costs $35.

Jul 29·9to5google.com

Galaxy Z Fold 8 gives apps new scaling options for its large displays

Samsung's Galaxy Z Fold 8 gets a new feature in One UI 9 that allows users to adjust the zoom level of individual apps on the large display. This feature is currently in beta and can be enabled in Samsung Labs.

Jul 29·techcrunch.com

Elon Musk’s X settles multiyear legal battle with the World Federation of Advertisers

Elon Musk's X has settled its multiyear legal battle with advertising trade group the World Federation of Advertisers (WFA). The settlement ends Musk's aggressive attempt to hold advertisers legally responsible for pulling spending from X over brand safety concerns.

Jul 29·9to5google.com

Samsung has restocked Galaxy Z Fold 8’s popular ‘Pistachio’ color, shipping in August

Samsung has restocked the Galaxy Z Fold 8 in the popular 'Pistachio' color, with shipping dates moved up to August. The device was previously delayed due to a sell-out and shipping issues.