Internal Microsoft account being used to send scams, phishing links

TL;DR AI
2 min readKey summary
Scammers are abusing a real Microsoft notification email address to send phishing messages.
Researchers say attackers can manipulate Microsoft tenant branding so Microsoft delivers a message with the scammer’s text in the subject line.
Because the email comes from a trusted Microsoft sender, it can look authentic and slip past common spam and phishing filters.
The tactic raises the risk of credential theft and financial fraud for Microsoft 365 users.



