Scammers are using a real Microsoft email address to send phishing messages

news
Scammers are using a real Microsoft email address to send phishing messages

Scammers have found a dangerous way to make phishing emails look more convincing. Instead of only spoofing Microsoft’s name, they are reportedly sending scam messages from a real Microsoft email address that is normally used for account alerts and authentication notices.

The address in question is [email protected]. This email is usually connected to Microsoft account notifications, including two factor authentication codes and other security messages. That makes the scam harder to spot because checking the sender address alone may not be enough.

Security warnings like this matter because many people have been trained to look at the sender first. If the address looks fake, they delete the email. But in this case, the warning is more serious because the messages appear to come from a genuine Microsoft system, not just a fake display name.

You should not trust an email only because the sender looks real

According to the report, the Microsoft address does not appear to be simply spoofed. Security researchers believe criminals may have found a way to misuse a legitimate Microsoft notification system or related account mechanism. The phishing links inside the emails may look official, but they can lead to fake pages designed to steal login details or account information.

Warning signWhat you should do
Email asks you to act urgentlyDo not click links inside the message
Sender looks like MicrosoftStill check the content carefully
Link points to an unfamiliar domainTreat it as suspicious
Message has odd wording or strange subject lineVerify directly through Microsoft
Account warning appears in emailOpen Microsoft’s website or app yourself

The safest response is simple. Do not click any links inside the email. Open the Microsoft website or the relevant Microsoft app directly, then check your account notifications from there. If there is no warning, alert, or account message inside your real Microsoft account, the email is likely fake.

This is especially important for messages that create panic. Phishing emails often tell you that your account will be locked, your password has expired, suspicious activity was detected, or immediate action is needed. That pressure is part of the trick. The goal is to make you click before you think.

Broken handset on a floor with pixel details. Robocall regulations, law against deepfakes and phone frauds. Vector illustration.

Microsoft has reportedly been informed and is investigating the issue. It is still unclear how the scammers are abusing the legitimate address, whether only certain workflows are affected, or whether the problem is tied to specific account notification systems.

For now, the best protection is caution. A real sender address does not automatically mean a real email. If a Microsoft message asks you to sign in, reset something, verify your account, or click a security link, do not follow the email link. Go to Microsoft directly and check from there.

This phishing method is worrying because it weakens one of the basic checks people rely on. But the rule is still clear: trust the official site or app, not the link inside the message.

Discover: News

Discussion (0)

Be the first to comment.