诈骗者正在滥用微软内部账户发送垃圾链接。
Scammers are abusing an internal Microsoft account to send spam links

原始链接: https://techcrunch.com/2026/05/21/scammers-are-abusing-an-internal-microsoft-account-to-send-spam/

诈骗者正利用微软内部系统的一个漏洞,通过该公司官方通知地址 `[email protected]` 发送欺诈邮件。这些邮件伪装成安全通知或欺诈警告等合规账户提醒,诱骗收件人点击恶意链接。 据报道,此问题已持续数月。反垃圾邮件组织 Spamhaus Project 证实,滥用行为源于微软自动化系统允许过度的自定义设置。这一趋势反映出黑客正通过入侵企业平台来发起网络钓鱼攻击的普遍模式,此前 Betterment 和 Namecheap 等公司也曾遭遇类似事件。 针对相关报告,微软表示正在积极调查该漏洞,移除违规账户,并加强检测机制以防止进一步滥用。不过,微软尚未给出彻底解决该问题的明确时间表。

Hacker News 最新 | 过往 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 诈骗者正在滥用微软内部账户发送垃圾邮件链接 (techcrunch.com) 12 分,由 spike021 发布于 1 小时前 | 隐藏 | 过往 | 收藏 | 1 条评论 帮助 MichaelZuo 9 分钟前 [–] 当一个真正的微软域名在发送垃圾邮件时,它是如何运作的?其他电子邮件服务商是只惩罚该特定域名,还是会轻微波及所有微软域名?回复 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请 YC | 联系 搜索:
相关文章

原文

For months, scammers have been taking advantage of a loophole that allows them to send spammy emails from an internal Microsoft email address typically used for sending legitimate account alerts.

It’s not clear how the scammers are abusing the system, but they have been able to set up new Microsoft accounts as if they are new customers and use that access to send out emails purportedly from the tech giant, potentially tricking people into thinking these emails are genuine.

Microsoft doesn’t yet appear to have gotten a handle on the issue.

Last week, I received several, similarly structured emails containing subject lines and web links to scammy sites from Microsoft across different email accounts. These crudely made emails were sent from [email protected], an email account that Microsoft uses to send important notifications to users, such as two-factor authentication codes and other critical alerts about their online account.

Some of these emails’ subject lines resembled official emails that would alert users to fraudulent transactions, while other emails claimed to have a private message waiting for the recipient at a web address mentioned in the email body.

a copy of the spammy email, which comes from "msonlineservicesteam@microsoftonline.com" but contains clearly spammy content.
Image Credits:TechCrunch (screenshot)

In a social post on Tuesday, anti-spam nonprofit The Spamhaus Project said it had also seen Microsoft’s account notification email address being abused to send spam and that the activity dated back “several months.”

“Automated notification systems should not allow this level of customization,” wrote Spamhaus. The nonprofit added that it has notified Microsoft of the issue.

When contacted by TechCrunch earlier this week, Microsoft acknowledged our inquiry but did not comment by press time.

In a statement provided after publication by Emelia Katon, representing Microsoft via a third-party public relations agency, the company said: “We are actively investigating and taking action against these phishing reports to help keep customers protected. This includes further strengthening our detection and blocking mechanisms, while removing accounts that violate our Terms of Use.”

This is the latest in a rash of incidents in which hackers or scammers have abused company systems to trick unsuspecting customers in recent months. Earlier this year, hackers broke into a platform used by fintech firm Betterment to send out fraudulent notifications that purported to triple the value of any crypto users send in — a widely known scam used to steal people’s cryptocurrency.

Back in 2023, hackers similarly abused access to an email account run by Namecheap to send out phishing emails aimed at stealing people’s credentials.

Other users commenting on social media say that other companies’ email addresses are also being used to send out spam, suggesting the issue is not limited to Microsoft.

Updated with a response from Microsoft.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

联系我们 contact @ memedata.com