ImportantSecurity & Privacy
Scammers are abusing an internal Microsoft account to send spam links
Scammers have exploited a security loophole in Microsoft's internal notification system to send phishing emails from legitimate Microsoft addresses (msonlineservicesteam@microsoftonline.com) for several months, potentially deceiving users into trusting malicious links. This incident reflects a broader vulnerability pattern across enterprise notification systems and demonstrates how attackers can leverage trusted communication channels to bypass user skepticism and security awareness. IT organizations must immediately audit notification system access controls and implement strict authentication protocols to prevent similar abuse of legitimate internal email infrastructure.

The loophole allows spammers and scammers to send emails from a legitimate Microsoft email address typically used for sending genuine account alerts.