Scammers Are Exploiting a Microsoft Email Address to Send Spam and Phishing Links

Scammers have been exploiting a loophole in Microsoft’s systems for several months, using a legitimate internal Microsoft email address to send spam and phishing emails to unsuspecting users, according to a TechCrunch report published in May 2026.

The emails are being sent from msonlineservicesteam@microsoftonline.com, an address Microsoft uses for genuine account notifications such as two-factor authentication codes and critical account alerts. By sending from this address, scammers may trick recipients into believing the messages are legitimate communications from Microsoft.

It is not yet clear exactly how the loophole is being exploited, but scammers appear to have set up new Microsoft accounts as if they were ordinary customers and used that access to send outbound emails from the trusted address. The emails reported by TechCrunch contained subject lines mimicking fraud alerts and messages directing recipients to follow web links to scammy sites.

Anti-spam non-profit The Spamhaus Project confirmed it had also observed the abuse, noting the activity dates back “several months.” Spamhaus stated that “automated notification systems should not allow this level of customization” and said it had notified Microsoft of the issue. As of the report’s publication, Microsoft had acknowledged the inquiry but had not commented or confirmed whether the abuse had been stopped.

The incident is part of a broader pattern of scammers abusing company email systems. Earlier in 2026, hackers compromised a platform used by fintech firm Betterment to send fraudulent cryptocurrency notifications. In 2023, hackers similarly abused a Namecheap email account to send phishing emails targeting user credentials. Social media users have also reported other companies’ email addresses being used for spam, suggesting the problem may extend beyond Microsoft.

For users, this type of attack is particularly difficult to detect, as the emails originate from a verified address associated with a trusted company, potentially bypassing standard spam filters and user skepticism.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top