Observed Signal · May 21, 2026 · Security Incident · Source: techcrunch · Impact: 3/5 · Sentiment: Negative
Scammers Abuse Internal Microsoft Account to Send Spam
Scammers have been exploiting a loophole to send spam emails appearing to come from an internal Microsoft notification address (msonlineservicesteam@microsoftonline.com) that is normally used for legitimate account alerts like two-factor authentication. Attackers apparently create new Microsoft accounts and use that access to send emails with subject lines and links that mimic official alerts, directing recipients to scam websites. The Spamhaus Project confirmed the abuse and said the activity dates back several months; it has notified Microsoft. TechCrunch contacted Microsoft, which acknowledged the inquiry but has not confirmed whether the issue is resolved. The report notes similar incidents at other companies, and places this episode in a broader pattern of threat actors abusing trusted notification systems to phish users.
Abuse of a trusted platform notification address undermines user trust, increases phishing risk, and signals a vulnerability in account-notification systems that could affect many organizations and security practices across industries.
Track Microsoft Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Scammers have sent spam emails from msonlineservicesteam@microsoftonline.com, an address Microsoft uses for account notifications.
- The Spamhaus Project reported seeing the abuse and said the activity dates back several months.
- Attackers appear to create new Microsoft accounts and use them to send emails that mimic official alerts and include links to scam sites.
- Microsoft acknowledged TechCrunch's inquiry but has not publicly confirmed a fix or that the abuse has stopped.
- Users and social media posts indicate other companies' notification email addresses have also been abused.
Connected Companies & Entities
2 Entities mappedRelated Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Microsoft warns against SMS-based 2FA over AI phishing
Microsoft has warned IT administrators that SMS- and voice-based two-factor authentication (2FA) are increasingly vulnerable due to AI-assisted phishing and easier SIM-swapping. In an internal email, the company recommended migrating to phishing-resistant methods such as passkeys. Microsoft said it has observed a strong rise in AI-driven attacks with higher click-through rates that aim to capture passwords and MFA codes. As a consequence, Microsoft will disable SMS- and voice-based authentication for Entra ID accounts starting February 1, 2027; a timeline for personal Microsoft accounts has not yet been announced.
Public Wi‑Fi DNS Poisoning Hijacks Microsoft 365 Sessions
Security researchers report a campaign that compromises public Wi‑Fi gateway management interfaces (e.g., in hotels, conference centers) to forge DNS responses and WPAD proxy settings, redirecting users to fake Microsoft sign‑in pages. Attackers exploit the OAuth device‑code flow (Microsoft Entra ID) and WPAD to obtain MFA‑authenticated tokens and access Microsoft 365 sessions without installing malware on victims' devices. Activity has been observed since June 2026 in the US, India, and Saudi Arabia. Detection techniques include monitoring for IOC IPs/domains, PAC/WPAD downloads (WinHttpAutoProxySvc), device‑code sign‑ins, and unusual post‑MFA access from unknown IPs/locations. Primary coverage cites SecurityWeek and a detailed ReliaQuest threat spotlight as sources.
FBI warns Microsoft 365 users about Kali365 phishing
The U.S. FBI has issued a public advisory warning Microsoft 365 users about a new phishing platform called Kali365. First observed in April and reported to circulate mainly on Telegram, Kali365 provides Phishing-as-a-Service tooling that helps attackers harvest OAuth access and refresh tokens via a device-code phishing flow. According to the FBI, criminals can use those tokens to bypass passwords and multi-factor authentication and access Microsoft 365 services such as Outlook, Teams and OneDrive. The FBI recommends restricting or disabling OAuth device-code flows except where absolutely necessary and following other hardening measures to reduce exposure.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
