Observed Signal · May 21, 2026 · Security Incident · Source: techcrunch · Impact: 3/5 · Sentiment: Negative

Scammers Abuse Internal Microsoft Account to Send Spam

Executive Signal Summary

Scammers have been exploiting a loophole to send spam emails appearing to come from an internal Microsoft notification address (msonlineservicesteam@microsoftonline.com) that is normally used for legitimate account alerts like two-factor authentication. Attackers apparently create new Microsoft accounts and use that access to send emails with subject lines and links that mimic official alerts, directing recipients to scam websites. The Spamhaus Project confirmed the abuse and said the activity dates back several months; it has notified Microsoft. TechCrunch contacted Microsoft, which acknowledged the inquiry but has not confirmed whether the issue is resolved. The report notes similar incidents at other companies, and places this episode in a broader pattern of threat actors abusing trusted notification systems to phish users.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Abuse of a trusted platform notification address undermines user trust, increases phishing risk, and signals a vulnerability in account-notification systems that could affect many organizations and security practices across industries.

SIGNAL RADAR

Track Microsoft Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Scammers have sent spam emails from msonlineservicesteam@microsoftonline.com, an address Microsoft uses for account notifications.
  • The Spamhaus Project reported seeing the abuse and said the activity dates back several months.
  • Attackers appear to create new Microsoft accounts and use them to send emails that mimic official alerts and include links to scam sites.
  • Microsoft acknowledged TechCrunch's inquiry but has not publicly confirmed a fix or that the abuse has stopped.
  • Users and social media posts indicate other companies' notification email addresses have also been abused.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: May 21, 2026
Original Coverage Title: “Scammers are abusing an internal Microsoft account to send spam links”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

IdentityAug 13, 2026

Microsoft warns against SMS-based 2FA over AI phishing

Microsoft has warned IT administrators that SMS- and voice-based two-factor authentication (2FA) are increasingly vulnerable due to AI-assisted phishing and easier SIM-swapping. In an internal email, the company recommended migrating to phishing-resistant methods such as passkeys. Microsoft said it has observed a strong rise in AI-driven attacks with higher click-through rates that aim to capture passwords and MFA codes. As a consequence, Microsoft will disable SMS- and voice-based authentication for Entra ID accounts starting February 1, 2027; a timeline for personal Microsoft accounts has not yet been announced.

Read assessment
IdentityJul 28, 2026

Public Wi‑Fi DNS Poisoning Hijacks Microsoft 365 Sessions

Security researchers report a campaign that compromises public Wi‑Fi gateway management interfaces (e.g., in hotels, conference centers) to forge DNS responses and WPAD proxy settings, redirecting users to fake Microsoft sign‑in pages. Attackers exploit the OAuth device‑code flow (Microsoft Entra ID) and WPAD to obtain MFA‑authenticated tokens and access Microsoft 365 sessions without installing malware on victims' devices. Activity has been observed since June 2026 in the US, India, and Saudi Arabia. Detection techniques include monitoring for IOC IPs/domains, PAC/WPAD downloads (WinHttpAutoProxySvc), device‑code sign‑ins, and unusual post‑MFA access from unknown IPs/locations. Primary coverage cites SecurityWeek and a detailed ReliaQuest threat spotlight as sources.

Read assessment
IdentityMay 28, 2026

FBI warns Microsoft 365 users about Kali365 phishing

The U.S. FBI has issued a public advisory warning Microsoft 365 users about a new phishing platform called Kali365. First observed in April and reported to circulate mainly on Telegram, Kali365 provides Phishing-as-a-Service tooling that helps attackers harvest OAuth access and refresh tokens via a device-code phishing flow. According to the FBI, criminals can use those tokens to bypass passwords and multi-factor authentication and access Microsoft 365 services such as Outlook, Teams and OneDrive. The FBI recommends restricting or disabling OAuth device-code flows except where absolutely necessary and following other hardening measures to reduce exposure.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.