Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

31–40 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#31

Earlier quoted context omitted.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

Knowing what numbers are real through an official publication is very good, but it only allows you to place trust in calls you make, not calls you receive, because making calls doesn't involve caller ID, receiving calls does, and caller ID is spoofable.

That's the number one rule though. If someone calls you claiming to be your bank, just say "I'll call you back"

Re: Scammers are abusing an internal Microsoft account to send spam links

#32

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

This was a common issue when I consulted with bankruptcy lawyers and had to figure out what domain assets the company had. Commonly the representatives only knew about some of the domains and we found at least a few more.

Same with third party services, sometimes they used one for something for a while and collected customer or user data there and then stopped but kept paying for it, and forgot they had it. We typically found these through analysis of their accounting.

Re: Scammers are abusing an internal Microsoft account to send spam links

#33

Earlier quoted context omitted.

Knowing what numbers are real through an official publication is very good, but it only allows you to place trust in calls you make, not calls you receive, because making calls doesn't involve caller ID, receiving calls does, and caller ID is spoofable.

That would take nothing to implement. Services like Truecaller already do live caller ID against databases on iOS / Android. All it would take is a sensible register of verified numbers

Several of the bank scammers had their profile verified as the bank in the Truecaller[1].

[1] https://xcancel.com/Abishek_Muthian/status/18063480222902113...

Re: Scammers are abusing an internal Microsoft account to send spam links

#34
post #29
post #27

Earlier quoted context omitted.

> Who even can be sure microsoftonline.com is legit Spam filters.

I'm either impressed by whatever spam filter you having literally zero false positives or negatives, or I'm confused about what you think it means to "be sure".

I have plenty of false negatives, mostly due to companies in know I get a mail from using spamlike html mails, I always verify on the phone it is the mail they send to be sure but it happens way too often.

Re: Scammers are abusing an internal Microsoft account to send spam links

#35
post #31

Earlier quoted context omitted.

Knowing what numbers are real through an official publication is very good, but it only allows you to place trust in calls you make, not calls you receive, because making calls doesn't involve caller ID, receiving calls does, and caller ID is spoofable.

That's the number one rule though. If someone calls you claiming to be your bank, just say "I'll call you back"

Ask them their name/ last initial, employee ID or unique identifier for the conversation, direct phone number, job title and what location they're based at. Scammers will pretty much always refuse/argue/hang up on this (once I had one start insulting my mother in Hindi when I asked him this). Then call your bank's proper number and verify all of these details.

(But in any case your bank will never call outwards to you, unless you've specifically requested that, which you almost never do.)

Re: Scammers are abusing an internal Microsoft account to send spam links

#36

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

https://github.com/HotCakeX/MicrosoftDomains

...and microsoftonline.com is not among them (unlike microsoftonline.net and other variants). But it seems to have been registered in 2002, and the record looks legit:

https://whois.domaintools.com/microsoftonline.com

Re: Scammers are abusing an internal Microsoft account to send spam links

#38
post #20

Earlier quoted context omitted.

Bluesky is even worse, some of their emails come from "moderation@blueskyweb.xyz". They have to make posts to assure people it's not a scam, especially as they'll ask you to mail ID etc to that address: https://bsky.app/profile/safety.bsky.app/post/3ljp6zi7tp227

Sending your id to a social media IS a scam.

What definition of the word scam are you using here? What promise of a product that you pay for that isn't being delivered, with uploading your id to a site on the Internet?

Re: Scammers are abusing an internal Microsoft account to send spam links

#39
post #35
post #31

Earlier quoted context omitted.

That's the number one rule though. If someone calls you claiming to be your bank, just say "I'll call you back"

Ask them their name/ last initial, employee ID or unique identifier for the conversation, direct phone number, job title and what location they're based at. Scammers will pretty much always refuse/argue/hang up on this (once I had one start insulting my mother in Hindi when I asked him this). Then call your bank's proper number and verify all of these details. (But in any case your bank will never call outwards to yo…

Unfortunately my UK banks (and others) DO regularly make calls to me unannounced and demand my ID to 'prove who I am'. They are not scam calls and the callers cannot understand what they are doing wrong. If I'd had more strength in the last round of this stupidity I'd have done a number on them with the regulator. (I used to work in finance and was the director of a regulated financial entity, so I think I'd have a head start.)

Re: Scammers are abusing an internal Microsoft account to send spam links

#40
post #39
post #35

Earlier quoted context omitted.

Ask them their name/ last initial, employee ID or unique identifier for the conversation, direct phone number, job title and what location they're based at. Scammers will pretty much always refuse/argue/hang up on this (once I had one start insulting my mother in Hindi when I asked him this). Then call your bank's proper number and verify all of these details. (But in any case your bank will never call outwards to yo…

Unfortunately my UK banks (and others) DO regularly make calls to me unannounced and demand my ID to 'prove who I am'. They are not scam calls and the callers cannot understand what they are doing wrong. If I'd had more strength in the last round of this stupidity I'd have done a number on them with the regulator. (I used to work in finance and was the director of a regulated financial entity, so I think I'd have a h…

Yeah and people call crypto a scam.

It mostly is, but Monero is pretty good.

Post reply on HN