Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

41–50 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#41
post #39
post #35

Earlier quoted context omitted.

Ask them their name/ last initial, employee ID or unique identifier for the conversation, direct phone number, job title and what location they're based at. Scammers will pretty much always refuse/argue/hang up on this (once I had one start insulting my mother in Hindi when I asked him this). Then call your bank's proper number and verify all of these details. (But in any case your bank will never call outwards to yo…

Unfortunately my UK banks (and others) DO regularly make calls to me unannounced and demand my ID to 'prove who I am'. They are not scam calls and the callers cannot understand what they are doing wrong. If I'd had more strength in the last round of this stupidity I'd have done a number on them with the regulator. (I used to work in finance and was the director of a regulated financial entity, so I think I'd have a h…

it is time we have a good industry standard for this stuff

Re: Scammers are abusing an internal Microsoft account to send spam links

#42
post #36

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

https://github.com/HotCakeX/MicrosoftDomains ...and microsoftonline.com is not among them (unlike microsoftonline.net and other variants). But it seems to have been registered in 2002, and the record looks legit: https://whois.domaintools.com/microsoftonline.com

but microsoftgenuinerewardsrc.com is! shameful!

Re: Scammers are abusing an internal Microsoft account to send spam links

#43

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

> unable publish a list with all domains they officially use to send mail That's because people report them as spam, so they hop domains to avoid that.

For a company with as much weight in the industry as Microsoft, it would be trivial to ensure their domains don’t end up on spam lists. Heck, because of outlook.com, they control have the spam lists themselves.

The real reason for multiple domains is likely more stupid than that. It’s likely because different teams want to move faster than the whole of Microsoft, so register a domain for their MVP to enable them to prototype like a start up. Because going through the usual hoops with enterprise regarding using their established domains will be a long and torturous process. And before long, their new prototype domain becomes so integrated into their product that adopting it as official is just easier than switching to microsoft.com.

I couldn’t say for sure that’s what has happened here. But it’s the story I’ve seen with domain ownership in other enterprises

Re: Scammers are abusing an internal Microsoft account to send spam links

#44

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

I got used to that one, but the other day I was checking Outlook in the web browser and I ended up on outlook.cloud.microsoft, I couldn't believe my eyes.

Re: Scammers are abusing an internal Microsoft account to send spam links

#45
post #20

Earlier quoted context omitted.

Bluesky is even worse, some of their emails come from "moderation@blueskyweb.xyz". They have to make posts to assure people it's not a scam, especially as they'll ask you to mail ID etc to that address: https://bsky.app/profile/safety.bsky.app/post/3ljp6zi7tp227

Sending your id to a social media IS a scam.

By email... Just to add insult to injury

Re: Scammers are abusing an internal Microsoft account to send spam links

#46
post #39

Earlier quoted context omitted.

Unfortunately my UK banks (and others) DO regularly make calls to me unannounced and demand my ID to 'prove who I am'. They are not scam calls and the callers cannot understand what they are doing wrong. If I'd had more strength in the last round of this stupidity I'd have done a number on them with the regulator. (I used to work in finance and was the director of a regulated financial entity, so I think I'd have a h…

it is time we have a good industry standard for this stuff

I dream of a time I don’t have a bank, or not in any traditional sense.

I’d been hunting for ways to use a Wisecard standoff a bank but got a bit wary of what would happen if they went bust. Government backed guarantee do not exist for Wise.

Re: Scammers are abusing an internal Microsoft account to send spam links

#47
post #16

Earlier quoted context omitted.

Bluesky is even worse, some of their emails come from "moderation@blueskyweb.xyz". They have to make posts to assure people it's not a scam, especially as they'll ask you to mail ID etc to that address: https://bsky.app/profile/safety.bsky.app/post/3ljp6zi7tp227

At least Bluesky has an excuse of not being a Fortune 50 company. What’s Microsoft’s excuse?

‘We built it 30 years ago, it’s sort of compatible with everything and we will never deprecate.’

It’s not a good excuse…

Re: Scammers are abusing an internal Microsoft account to send spam links

#48
post #32

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

This was a common issue when I consulted with bankruptcy lawyers and had to figure out what domain assets the company had. Commonly the representatives only knew about some of the domains and we found at least a few more. Same with third party services, sometimes they used one for something for a while and collected customer or user data there and then stopped but kept paying for it, and forgot they had it. We typica…

Having a service crap out because someone didn’t pay for the domain is almost a trope. It never occurred to me that the reverse might happen - paying for unused domains.

Re: Scammers are abusing an internal Microsoft account to send spam links

#49
post #13

I mean, it happened to the FBI... https://krebsonsecurity.com/2021/11/hoax-email-blast-abused-...

>The FBI is aware of a software misconfiguration

That's not a misconfiguration, that's incompetence.

How do these people get hired?

Post reply on HN