Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

51–60 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#51
I'm receiving daily about 20 to 30 spam mails from google servers. I'm sorting them into a separate SPAM folder for the "fun" of it.

Who to contact? How to make Google stop? Where to report the abuse of their services? I can't find out. The whole service is basically a big off and "we don't want any contact."

Maybe I also need to publish some article, so it can be published here on HN? Maybe that could give it some traction for someone at Google to look into it?

Re: Scammers are abusing an internal Microsoft account to send spam links

#52
post #20

Earlier quoted context omitted.

Sending your id to a social media IS a scam.

What definition of the word scam are you using here? What promise of a product that you pay for that isn't being delivered, with uploading your id to a site on the Internet?

I'm not gonna get hoodwinked into highbrow shenanigans. Social media doesn't need IDs to work, demanding it is a scam.

Re: Scammers are abusing an internal Microsoft account to send spam links

#53

I'm receiving daily about 20 to 30 spam mails from google servers. I'm sorting them into a separate SPAM folder for the "fun" of it. Who to contact? How to make Google stop? Where to report the abuse of their services? I can't find out. The whole service is basically a big off and "we don't want any contact." Maybe I also need to publish some article, so it can be published here on HN? Maybe that could give it some t…

You can try: https://support.google.com/mail/contact/abuse?hl=en

I submitted an account that sent phishing emails last week, but I’m told it’s basically a black hole and to not expect anything anything to happen.

Re: Scammers are abusing an internal Microsoft account to send spam links

#55
On a semi-related note, Microsoft security is genuinely terrible.

For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up.

Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password required. In their eternal wisdom this option is not changeable in the app.

Microsoft really should realize that the only reason the account still exists is because they bought Minecraft and stop complicating my life.

Re: Scammers are abusing an internal Microsoft account to send spam links

#56
post #52

Earlier quoted context omitted.

What definition of the word scam are you using here? What promise of a product that you pay for that isn't being delivered, with uploading your id to a site on the Internet?

I'm not gonna get hoodwinked into highbrow shenanigans. Social media doesn't need IDs to work, demanding it is a scam.

Defining a word isn't "highbrow shenanigans", although I guess it depends on how you define that.

Re: Scammers are abusing an internal Microsoft account to send spam links

#57
post #7

A while back I had a reservation with a hotel on Booking and I received a phish attempt that came directly via the Booking site domain email and also DMs but "sent" by the hotel. When I looked into it at the time, it seemed less like an issue of hotels specifically having their accounts infiltrated and more like some kind of message/email endpoint on Booking's end was being abused in a similar manner. I'm not sure th…

I have not seen one of these that wasn't a compromised hotel email or booking account. I have had to "help" a hotel get malware/RATs off their system more than a dozen times as a _guest_

Re: Scammers are abusing an internal Microsoft account to send spam links

#59

Earlier quoted context omitted.

That would take nothing to implement. Services like Truecaller already do live caller ID against databases on iOS / Android. All it would take is a sensible register of verified numbers

Several of the bank scammers had their profile verified as the bank in the Truecaller[1]. [1] https://xcancel.com/Abishek_Muthian/status/18063480222902113...

Truecaller can tell you about who a phone number belongs to.

Truecaller cannot accurately tell you whether or not the person calling you from a phone number is actually in control of that phone number.

Re: Scammers are abusing an internal Microsoft account to send spam links

#60
post #55

On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…

I've been getting this too, authenticator prompts saying "logged in" and asking for confirmation, but no history whatsoever when I went to security to check.

It freaked me out the first time, I went through all the security settings I could find, but it was if it never happened.

I just ignored it the second time, but it's a bit unsettling, because the default authenticator flow also has the chance of accidentally hitting the right number.

Post reply on HN