Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

71–80 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#71
post #39

Earlier quoted context omitted.

Unfortunately my UK banks (and others) DO regularly make calls to me unannounced and demand my ID to 'prove who I am'. They are not scam calls and the callers cannot understand what they are doing wrong. If I'd had more strength in the last round of this stupidity I'd have done a number on them with the regulator. (I used to work in finance and was the director of a regulated financial entity, so I think I'd have a h…

> They are not scam calls What are they, then? Sales/marketing calls? Or some security notifications ("we noticed some suspicious operations in the last 3 days...")? If it's the former, that's still scam in my books. Specifically, it's a first-party scam , as opposed to a third-party scam , where some third party pretends to be your bank. They both should be treated similarly; unfortunately, you can't report first-pa…

In my experience they're security calls. UK has good opt out marketing rules for legit companies.

But the usual security call is exactly like a spam call, no authentication from their end, immediately requesting id verification "answer these security questions", and refusing to go off script.

People have been asking for years to be able to lodge a security challenge code on their profile that can add confidence in the caller. Given there are already multiple security questions on an account, this could be a process change: the security challenge script becomes "the first and sixteenth characters of your mother's maiden name are 7 and F, what are the third and fifth characters of your first pets name".

Re: Scammers are abusing an internal Microsoft account to send spam links

#72

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

My bank has a feature whereby it'll tell you promoinently in their app if they are currently calling you.

Re: Scammers are abusing an internal Microsoft account to send spam links

#74
post #36

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

https://github.com/HotCakeX/MicrosoftDomains ...and microsoftonline.com is not among them (unlike microsoftonline.net and other variants). But it seems to have been registered in 2002, and the record looks legit: https://whois.domaintools.com/microsoftonline.com

It's definitely a Microsoft owned domain and actively used - for example in Azure Active Directory (Entra).

Re: Scammers are abusing an internal Microsoft account to send spam links

#75
post #39
post #35

Earlier quoted context omitted.

Ask them their name/ last initial, employee ID or unique identifier for the conversation, direct phone number, job title and what location they're based at. Scammers will pretty much always refuse/argue/hang up on this (once I had one start insulting my mother in Hindi when I asked him this). Then call your bank's proper number and verify all of these details. (But in any case your bank will never call outwards to yo…

Unfortunately my UK banks (and others) DO regularly make calls to me unannounced and demand my ID to 'prove who I am'. They are not scam calls and the callers cannot understand what they are doing wrong. If I'd had more strength in the last round of this stupidity I'd have done a number on them with the regulator. (I used to work in finance and was the director of a regulated financial entity, so I think I'd have a h…

In the US Caller ID has been so hopelessly compromised (for almost two decades now, that's on Congress) that financial institutions almost never make outbound calls, and only ever use standardized published numbers; I wasn't aware other countries differ so much.

Please tell us more context with regard to your UK banks making multiple unannounced calls demanding your ID ... were you an individual customer? finance director? MD? or what? Why on earth do they do that? Have you told them in writing not to? There must be more backstory to that.

Re: Scammers are abusing an internal Microsoft account to send spam links

#76

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

Recently, banks where also asked to put their official websites/netbanking on *.bank.in domains. I have wanted that for SO long.

Re: Scammers are abusing an internal Microsoft account to send spam links

#77
post #39

Earlier quoted context omitted.

Unfortunately my UK banks (and others) DO regularly make calls to me unannounced and demand my ID to 'prove who I am'. They are not scam calls and the callers cannot understand what they are doing wrong. If I'd had more strength in the last round of this stupidity I'd have done a number on them with the regulator. (I used to work in finance and was the director of a regulated financial entity, so I think I'd have a h…

> They are not scam calls What are they, then? Sales/marketing calls? Or some security notifications ("we noticed some suspicious operations in the last 3 days...")? If it's the former, that's still scam in my books. Specifically, it's a first-party scam , as opposed to a third-party scam , where some third party pretends to be your bank. They both should be treated similarly; unfortunately, you can't report first-pa…

Yeah as sibling points out, lots of orgs have scammy official security calls. This leads to a dance I have been through quite often.

    Hello
   Them: Am I speaking to Sean Hunter
   Me: Yes
   Them: This is . Can you confirm your 
   Me: Yes
   Them: Err, … sorry I didn’t quite catch that.
   Me: Yes.
   Them: I asked whether you can confirm your 
   Me: Yes.  I can.
   Them: err… I can’t talk to you without you passing security.
   Me: You called me.
   Them:  I’m sorry…?
   Me: You called me.  You wanting to talk to me about something is your problem.
   Them: I need you to pass security before I can talk to you.
   Me: OK, well.  Have a nice day.  
Almost this exact thing has happened multiple times with one of my bank accounts which I can’t completely shut because of boring reasons but I have basically deprecated because they do this sort of nonsense. My main bank now is much better.

Re: Scammers are abusing an internal Microsoft account to send spam links

#78
post #36

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

https://github.com/HotCakeX/MicrosoftDomains ...and microsoftonline.com is not among them (unlike microsoftonline.net and other variants). But it seems to have been registered in 2002, and the record looks legit: https://whois.domaintools.com/microsoftonline.com

microsoftonline.com is in that list.

Re: Scammers are abusing an internal Microsoft account to send spam links

#79
post #31

Earlier quoted context omitted.

Knowing what numbers are real through an official publication is very good, but it only allows you to place trust in calls you make, not calls you receive, because making calls doesn't involve caller ID, receiving calls does, and caller ID is spoofable.

That's the number one rule though. If someone calls you claiming to be your bank, just say "I'll call you back"

We have an app called bankid. If my bank calls me they'll ask me to open the app to auth, the app shows that the specific bank initiated auth and also says that they called me.

Same app is used to auth to government pages and all kinds of stuff online, even purchases.

Re: Scammers are abusing an internal Microsoft account to send spam links

#80

Earlier quoted context omitted.

> They are not scam calls What are they, then? Sales/marketing calls? Or some security notifications ("we noticed some suspicious operations in the last 3 days...")? If it's the former, that's still scam in my books. Specifically, it's a first-party scam , as opposed to a third-party scam , where some third party pretends to be your bank. They both should be treated similarly; unfortunately, you can't report first-pa…

In my experience they're security calls. UK has good opt out marketing rules for legit companies. But the usual security call is exactly like a spam call, no authentication from their end, immediately requesting id verification "answer these security questions", and refusing to go off script. People have been asking for years to be able to lodge a security challenge code on their profile that can add confidence in th…

In the UK, banks like Starling, Monzo and Revolut (and building societies such as Nationwide) have added a call status feature in their apps [0][1][2] that tells you if they are actually the ones calling.

[0] https://www.starlingbank.com/news/starling-bank-launches-in-...

[1] https://monzo.com/help/monzo-fraud-category/monzo-call-statu...

[2] https://www.bbc.co.uk/articles/c1mj02vr0emo

Post reply on HN