Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

91–100 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#91
post #36

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

https://github.com/HotCakeX/MicrosoftDomains ...and microsoftonline.com is not among them (unlike microsoftonline.net and other variants). But it seems to have been registered in 2002, and the record looks legit: https://whois.domaintools.com/microsoftonline.com

I did not expect 645 entries!! That is insane.

Re: Scammers are abusing an internal Microsoft account to send spam links

#92
post #60
post #55

On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…

I've been getting this too, authenticator prompts saying "logged in" and asking for confirmation, but no history whatsoever when I went to security to check. It freaked me out the first time, I went through all the security settings I could find, but it was if it never happened. I just ignored it the second time, but it's a bit unsettling, because the default authenticator flow also has the chance of accidentally hit…

Is that because it’s two digits?

Re: Scammers are abusing an internal Microsoft account to send spam links

#93

Earlier quoted context omitted.

It is the same company that want to stop SMS 2fa to force you to use their shitty authenticator app.

SMS 2FA is the worst factor because of how insecure and phishable the phone network is, it deserves to die out where possible

But they could allow other 2fa apps, but they force their shitty one.

Re: Scammers are abusing an internal Microsoft account to send spam links

#95
post #92
post #60

Earlier quoted context omitted.

I've been getting this too, authenticator prompts saying "logged in" and asking for confirmation, but no history whatsoever when I went to security to check. It freaked me out the first time, I went through all the security settings I could find, but it was if it never happened. I just ignored it the second time, but it's a bit unsettling, because the default authenticator flow also has the chance of accidentally hit…

Is that because it’s two digits?

No, because the default is to present you 3 numbers and asks you which your number is!

1 in 3 and easy to hit by mistake.

Re: Scammers are abusing an internal Microsoft account to send spam links

#96
post #32

Earlier quoted context omitted.

This was a common issue when I consulted with bankruptcy lawyers and had to figure out what domain assets the company had. Commonly the representatives only knew about some of the domains and we found at least a few more. Same with third party services, sometimes they used one for something for a while and collected customer or user data there and then stopped but kept paying for it, and forgot they had it. We typica…

Having a service crap out because someone didn’t pay for the domain is almost a trope. It never occurred to me that the reverse might happen - paying for unused domains.

We pay for a bunch of old domains because nobody in the org can definitively say we never used it and/or don’t use it anymore.

Easier to just keep paying.

Re: Scammers are abusing an internal Microsoft account to send spam links

#97
post #94

I feel sad that what I think of as the obvious solution, companies using subdomains like internal.microsoft.com instead of making a million different domains, is so far from happening that no one here on HN has even brought it up.

You are correct.

Reminds me, we once got a letter by a German government body requesting some data exports from our company, and to upload them on findrive-ni.de

It turned out to be legit, but it's neither a subdomain of the state of Niedersachsen domain nor referenced in their official sites.

Re: Scammers are abusing an internal Microsoft account to send spam links

#99

Earlier quoted context omitted.

> They are not scam calls What are they, then? Sales/marketing calls? Or some security notifications ("we noticed some suspicious operations in the last 3 days...")? If it's the former, that's still scam in my books. Specifically, it's a first-party scam , as opposed to a third-party scam , where some third party pretends to be your bank. They both should be treated similarly; unfortunately, you can't report first-pa…

Yeah as sibling points out, lots of orgs have scammy official security calls. This leads to a dance I have been through quite often. Hello Them: Am I speaking to Sean Hunter Me: Yes Them: This is . Can you confirm your Me: Yes Them: Err, … sorry I didn’t quite catch that. Me: Yes. Them: I asked whether you can confirm your Me: Yes. I can. Them: err… I can’t talk to you without you passing security. Me: You called me.…

One of my banks refused to talk to me over the phone and informed me to go to a branch with 2 pieces of ID. Fair, it was a credit card opened online.

Only to find the 2 pieces of ID were just for them to talk to me and ask for more documents. Rubbish like employment letters (uhhhh, how about YOU call my employer instead of me printing out the “letter” they’ll email me?) or tax return stuff mid-year.

I cut up the credit card and mailed the pieces to their legal department. Someone called me pretty quick and without any authentication hassles.

Post reply on HN