Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.
https://github.com/HotCakeX/MicrosoftDomains ...and microsoftonline.com is not among them (unlike microsoftonline.net and other variants). But it seems to have been registered in 2002, and the record looks legit: https://whois.domaintools.com/microsoftonline.com
Scammers are abusing an internal Microsoft account to send spam links
91–100 of 196 posts
Re: Scammers are abusing an internal Microsoft account to send spam links
#92On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…
I've been getting this too, authenticator prompts saying "logged in" and asking for confirmation, but no history whatsoever when I went to security to check. It freaked me out the first time, I went through all the security settings I could find, but it was if it never happened. I just ignored it the second time, but it's a bit unsettling, because the default authenticator flow also has the chance of accidentally hit…
Re: Scammers are abusing an internal Microsoft account to send spam links
#93Earlier quoted context omitted.
It is the same company that want to stop SMS 2fa to force you to use their shitty authenticator app.
SMS 2FA is the worst factor because of how insecure and phishable the phone network is, it deserves to die out where possible
Re: Scammers are abusing an internal Microsoft account to send spam links
#94Re: Scammers are abusing an internal Microsoft account to send spam links
#95Earlier quoted context omitted.
I've been getting this too, authenticator prompts saying "logged in" and asking for confirmation, but no history whatsoever when I went to security to check. It freaked me out the first time, I went through all the security settings I could find, but it was if it never happened. I just ignored it the second time, but it's a bit unsettling, because the default authenticator flow also has the chance of accidentally hit…
Is that because it’s two digits?
1 in 3 and easy to hit by mistake.
Re: Scammers are abusing an internal Microsoft account to send spam links
#96Earlier quoted context omitted.
This was a common issue when I consulted with bankruptcy lawyers and had to figure out what domain assets the company had. Commonly the representatives only knew about some of the domains and we found at least a few more. Same with third party services, sometimes they used one for something for a while and collected customer or user data there and then stopped but kept paying for it, and forgot they had it. We typica…
Having a service crap out because someone didn’t pay for the domain is almost a trope. It never occurred to me that the reverse might happen - paying for unused domains.
Easier to just keep paying.
Re: Scammers are abusing an internal Microsoft account to send spam links
#97I feel sad that what I think of as the obvious solution, companies using subdomains like internal.microsoft.com instead of making a million different domains, is so far from happening that no one here on HN has even brought it up.
Reminds me, we once got a letter by a German government body requesting some data exports from our company, and to upload them on findrive-ni.de
It turned out to be legit, but it's neither a subdomain of the state of Niedersachsen domain nor referenced in their official sites.
Re: Scammers are abusing an internal Microsoft account to send spam links
#98Re: Scammers are abusing an internal Microsoft account to send spam links
#99Earlier quoted context omitted.
> They are not scam calls What are they, then? Sales/marketing calls? Or some security notifications ("we noticed some suspicious operations in the last 3 days...")? If it's the former, that's still scam in my books. Specifically, it's a first-party scam , as opposed to a third-party scam , where some third party pretends to be your bank. They both should be treated similarly; unfortunately, you can't report first-pa…
Yeah as sibling points out, lots of orgs have scammy official security calls. This leads to a dance I have been through quite often. Hello Them: Am I speaking to Sean Hunter Me: Yes Them: This is . Can you confirm your Me: Yes Them: Err, … sorry I didn’t quite catch that. Me: Yes. Them: I asked whether you can confirm your Me: Yes. I can. Them: err… I can’t talk to you without you passing security. Me: You called me.…
Only to find the 2 pieces of ID were just for them to talk to me and ask for more documents. Rubbish like employment letters (uhhhh, how about YOU call my employer instead of me printing out the “letter” they’ll email me?) or tax return stuff mid-year.
I cut up the credit card and mailed the pieces to their legal department. Someone called me pretty quick and without any authentication hassles.