Scammers are abusing an internal Microsoft account to send spam links
101–110 of 196 posts
Re: Scammers are abusing an internal Microsoft account to send spam links
#102I feel sad that what I think of as the obvious solution, companies using subdomains like internal.microsoft.com instead of making a million different domains, is so far from happening that no one here on HN has even brought it up.
Re: Scammers are abusing an internal Microsoft account to send spam links
#103Earlier quoted context omitted.
In my experience they're security calls. UK has good opt out marketing rules for legit companies. But the usual security call is exactly like a spam call, no authentication from their end, immediately requesting id verification "answer these security questions", and refusing to go off script. People have been asking for years to be able to lodge a security challenge code on their profile that can add confidence in th…
In the UK, banks like Starling, Monzo and Revolut (and building societies such as Nationwide) have added a call status feature in their apps [0][1][2] that tells you if they are actually the ones calling. [0] https://www.starlingbank.com/news/starling-bank-launches-in-... [1] https://monzo.com/help/monzo-fraud-category/monzo-call-statu... [2] https://www.bbc.co.uk/articles/c1mj02vr0emo
Re: Scammers are abusing an internal Microsoft account to send spam links
#104Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.
Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.
Same in their app eg you try to do a sepa wire to a new recipient and you get a warning "are you on the phone with someone ? did someone ask you to do that ? please call your bank by pressing this button. By the way we will never call you to ask an auth code or to do a wire"
Re: Scammers are abusing an internal Microsoft account to send spam links
#105Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.
Re: Scammers are abusing an internal Microsoft account to send spam links
#106My employer's domain starts with "m". Bunch of people recently fell victim for a fishing email whose domain started with "rn". In Outlook 's font the two look almost identical.
Re: Scammers are abusing an internal Microsoft account to send spam links
#107I'm receiving daily about 20 to 30 spam mails from google servers. I'm sorting them into a separate SPAM folder for the "fun" of it. Who to contact? How to make Google stop? Where to report the abuse of their services? I can't find out. The whole service is basically a big off and "we don't want any contact." Maybe I also need to publish some article, so it can be published here on HN? Maybe that could give it some t…
You can try: https://support.google.com/mail/contact/abuse?hl=en I submitted an account that sent phishing emails last week, but I’m told it’s basically a black hole and to not expect anything anything to happen.
When doing a WHOIS on that IP we'll get a contact address for abuse reports: "google-cloud-compliance@google.com", but sending anything there, returns an error that the user doesn't exists.
Re: Scammers are abusing an internal Microsoft account to send spam links
#108Earlier quoted context omitted.
Bluesky is even worse, some of their emails come from "moderation@blueskyweb.xyz". They have to make posts to assure people it's not a scam, especially as they'll ask you to mail ID etc to that address: https://bsky.app/profile/safety.bsky.app/post/3ljp6zi7tp227
Hard to beat Outlook 2007 which had some "smart tags" feature that all referenced "5iantlavalamp.com", and things started breaking when that domain expired.
Re: Scammers are abusing an internal Microsoft account to send spam links
#109Earlier quoted context omitted.
Bluesky is even worse, some of their emails come from "moderation@blueskyweb.xyz". They have to make posts to assure people it's not a scam, especially as they'll ask you to mail ID etc to that address: https://bsky.app/profile/safety.bsky.app/post/3ljp6zi7tp227
Hard to beat Outlook 2007 which had some "smart tags" feature that all referenced "5iantlavalamp.com", and things started breaking when that domain expired.
Would you please explain more?
Re: Scammers are abusing an internal Microsoft account to send spam links
#110Earlier quoted context omitted.
Hard to beat Outlook 2007 which had some "smart tags" feature that all referenced "5iantlavalamp.com", and things started breaking when that domain expired.
I simultaneously don’t believe this and fully believe this is something they would do. Do you have any sources on this?
I was working in anti-spam at the time, so I was eyeballing a lot of raw email dumps and writing analysis scripts for "anomalous" urls, so it popped up fairly frequently.