Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

121–130 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#121
post #95
post #92

Earlier quoted context omitted.

Is that because it’s two digits?

No, because the default is to present you 3 numbers and asks you which your number is! 1 in 3 and easy to hit by mistake.

Shouldn't there be a button like "i didn't request this" or something? Why would you hit one of the buttons if you know the request is bogus?

Re: Scammers are abusing an internal Microsoft account to send spam links

#122
post #95

Earlier quoted context omitted.

No, because the default is to present you 3 numbers and asks you which your number is! 1 in 3 and easy to hit by mistake.

Shouldn't there be a button like "i didn't request this" or something? Why would you hit one of the buttons if you know the request is bogus?

You've never hit the wrong button by mistake on a phone touchscreen?

I can only envy your adroitness.

Re: Scammers are abusing an internal Microsoft account to send spam links

#124
post #75
post #39

Earlier quoted context omitted.

Unfortunately my UK banks (and others) DO regularly make calls to me unannounced and demand my ID to 'prove who I am'. They are not scam calls and the callers cannot understand what they are doing wrong. If I'd had more strength in the last round of this stupidity I'd have done a number on them with the regulator. (I used to work in finance and was the director of a regulated financial entity, so I think I'd have a h…

In the US Caller ID has been so hopelessly compromised (for almost two decades now, that's on Congress) that financial institutions almost never make outbound calls, and only ever use standardized published numbers; I wasn't aware other countries differ so much. Please tell us more context with regard to your UK banks making multiple unannounced calls demanding your ID ... were you an individual customer? finance dir…

Banking example: trying to move some savings from one UK bank to another - back to where the money had originally come from, and that had just purchased the first bank too. It took 8h on the phone over a week or so to get the money back, which was interspersed with a comedic number of calls from withheld numbers and people unknown to me demanding enough info to get access to my money. And other very poor practice. The bank even conceeded at least once in writing that it knew that it was screwing up and sent me £100 by way of apology - but carried right on screwing up.

Non-banking: getting a call out of the blue from my Internet Service Provider again demanding enough credentials to get access to my (business) account, and unable to understand why that was very poor practice. I used to like that ISP a lot, and have been with it for a looooooong time, but the angry exchange with who seems to have been my account manager has soured the relationship a lot.

Re: Scammers are abusing an internal Microsoft account to send spam links

#125

Earlier quoted context omitted.

Having a service crap out because someone didn’t pay for the domain is almost a trope. It never occurred to me that the reverse might happen - paying for unused domains.

We pay for a bunch of old domains because nobody in the org can definitively say we never used it and/or don’t use it anymore. Easier to just keep paying.

Not only have you stopped using it, but did any of your customers ever allow list it in the past? Great way to attack customers of some large businesses if you ever see it happen.

Re: Scammers are abusing an internal Microsoft account to send spam links

#126

Earlier quoted context omitted.

> They are not scam calls What are they, then? Sales/marketing calls? Or some security notifications ("we noticed some suspicious operations in the last 3 days...")? If it's the former, that's still scam in my books. Specifically, it's a first-party scam , as opposed to a third-party scam , where some third party pretends to be your bank. They both should be treated similarly; unfortunately, you can't report first-pa…

Yeah as sibling points out, lots of orgs have scammy official security calls. This leads to a dance I have been through quite often. Hello Them: Am I speaking to Sean Hunter Me: Yes Them: This is . Can you confirm your Me: Yes Them: Err, … sorry I didn’t quite catch that. Me: Yes. Them: I asked whether you can confirm your Me: Yes. I can. Them: err… I can’t talk to you without you passing security. Me: You called me.…

This is very much my experience.

I generally say at some point before terminating the call "you should not train your customers to give out account access credentials to strangers" and the caller usually has no clue what I mean. Does no one in the security teams have theory of mind?

This will be the way I bring up the issue with the regulator if I do. I can think of many ways round this issue that would be much safer and not especially arduous.

Re: Scammers are abusing an internal Microsoft account to send spam links

#127
post #104

Earlier quoted context omitted.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

In France, basically every bank say (show in their app and everything) "if we call you and ask anything like code, confirmation, to do an action, anything, end the call and call us back, don't do anything on a call you didn't initiate". Same in their app eg you try to do a sepa wire to a new recipient and you get a warning "are you on the phone with someone ? did someone ask you to do that ? please call your bank by…

Here is a fun one, my mobile phone company has an account lock along with a pin and OTP over SMS system. In order for me to activate a new device (like an phone upgrade) with eSIM over the phone, I need to unlock my account with account lock, give them the pin over the phone, and read the SMS OTP to the mobile phone rep online. I get doing the account unlock and verbal pin, but I don't get why they ask for the OTP especially when they train us to never share the OTP over the phone. I even asked the rep about it, but he mentioned that you should never share the OTP if you did not initiate the service request. From a security posture point of view I think that stinks. I am not exactly sure how they expect SMS OTP to work in the case where my phone is not functional.

Re: Scammers are abusing an internal Microsoft account to send spam links

#128
post #43

Earlier quoted context omitted.

> unable publish a list with all domains they officially use to send mail That's because people report them as spam, so they hop domains to avoid that.

For a company with as much weight in the industry as Microsoft, it would be trivial to ensure their domains don’t end up on spam lists. Heck, because of outlook.com, they control have the spam lists themselves. The real reason for multiple domains is likely more stupid than that. It’s likely because different teams want to move faster than the whole of Microsoft, so register a domain for their MVP to enable them to p…

Microsoft.com is also owned by the marketing org, not the engineering org, for various reasons that predate the existence of many employees at Microsoft now.

This is why with rare, rare exceptions nothing "real" is on Microsoft.com including even the login page, with one exception (the passkey domain).

The new cloud.microsoft domain for Office will possibly help, but it's still a heck of a long list - https://learn.microsoft.com/en-us/microsoft-365/enterprise/u...

And IIRC this is just for office and windows, not azure.

Re: Scammers are abusing an internal Microsoft account to send spam links

#129
post #78
post #36

Earlier quoted context omitted.

https://github.com/HotCakeX/MicrosoftDomains ...and microsoftonline.com is not among them (unlike microsoftonline.net and other variants). But it seems to have been registered in 2002, and the record looks legit: https://whois.domaintools.com/microsoftonline.com

microsoftonline.com is in that list.

You're right. I wonder how I managed to miss it. For a moment I thought I must have looked at

https://github.com/HotCakeX/MicrosoftDomains/blob/main/Micro...

but that one doesn't contain any microsoftonline.

Re: Scammers are abusing an internal Microsoft account to send spam links

#130
post #75
post #39

Earlier quoted context omitted.

Unfortunately my UK banks (and others) DO regularly make calls to me unannounced and demand my ID to 'prove who I am'. They are not scam calls and the callers cannot understand what they are doing wrong. If I'd had more strength in the last round of this stupidity I'd have done a number on them with the regulator. (I used to work in finance and was the director of a regulated financial entity, so I think I'd have a h…

In the US Caller ID has been so hopelessly compromised (for almost two decades now, that's on Congress) that financial institutions almost never make outbound calls, and only ever use standardized published numbers; I wasn't aware other countries differ so much. Please tell us more context with regard to your UK banks making multiple unannounced calls demanding your ID ... were you an individual customer? finance dir…

My bank(s) have never called me and if they did I wouldn’t pick up - it’s definitely not a standard in the EU.
Post reply on HN