Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

111–120 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#111

Earlier quoted context omitted.

Hard to beat Outlook 2007 which had some "smart tags" feature that all referenced "5iantlavalamp.com", and things started breaking when that domain expired.

I'm struggling to find information about this and it's extremely interesting. Would you please explain more?

It's hard to remember many details from almost 20 years ago, I just remember coming across it in email spools while writing anti-spam analysis scripts. Only mention I can find nowadays is https://www.experts-exchange.com/questions/22812691/What-is-....

Re: Scammers are abusing an internal Microsoft account to send spam links

#112

Earlier quoted context omitted.

Bluesky is even worse, some of their emails come from "moderation@blueskyweb.xyz". They have to make posts to assure people it's not a scam, especially as they'll ask you to mail ID etc to that address: https://bsky.app/profile/safety.bsky.app/post/3ljp6zi7tp227

Hard to beat Outlook 2007 which had some "smart tags" feature that all referenced "5iantlavalamp.com", and things started breaking when that domain expired.

This story is ludicrous… yet, it seems to check out. https://spamassassin.apache.org/full/3.0.x/dist/rules/25_uri... says this is one of the "Top 125 domains whitelisted by SURBL", and there's an answer on the hyphen site about it: https://www.experts-exchange.com/questions/22812691/What-is-.... Can someone with a Bottom-Surgery account tell us the details?

Re: Scammers are abusing an internal Microsoft account to send spam links

#113
post #55

On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…

I also had this starting a few months back. I changed the email address (really, just an alias to the same mailbox as before) and the notifications stopped.

Re: Scammers are abusing an internal Microsoft account to send spam links

#114

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

is it common for banks to call you?

always though the agreement was: we don't call you, you call us. we'll send letters though.

Re: Scammers are abusing an internal Microsoft account to send spam links

#115

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

“So Microsoft’s domain story is a total mess?”

“Always has been.”

https://www.techmonitor.ai/technology/microsoft_forget_to_re...

Re: Scammers are abusing an internal Microsoft account to send spam links

#116
post #94

I feel sad that what I think of as the obvious solution, companies using subdomains like internal.microsoft.com instead of making a million different domains, is so far from happening that no one here on HN has even brought it up.

Hell, they have .microsoft. Why'd they bother?

Re: Scammers are abusing an internal Microsoft account to send spam links

#117

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

Seems like it would make sense to only use subdomains of microsoft.com?

Re: Scammers are abusing an internal Microsoft account to send spam links

#118

Earlier quoted context omitted.

> They are not scam calls What are they, then? Sales/marketing calls? Or some security notifications ("we noticed some suspicious operations in the last 3 days...")? If it's the former, that's still scam in my books. Specifically, it's a first-party scam , as opposed to a third-party scam , where some third party pretends to be your bank. They both should be treated similarly; unfortunately, you can't report first-pa…

Yeah as sibling points out, lots of orgs have scammy official security calls. This leads to a dance I have been through quite often. Hello Them: Am I speaking to Sean Hunter Me: Yes Them: This is . Can you confirm your Me: Yes Them: Err, … sorry I didn’t quite catch that. Me: Yes. Them: I asked whether you can confirm your Me: Yes. I can. Them: err… I can’t talk to you without you passing security. Me: You called me.…

Just don’t answer the phone. If it’s something important they know how to reach you, or they can leave a voicemail.
Post reply on HN