Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

131–140 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#131

Earlier quoted context omitted.

> They are not scam calls What are they, then? Sales/marketing calls? Or some security notifications ("we noticed some suspicious operations in the last 3 days...")? If it's the former, that's still scam in my books. Specifically, it's a first-party scam , as opposed to a third-party scam , where some third party pretends to be your bank. They both should be treated similarly; unfortunately, you can't report first-pa…

Yeah as sibling points out, lots of orgs have scammy official security calls. This leads to a dance I have been through quite often. Hello Them: Am I speaking to Sean Hunter Me: Yes Them: This is . Can you confirm your Me: Yes Them: Err, … sorry I didn’t quite catch that. Me: Yes. Them: I asked whether you can confirm your Me: Yes. I can. Them: err… I can’t talk to you without you passing security. Me: You called me.…

That’s wild. If my bank needs something from me they send an email saying that a message is available in the online portal - or in some cases they send me a physical letter. Anything else would be highly suspicious

Re: Scammers are abusing an internal Microsoft account to send spam links

#132

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

Oh man that brings back memories!

"Hello, I'm calling from Blockchain, I would like to talk about your investment portfolio"

it weirded me out they would pretend to be from the underlying technology instead of an exchange or something. I kept thinking I should pretend to be the CEO of TCP/IP or something when they called.

Re: Scammers are abusing an internal Microsoft account to send spam links

#133
post #24

Earlier quoted context omitted.

Companies do register domains before launching products and don't want to leak them. Now, I still support Microsoft and other companies to list the domains they send official emails from.

Why would that not be possible? You can still do that and then once the rabbit is out add it to the main list. Come on, don't let the good be the enemy of the perfect. I'm sure there are several ways to find and list all domains. What bothers me more is that they allowed to have different domains in the first place. Why not sub domains to make it clear.

That's what I said? Companies can hide domains while they are under development but then they should still maintain a list that they send emails from. I was opposed to legislation that required all registered domains regardless of use being published.

Re: Scammers are abusing an internal Microsoft account to send spam links

#135

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

Not only that, but they wrap the links in their email with click tracking provided by domains that have nothing to do with them (Mailgun or whatever). So even if you try to introspect the links you're clicking, they seem to go to a scammy domain even if they're legit!

Re: Scammers are abusing an internal Microsoft account to send spam links

#136
post #101

My employer's domain starts with "m". Bunch of people recently fell victim for a fishing email whose domain started with "rn". In Outlook 's font the two look almost identical.

A keming attack in the wild...

This happens all the time, it's a classic phishing tactic.

Re: Scammers are abusing an internal Microsoft account to send spam links

#137

Earlier quoted context omitted.

Or, which has worked great for me; just never answer the phone. If people need something they will email or chat. If not then it is not going to be important.

This. If people have a "real" reason to correspond with you they will have no problem making a record of it via a voicemail or text or email or whatever.

I've had friends that got into a spot of bother and tried calling from an unknown number. If it's a phone you can't text from, then leaving a voice mail with voice transcription is about the only way I'll know it's a friendly call

Re: Scammers are abusing an internal Microsoft account to send spam links

#138

Earlier quoted context omitted.

I simultaneously don’t believe this and fully believe this is something they would do. Do you have any sources on this?

It's amazing how little information has survived: the only reference I can find right away is https://www.experts-exchange.com/questions/22812691/What-is-... I was working in anti-spam at the time, so I was eyeballing a lot of raw email dumps and writing analysis scripts for "anomalous" urls, so it popped up fairly frequently.

The primary problem is we can't search through time via WayBack Machine where a lot of these things have gone. Took me a while the other day to surface the Choco-Banana Shake Hang which Microsoft deleted from their production site.

https://web.archive.org/web/20000608173453/http://support.mi...

Re: Scammers are abusing an internal Microsoft account to send spam links

#140

I'm receiving daily about 20 to 30 spam mails from google servers. I'm sorting them into a separate SPAM folder for the "fun" of it. Who to contact? How to make Google stop? Where to report the abuse of their services? I can't find out. The whole service is basically a big off and "we don't want any contact." Maybe I also need to publish some article, so it can be published here on HN? Maybe that could give it some t…

Yeah, I fell into that rabbit hole once. Tried all abuse channels that I could find. network-abuse@ refers you to the Google Cloud abuse form. They ‘are not able to take action on this report since the IP mentioned in the report is not hosted on Google Cloud.’ Gmail abuse doesn’t even bother to reply (why should they, it’s not about Gmail after all). In the end, I just blocked DKIM identifiers related to Firebase via Rspamd.
Post reply on HN