Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

151–160 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#151

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

[dead]

Re: Scammers are abusing an internal Microsoft account to send spam links

#152
post #75
post #39

Earlier quoted context omitted.

Unfortunately my UK banks (and others) DO regularly make calls to me unannounced and demand my ID to 'prove who I am'. They are not scam calls and the callers cannot understand what they are doing wrong. If I'd had more strength in the last round of this stupidity I'd have done a number on them with the regulator. (I used to work in finance and was the director of a regulated financial entity, so I think I'd have a h…

In the US Caller ID has been so hopelessly compromised (for almost two decades now, that's on Congress) that financial institutions almost never make outbound calls, and only ever use standardized published numbers; I wasn't aware other countries differ so much. Please tell us more context with regard to your UK banks making multiple unannounced calls demanding your ID ... were you an individual customer? finance dir…

[dead]

Re: Scammers are abusing an internal Microsoft account to send spam links

#153

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

> Microsoft's domain story is such a mess

You mean like how they moved from a perfectly legible and rememberable domain like office.com to the strange vanity domain m365.cloud.microsoft?

Re: Scammers are abusing an internal Microsoft account to send spam links

#154

Earlier quoted context omitted.

Bluesky is even worse, some of their emails come from "moderation@blueskyweb.xyz". They have to make posts to assure people it's not a scam, especially as they'll ask you to mail ID etc to that address: https://bsky.app/profile/safety.bsky.app/post/3ljp6zi7tp227

Hard to beat Outlook 2007 which had some "smart tags" feature that all referenced "5iantlavalamp.com", and things started breaking when that domain expired.

Ah I misremembered one thing, nothing broke because it wasn’t even an existing domain when they used it. That was a different Microsoft domain I was thinking of.

Re: Scammers are abusing an internal Microsoft account to send spam links

#155
post #101

My employer's domain starts with "m". Bunch of people recently fell victim for a fishing email whose domain started with "rn". In Outlook 's font the two look almost identical.

Yes, the Outlook sender font is such a joke. They preach about 365 security but don’t practice basics.

Re: Scammers are abusing an internal Microsoft account to send spam links

#156
post #36

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

https://github.com/HotCakeX/MicrosoftDomains ...and microsoftonline.com is not among them (unlike microsoftonline.net and other variants). But it seems to have been registered in 2002, and the record looks legit: https://whois.domaintools.com/microsoftonline.com

1drv.ms always catches me out.

Re: Scammers are abusing an internal Microsoft account to send spam links

#158

Earlier quoted context omitted.

The primary problem is we can't search through time via WayBack Machine where a lot of these things have gone. Took me a while the other day to surface the Choco-Banana Shake Hang which Microsoft deleted from their production site. https://web.archive.org/web/20000608173453/http://support.mi...

There are a few archives of Microsoft KB articles. I found this article in Beta Archive wiki's, which has a full-text search. https://www.betaarchive.com/wiki/index.php?title=Microsoft_K...

This is good news. I fear for those poor souls struggling with their Blendolinis.

Re: Scammers are abusing an internal Microsoft account to send spam links

#159
post #39
post #35

Earlier quoted context omitted.

Ask them their name/ last initial, employee ID or unique identifier for the conversation, direct phone number, job title and what location they're based at. Scammers will pretty much always refuse/argue/hang up on this (once I had one start insulting my mother in Hindi when I asked him this). Then call your bank's proper number and verify all of these details. (But in any case your bank will never call outwards to yo…

Unfortunately my UK banks (and others) DO regularly make calls to me unannounced and demand my ID to 'prove who I am'. They are not scam calls and the callers cannot understand what they are doing wrong. If I'd had more strength in the last round of this stupidity I'd have done a number on them with the regulator. (I used to work in finance and was the director of a regulated financial entity, so I think I'd have a h…

Same in Australia, I've had genuine calls from a bank asking for my security code for identification purposes.

Re: Scammers are abusing an internal Microsoft account to send spam links

#160
post #35
post #31

Earlier quoted context omitted.

That's the number one rule though. If someone calls you claiming to be your bank, just say "I'll call you back"

Ask them their name/ last initial, employee ID or unique identifier for the conversation, direct phone number, job title and what location they're based at. Scammers will pretty much always refuse/argue/hang up on this (once I had one start insulting my mother in Hindi when I asked him this). Then call your bank's proper number and verify all of these details. (But in any case your bank will never call outwards to yo…

That is an unnecessary interrogation, you don't need to verify the initial call at all. Simply call your bank on your own.
Post reply on HN