Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

161–170 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#161
post #104

Earlier quoted context omitted.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

In France, basically every bank say (show in their app and everything) "if we call you and ask anything like code, confirmation, to do an action, anything, end the call and call us back, don't do anything on a call you didn't initiate". Same in their app eg you try to do a sepa wire to a new recipient and you get a warning "are you on the phone with someone ? did someone ask you to do that ? please call your bank by…

Unfortunately in the US, maybe elsewhere, pharmacies and medical offices have trained the elderly it’s okay to verify their dob when they call. Costco does that when they call and it drives me nuts.

Re: Scammers are abusing an internal Microsoft account to send spam links

#162
I own a domain and have a catch all email. I routinely get emails from Microsoft and Google's official email addresses telling me that some account will be closed, or some other account notifications. I never created these accounts, and when I try to log into them or do a password reset, it does not go anywhere. It's been a minor mystery why I keep getting these emails for a while.

The Microsoft emails are coming from microsoft-noreply@microsoft.com so it's a bit different than in this article.

Re: Scammers are abusing an internal Microsoft account to send spam links

#163

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

the domain that ever m365 tennant exists on? that microsoftonline.com?

Re: Scammers are abusing an internal Microsoft account to send spam links

#164
post #35
post #31

Earlier quoted context omitted.

That's the number one rule though. If someone calls you claiming to be your bank, just say "I'll call you back"

Ask them their name/ last initial, employee ID or unique identifier for the conversation, direct phone number, job title and what location they're based at. Scammers will pretty much always refuse/argue/hang up on this (once I had one start insulting my mother in Hindi when I asked him this). Then call your bank's proper number and verify all of these details. (But in any case your bank will never call outwards to yo…

I ask them for all of that and their credit card details, mothers maiden name, name of their first pet, first school they went to, and what colour underwear they’re wearing.

I should probably learn how to insult their mother in Hindi too.

Re: Scammers are abusing an internal Microsoft account to send spam links

#165
post #55

On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…

Agreed; and more generally, Microsoft's online services in general are terrible. Their login system is a mess, their UX is awful... our company is a microsoft partner but there's like 27 different ways to be one, with a bunch of different accounts, forms and systems for it. Azure UX is atrocious. And this nonsense spills into every single enterprise product they offer too (how many people complain about Teams?).

Here in Belgium, 80% of enterprise accounts use MS over Google and I genuinely don't get why. (Without getting into the fiasco of not really having an EU alternative to either of those)

Re: Scammers are abusing an internal Microsoft account to send spam links

#166

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

the domain that ever m365 tennant exists on? that microsoftonline.com?

I think you may be referring to *.onmicrosoft.com (add that one to the list too...)

Re: Scammers are abusing an internal Microsoft account to send spam links

#167
post #104

Earlier quoted context omitted.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

In France, basically every bank say (show in their app and everything) "if we call you and ask anything like code, confirmation, to do an action, anything, end the call and call us back, don't do anything on a call you didn't initiate". Same in their app eg you try to do a sepa wire to a new recipient and you get a warning "are you on the phone with someone ? did someone ask you to do that ? please call your bank by…

A few UK banks detect that you're on a phone call and show a message like "we've never called you" or "we are not calling you right now" in their app, I think that's really smart.

Re: Scammers are abusing an internal Microsoft account to send spam links

#168
post #55

On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…

Agreed; and more generally, Microsoft's online services in general are terrible. Their login system is a mess, their UX is awful... our company is a microsoft partner but there's like 27 different ways to be one, with a bunch of different accounts, forms and systems for it. Azure UX is atrocious. And this nonsense spills into every single enterprise product they offer too (how many people complain about Teams?). Here…

> Here in Belgium, 80% of enterprise accounts use MS over Google and I genuinely don't get why. (Without getting into the fiasco of not really having an EU alternative to either of those)

Maybe because those enterprises already used on-prem AD? It's much "easier" to have a hybrid monstrosity combining on-prem AD and Azure AD than on-prem AD and Google (or anything non-MS, really). Plus, MS is already a supplier, so for large, bureaucratic entities, they already have a foot in the door.

Re: Scammers are abusing an internal Microsoft account to send spam links

#169
post #93

Earlier quoted context omitted.

SMS 2FA is the worst factor because of how insecure and phishable the phone network is, it deserves to die out where possible

But they could allow other 2fa apps, but they force their shitty one.

They now support passkeys with things other than their shitty app. I use 1Password, and it works fine.

I've also had a yubikey for a long time and can't be bothered to type in codes, so I didn't know their shitty app did OTP or even that OTP was actually a possibility for MS accounts.

Re: Scammers are abusing an internal Microsoft account to send spam links

#170

Earlier quoted context omitted.

Nowadays, when banks call you here, they allow you to verify the bank is actually calling you with the mobile app - you can see their name and number they're calling you from in the app. Also, you can often verify you're you with the app too, same as any other app authorization, so you don't have to share any details over the phone. I feel like this is a pretty good improvement.

That does seem better than blind trust but that app infrastructure could get compromised. I would still be wary in any situation where I did not originate the call with the bank.

Ye, I only get called by banks when my transaction gets classified as potentially fraudulent (which pretty much just means that it is for a bigger amount of money) or some other even more rare situations like finishing a loan application. Still, I'd rather be double sure that it is the bank that's calling me because I don't want to assume solely based on the convenient timing. If the app infrastructure is compromised, the bank is liable so it feels like less of a problem. If the app does offer authorizing through the app, I shouldn't be asked any personal details that my bank already knows so I (hopefully) would still be wary, if put in such a situation though. Obviously hard to know what I'd actually do unless it actually happens to me.
Post reply on HN