Earlier quoted context omitted.
Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.
In France, basically every bank say (show in their app and everything) "if we call you and ask anything like code, confirmation, to do an action, anything, end the call and call us back, don't do anything on a call you didn't initiate". Same in their app eg you try to do a sepa wire to a new recipient and you get a warning "are you on the phone with someone ? did someone ask you to do that ? please call your bank by…
Scammers are abusing an internal Microsoft account to send spam links
161–170 of 196 posts
Re: Scammers are abusing an internal Microsoft account to send spam links
#162The Microsoft emails are coming from microsoft-noreply@microsoft.com so it's a bit different than in this article.
Re: Scammers are abusing an internal Microsoft account to send spam links
#163Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.
Re: Scammers are abusing an internal Microsoft account to send spam links
#164Earlier quoted context omitted.
That's the number one rule though. If someone calls you claiming to be your bank, just say "I'll call you back"
Ask them their name/ last initial, employee ID or unique identifier for the conversation, direct phone number, job title and what location they're based at. Scammers will pretty much always refuse/argue/hang up on this (once I had one start insulting my mother in Hindi when I asked him this). Then call your bank's proper number and verify all of these details. (But in any case your bank will never call outwards to yo…
I should probably learn how to insult their mother in Hindi too.
Re: Scammers are abusing an internal Microsoft account to send spam links
#165On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…
Here in Belgium, 80% of enterprise accounts use MS over Google and I genuinely don't get why. (Without getting into the fiasco of not really having an EU alternative to either of those)
Re: Scammers are abusing an internal Microsoft account to send spam links
#166Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.
the domain that ever m365 tennant exists on? that microsoftonline.com?
Re: Scammers are abusing an internal Microsoft account to send spam links
#167Earlier quoted context omitted.
Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.
In France, basically every bank say (show in their app and everything) "if we call you and ask anything like code, confirmation, to do an action, anything, end the call and call us back, don't do anything on a call you didn't initiate". Same in their app eg you try to do a sepa wire to a new recipient and you get a warning "are you on the phone with someone ? did someone ask you to do that ? please call your bank by…
Re: Scammers are abusing an internal Microsoft account to send spam links
#168On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…
Agreed; and more generally, Microsoft's online services in general are terrible. Their login system is a mess, their UX is awful... our company is a microsoft partner but there's like 27 different ways to be one, with a bunch of different accounts, forms and systems for it. Azure UX is atrocious. And this nonsense spills into every single enterprise product they offer too (how many people complain about Teams?). Here…
Maybe because those enterprises already used on-prem AD? It's much "easier" to have a hybrid monstrosity combining on-prem AD and Azure AD than on-prem AD and Google (or anything non-MS, really). Plus, MS is already a supplier, so for large, bureaucratic entities, they already have a foot in the door.
Re: Scammers are abusing an internal Microsoft account to send spam links
#169Earlier quoted context omitted.
SMS 2FA is the worst factor because of how insecure and phishable the phone network is, it deserves to die out where possible
But they could allow other 2fa apps, but they force their shitty one.
I've also had a yubikey for a long time and can't be bothered to type in codes, so I didn't know their shitty app did OTP or even that OTP was actually a possibility for MS accounts.
Re: Scammers are abusing an internal Microsoft account to send spam links
#170Earlier quoted context omitted.
Nowadays, when banks call you here, they allow you to verify the bank is actually calling you with the mobile app - you can see their name and number they're calling you from in the app. Also, you can often verify you're you with the app too, same as any other app authorization, so you don't have to share any details over the phone. I feel like this is a pretty good improvement.
That does seem better than blind trust but that app infrastructure could get compromised. I would still be wary in any situation where I did not originate the call with the bank.