Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

181–190 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#182
post #57
post #7

A while back I had a reservation with a hotel on Booking and I received a phish attempt that came directly via the Booking site domain email and also DMs but "sent" by the hotel. When I looked into it at the time, it seemed less like an issue of hotels specifically having their accounts infiltrated and more like some kind of message/email endpoint on Booking's end was being abused in a similar manner. I'm not sure th…

I have not seen one of these that wasn't a compromised hotel email or booking account. I have had to "help" a hotel get malware/RATs off their system more than a dozen times as a _guest_

Hotels should start giving 5-star reviews to their guests I suggest!

Re: Scammers are abusing an internal Microsoft account to send spam links

#183
post #182
post #57

Earlier quoted context omitted.

I have not seen one of these that wasn't a compromised hotel email or booking account. I have had to "help" a hotel get malware/RATs off their system more than a dozen times as a _guest_

Hotels should start giving 5-star reviews to their guests I suggest!

TBH I can't imagine the trust of letting a guest access their booking computer handling cards and given the admin password for UAC particularly helped their case here ;-;

Re: Scammers are abusing an internal Microsoft account to send spam links

#185
post #174

Earlier quoted context omitted.

Unfortunately in the US, maybe elsewhere, pharmacies and medical offices have trained the elderly it’s okay to verify their dob when they call. Costco does that when they call and it drives me nuts.

US insurers expect you to click on sms links and log in with your username, password, and 2fa all so you can receive a fucking marketing message.

Why would anyone stick with an insurer that clearly doesn’t give a darn about them?

Just for a discount?

Re: Scammers are abusing an internal Microsoft account to send spam links

#186
post #175

Earlier quoted context omitted.

This is very much my experience. I generally say at some point before terminating the call "you should not train your customers to give out account access credentials to strangers" and the caller usually has no clue what I mean. Does no one in the security teams have theory of mind? This will be the way I bring up the issue with the regulator if I do. I can think of many ways round this issue that would be much safer…

The caller is a minimal wagie following a script, you can't get mad at them. The chucklefuck that wrote the script that you can get mad at won't pick up your calls. That's how responsibility works.

A few of the bank people that I spoke to during the last caper were pretty senior and those did understand the issue that I raised but found themselves constrained by their rules, though one or two got creative with me in a good way. (Pretty much none of those who called me were 'minimum wage' in my estimation.) But very more senior management should be setting good scripts and expectations for the less-well-paid staff doing the grunt work. That is what their higher pay should be buying, IMHO.

Re: Scammers are abusing an internal Microsoft account to send spam links

#187
post #174

Earlier quoted context omitted.

US insurers expect you to click on sms links and log in with your username, password, and 2fa all so you can receive a fucking marketing message.

Why would anyone stick with an insurer that clearly doesn’t give a darn about them? Just for a discount?

Don’t have much of a choice. Gotta love our system.

Re: Scammers are abusing an internal Microsoft account to send spam links

#188
post #49
post #13

I mean, it happened to the FBI... https://krebsonsecurity.com/2021/11/hoax-email-blast-abused-...

>The FBI is aware of a software misconfiguration That's not a misconfiguration, that's incompetence. How do these people get hired?

in 2026, by a drunk who gives out whiskey bottles branded with their name

Re: Scammers are abusing an internal Microsoft account to send spam links

#189
post #174

Earlier quoted context omitted.

US insurers expect you to click on sms links and log in with your username, password, and 2fa all so you can receive a fucking marketing message.

Why would anyone stick with an insurer that clearly doesn’t give a darn about them? Just for a discount?

Well, I could go with a different insurer that blatantly and brazenly lies about their network coverage[1], or I could go with one that doesn't, but still doesn't have my doctors in it, or I could go with the other one that people claim consistently denies care and coverage.

Also, if 'Just for a discount' isn't a reason to use them, do you have $3,000 lying around to wire me? If you do, I'll happily switch to a much more expensive insurer that meets my other criteria, and might or might not send me marketing materials disguised as fishing SMS. (I'll let you know if they do.)

---

Insurers aren't banks or ISPs or gas stations. They don't provide a fungible service that is nearly identical from one to the other. You can't 'just switch'. They are both heavily obfuscated, and heavily differentialized, because the healthcare 'market' is obfuscated and heavily balkanized.

And all of them are utter shit, but in different ways, and if you are lucky, you won't discover the ways in which yours is shit.

---

[1] How this isn't a statutory capital crime for anyone with the rank of director and higher, I have no idea. But the fact that the people orchestrating this are permitted in civil society does lead me to believe that maybe we don't live in a just world.

Re: Scammers are abusing an internal Microsoft account to send spam links

#190

Earlier quoted context omitted.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

Oh man that brings back memories! "Hello, I'm calling from Blockchain, I would like to talk about your investment portfolio" it weirded me out they would pretend to be from the underlying technology instead of an exchange or something. I kept thinking I should pretend to be the CEO of TCP/IP or something when they called.

I was several times called by windows employeesq
Post reply on HN