Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

191–196 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#191
post #189

Earlier quoted context omitted.

Why would anyone stick with an insurer that clearly doesn’t give a darn about them? Just for a discount?

Well, I could go with a different insurer that blatantly and brazenly lies about their network coverage[1], or I could go with one that doesn't, but still doesn't have my doctors in it, or I could go with the other one that people claim consistently denies care and coverage. Also, if 'Just for a discount' isn't a reason to use them, do you have $3,000 lying around to wire me? If you do, I'll happily switch to a much…

From what it sounds like… you are the one already paying either way.

It’s just one firm takes, instead of more dollars, some other value out of you?

I’m not sure why the latter is more preferable. But if your sticking with it after seriously thinking about it, then that is your choice.

Re: Scammers are abusing an internal Microsoft account to send spam links

#192
post #55

On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…

You have to create a new @outlook email to use as a username only you know, and then remove your actual email as a sign-in option. Only way to mitigate the MFA spam currently.

Re: Scammers are abusing an internal Microsoft account to send spam links

#193
post #75

Earlier quoted context omitted.

In the US Caller ID has been so hopelessly compromised (for almost two decades now, that's on Congress) that financial institutions almost never make outbound calls, and only ever use standardized published numbers; I wasn't aware other countries differ so much. Please tell us more context with regard to your UK banks making multiple unannounced calls demanding your ID ... were you an individual customer? finance dir…

Banking example: trying to move some savings from one UK bank to another - back to where the money had originally come from, and that had just purchased the first bank too. It took 8h on the phone over a week or so to get the money back, which was interspersed with a comedic number of calls from withheld numbers and people unknown to me demanding enough info to get access to my money. And other very poor practice. Th…

Happy note: just had a sensible interaction with my bank where it called me back but the caller understood why NOT to ask data that could be used to access my account, and we managed to resolve the issue that I was having (which, I think, was my error)!

Re: Scammers are abusing an internal Microsoft account to send spam links

#194
post #104

Earlier quoted context omitted.

Tangent: I used to receive at least a dozen bank scam calls per day in India, especially during insurance renewal. I wanted the banks to publish official phone numbers and mandate their employees to use only official numbers. Recently the regulatory bodies did just that and so the banks should only use 1600 numbers to contact their customers. My bank scam calls have dropped to 0.

In France, basically every bank say (show in their app and everything) "if we call you and ask anything like code, confirmation, to do an action, anything, end the call and call us back, don't do anything on a call you didn't initiate". Same in their app eg you try to do a sepa wire to a new recipient and you get a warning "are you on the phone with someone ? did someone ask you to do that ? please call your bank by…

In Turkey, if my bank calls me, they also send a push notification telling "We are calling you. The representative's name is $NAME. You can talk safely".

Re: Scammers are abusing an internal Microsoft account to send spam links

#195

Earlier quoted context omitted.

PayPal itself is a scam.

How so?

The minimum withdrawal is 10 usd or 20 usd, depending on where you'll be withrdrawing it to. You have less than that in your account and won't be using Paypal soon? say goodbye to those 7 dollars.

-- Oh, but you can wait, maybe later you'll use those 7 dollars

No, if you don't do transactions for 1 year, they charge you a $10 inactivity fee.

It’s designed to hold your money hostage and then take it afterward

The only reason to use Paypal is that you have no other way of paying for something. Even cryptocurrency is more user-friendly than Paypal.

Btw, their conversion rates are awful.

Re: Scammers are abusing an internal Microsoft account to send spam links

#196
post #166

Earlier quoted context omitted.

the domain that ever m365 tennant exists on? that microsoftonline.com?

I think you may be referring to *.onmicrosoft.com (add that one to the list too...)

I walked right into that one.
Post reply on HN