Live data from Hacker News

Scammers are abusing an internal Microsoft account to send spam links

techcrunch.com

81–90 of 196 posts

Re: Scammers are abusing an internal Microsoft account to send spam links

#81
post #49
post #13

I mean, it happened to the FBI... https://krebsonsecurity.com/2021/11/hoax-email-blast-abused-...

>The FBI is aware of a software misconfiguration That's not a misconfiguration, that's incompetence. How do these people get hired?

That's actually really easy:

1. be government agency

2. pay 30-70% less than private sector companies would for a similar position

3. receive applicants that are 30-70% less competent

Bonus:

- have 30+ year old systems nobody understands anymore because the team behind them has been dead/retired for a decade

- have hiring process handled entirely by out of touch suits

- have a revolving door of motivated soon-to-be burnouts mopping up the mess behind the aforementioned regular employees

Re: Scammers are abusing an internal Microsoft account to send spam links

#82
post #57
post #7

A while back I had a reservation with a hotel on Booking and I received a phish attempt that came directly via the Booking site domain email and also DMs but "sent" by the hotel. When I looked into it at the time, it seemed less like an issue of hotels specifically having their accounts infiltrated and more like some kind of message/email endpoint on Booking's end was being abused in a similar manner. I'm not sure th…

I have not seen one of these that wasn't a compromised hotel email or booking account. I have had to "help" a hotel get malware/RATs off their system more than a dozen times as a _guest_

I've started to assume that any non-chain hotel is compromised after losing $2k to hackers that completely owned the hotel's email system. Thankfully DMARC made it irrefutable that it was their system at fault and they assumed liability. BEC is shockingly common and difficult to detect until it's too late.

Re: Scammers are abusing an internal Microsoft account to send spam links

#83
Meta had(has?) a similar bug with one of their business manager features, the attacker has complete control of the initial body text which makes it highly convincing.

Trying to report this was an exercise in futility, I guess they get so much beg bounty spam that their security submission process filters out the occasional legitimate issue.

Re: Scammers are abusing an internal Microsoft account to send spam links

#84
post #31

Earlier quoted context omitted.

Knowing what numbers are real through an official publication is very good, but it only allows you to place trust in calls you make, not calls you receive, because making calls doesn't involve caller ID, receiving calls does, and caller ID is spoofable.

That's the number one rule though. If someone calls you claiming to be your bank, just say "I'll call you back"

Or, which has worked great for me; just never answer the phone. If people need something they will email or chat. If not then it is not going to be important.

Re: Scammers are abusing an internal Microsoft account to send spam links

#85
post #83

Meta had(has?) a similar bug with one of their business manager features, the attacker has complete control of the initial body text which makes it highly convincing. Trying to report this was an exercise in futility, I guess they get so much beg bounty spam that their security submission process filters out the occasional legitimate issue.

I've been receiving these for so long I started thinking it must be just me being targeted and not widespread, as Meta seems to not do anything about it.

Emails comming legitimeley from noreply@business.facebook.com with the text below. Go and decypher which part is Meta template and which is creative use of user supplied text...

  Your Meta's Page may be at risk due to unusual
  activity is not part of or affiliated with
  Meta. Only approve requests and invitations from
  people and businesses that you know and trust.
  Meta will never ask for passwords, payment
  information or personal details in an email. You've
  received a partner request. Partners are other
  businesses that you work with on Facebook. Partner
  sharing lets you give access to your business assets,
  but not to your business portfolio. This request is
  from:

  Your Page is under restriction review Contact Meta
  Support: metafanpageviolate@gmail.com Protect yourself
  from fraud: Verify the identity of the requester by
  contacting the business using official contact information.

Re: Scammers are abusing an internal Microsoft account to send spam links

#86
post #55

On a semi-related note, Microsoft security is genuinely terrible. For the past week, my Microsoft authenticator has been pinging about sign-ins from random places. Except the login history page is completely empty. Not even my own sign ins show up. Now, you would be forgiven for thinking it's because my password leaked, but no. The default sign in flow with the app enabled is email + authenticator. No password requir…

Microsoft also has this cool thing where if someone fails to get into your account too many times, your account can get locked and you are asked to reset your password. For a working password. Even after changing my password, I couldn't login to my email on my phone, so I just gave up. I only use that email for a handful of things anyway.

Their enterprise account system (active directory or whatever it's called) also has an awesome bug where if you accidentally reload the page during password reset, the link will no longer be valid, but your old password will already be invalidated. So you won't be able to log in at all untill IT staff manually changes your password.

Re: Scammers are abusing an internal Microsoft account to send spam links

#87
post #62
post #52

Earlier quoted context omitted.

I'm not gonna get hoodwinked into highbrow shenanigans. Social media doesn't need IDs to work, demanding it is a scam.

Rhetoric won't save you from the embarrassing situation you created for yourself. You accused something of being a scam without understanding the definition of the word. Now that your claim has been challenged, you're trying to redefine terms and argue around the issue rather than admit you were wrong.

From dictionary.cambridge.org: a dishonest plan for making money or getting an advantage, especially one that involves tricking people:

I can easily see a social media company demanding an ID falling under this definition if the accuser believes that the actual use of said ID will be different or more expansive than implied. That is not an unreasonable assumption, IMO.

Re: Scammers are abusing an internal Microsoft account to send spam links

#88

Who even can be sure microsoftonline.com is legit. Microsoft's domain story is such a mess, I wouldn't be surprised if not even internally they have one complete list of all the domain assets they own. But they are not alone. It is kind of ironic when companies insist that we check the domain to spot spam but are unable publish a list with all domains they officially use to send mail.

Bluesky is even worse, some of their emails come from "moderation@blueskyweb.xyz". They have to make posts to assure people it's not a scam, especially as they'll ask you to mail ID etc to that address: https://bsky.app/profile/safety.bsky.app/post/3ljp6zi7tp227

Hard to beat Outlook 2007 which had some "smart tags" feature that all referenced "5iantlavalamp.com", and things started breaking when that domain expired.

Re: Scammers are abusing an internal Microsoft account to send spam links

#89
post #21

Earlier quoted context omitted.

Bluesky is even worse, some of their emails come from "moderation@blueskyweb.xyz". They have to make posts to assure people it's not a scam, especially as they'll ask you to mail ID etc to that address: https://bsky.app/profile/safety.bsky.app/post/3ljp6zi7tp227

Microsoft is the 4th largest company in the world. There should be a long list of companies whose policies are worse than theirs.

That doesn't follow. I would expect the list of companies worst than Microsoft to be about 4 items long

Re: Scammers are abusing an internal Microsoft account to send spam links

#90
post #31

Earlier quoted context omitted.

That's the number one rule though. If someone calls you claiming to be your bank, just say "I'll call you back"

Or, which has worked great for me; just never answer the phone. If people need something they will email or chat. If not then it is not going to be important.

This. If people have a "real" reason to correspond with you they will have no problem making a record of it via a voicemail or text or email or whatever.
Post reply on HN