Blog

Microsoft Account Email Phishing Attempt Looks Legitimate

By Mersad March 26, 2019

Researchers have discovered a pair of nasty phishing campaigns that are making use of Microsoft's Azure Blob Storage in a bid to steal the recipient's Microsoft and Outlook account credentials.


Both campaigns are noteworthy in that they utilize well-constructed landing pages that have SSL certificates and a windows.net domain, which combine to make them look totally legitimate.


Given that most users don't pay close attention to the exact address they're navigating when they click on a link embedded in an email, these things are more than enough to fool many users. The first campaign relies on some basic social engineering to prompt the user to do something.


The subject lines vary a bit, but fundamentally they are called to action like:


"Action Required: (user's email address) information is outdated - Re-validate now!"


The body of the email reinforces this point and helpfully contains a link to help you on your way to re-validating your account. Clicking on the link doesn't raise suspicion because the landing page is a carbon copy of the Outlook Web App that's complete with a box that allows you to "validate" your password. Of course, what you're actually doing is giving your email password to the hackers, who then have unfettered access to your inbox and contact list.


The second campaign is the weaker of the two, although it's set up much the same way. The subject line indicates that you need to take action to re-validate your Facebook Workplace service account, but when you click the link, you're actually taken to a clone of Microsoft's landing page. This was no doubt a mix-up on the part of the hackers and will be addressed in short order.


In any case, it pays to make sure your employees are aware of both of these, so they don't inadvertently wind up handing over the keys to their digital kingdom.


Used with permission from Article Aggregator

Related Posts

By Mersad September 23, 2025
How can a small-scale establishment stand out in today's competitive market? With the shift toward digital-first experiences, mobile apps help businesses stay relevant and accessible, no matter their size. Learn more about them here.
By Mersad September 22, 2025
Many businesses across various industries have already implemented a remote work model. Around 35% of Silicon Valley workers, for example, now work from home, a sharp rise from the 2019 pre-pandemic period's 6%, and for good reason. This shift brings many worthwhile advantages, including:
By Mersad September 20, 2025
There’s no question that the traditional username and password combination is a weak link when it comes to online security. For several years, experts have encouraged businesses to implement passkeys to overcome the pitfalls of traditional passwords, which have become increasingly vulnerable to cybercriminals.
By Mersad September 19, 2025
Just how safe is your establishment from online threats? A new phishing scam is making waves and targeting US-based organizations. Learn more about it here so you can bolster your defenses.
By Mersad September 18, 2025
Are you finding it harder to keep your offerings profitable over time? By investing in innovation, establishments can predict and control physical wear, combat obsolescence, and even discover new utilization opportunities. Learn more about technology for longer product lifecycles here.

Contact Information

1035 Medina Rd, Suite #800

Medina, OH 44256