<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[❗ We’ve observed a scammer clearly abusing Microsoft&#x27;s &#x27;msonlineservicesteam@microsoftonline[.]]></title><description><![CDATA[<p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2757.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--exclamation" style="height:23px;width:auto;vertical-align:middle" title="❗" alt="❗" /> We’ve observed a scammer clearly abusing Microsoft's 'msonlineservicesteam@microsoftonline[. ]com' for spam distribution.</p><p>The header and message body appear completely legitimate - the abuse is happening through injection into the Subject:</p><p><img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/2709.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--email" style="height:23px;width:auto;vertical-align:middle" title="✉" alt="✉" />️ Here's an example:<br />"Your PayPal order for 0.0092 BTC ($699.99) is complete. Not you? Call +1 (803) 237-5050 account email verification code."</p><p>At this point, it appears the attacker may have simply set the malicious text as either the account name or the organization name.</p><p>This also appears to line up with what <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span>  TechCrunch Security Editor identified last week:<br /><a href="https://mastodon.social/@zackwhittaker/116562360000833298" rel="nofollow noopener"><span>https://</span><span>mastodon.social/@zackwhittaker</span><span>/116562360000833298</span></a></p><p> ....although the activity we’re seeing appears to stretch back several months.</p><p>Takeaway: automated notification systems should not allow this level of customization.</p><p>Microsoft has been informed of this abusive activity.</p><p><a href="https://infosec.exchange/tags/ThreatIntel" rel="tag">#<span>ThreatIntel</span></a> <a href="https://infosec.exchange/tags/Spam" rel="tag">#<span>Spam</span></a> <a href="https://infosec.exchange/tags/InfoSec" rel="tag">#<span>InfoSec</span></a> <a href="https://infosec.exchange/tags/CyberSecurity" rel="tag">#<span>CyberSecurity</span></a></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/601/259/622/014/777/original/11d25e64e4db0f91.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/daf42584-63aa-48ea-afe8-2b7ce41fb049/we-ve-observed-a-scammer-clearly-abusing-microsoft-s-msonlineservicesteam@microsoftonline-.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 12:11:27 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/daf42584-63aa-48ea-afe8-2b7ce41fb049.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 19 May 2026 12:36:30 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to ❗ We’ve observed a scammer clearly abusing Microsoft&#x27;s &#x27;msonlineservicesteam@microsoftonline[. on Wed, 20 May 2026 14:14:13 GMT]]></title><description><![CDATA[<p><span><a href="/user/spamhaus%40infosec.exchange">@<span>spamhaus</span></a></span> <span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> same as calendly emails, and as sharepoint and gmail shared document links before them, etc etc etc repeat ad nauseum. </p><p>Here's a calendly one from today that M365 mail filtering decided needed to be delivered to my inbox.</p><p>Had to zoom out so that you can actually see the calendly footer, because calendly /also/ lets people insert a load of whitespace to try to hide their footer "below the fold"</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://thx.gg/system/media_attachments/files/116/607/312/085/850/078/original/c7280fa676c3402f.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://thx.gg/users/interpipes/statuses/116607317034331798</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://thx.gg/users/interpipes/statuses/116607317034331798</guid><dc:creator><![CDATA[interpipes@thx.gg]]></dc:creator><pubDate>Wed, 20 May 2026 14:14:13 GMT</pubDate></item><item><title><![CDATA[Reply to ❗ We’ve observed a scammer clearly abusing Microsoft&#x27;s &#x27;msonlineservicesteam@microsoftonline[. on Wed, 20 May 2026 08:15:33 GMT]]></title><description><![CDATA[<p><span><a href="/user/gossithedog%40cyberplace.social">@<span>GossiTheDog</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> thanks for sharing <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f64f.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--pray" style="height:23px;width:auto;vertical-align:middle" title="🙏" alt="🙏" /></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/spamhaus/statuses/116605906707133641</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/spamhaus/statuses/116605906707133641</guid><dc:creator><![CDATA[spamhaus@infosec.exchange]]></dc:creator><pubDate>Wed, 20 May 2026 08:15:33 GMT</pubDate></item><item><title><![CDATA[Reply to ❗ We’ve observed a scammer clearly abusing Microsoft&#x27;s &#x27;msonlineservicesteam@microsoftonline[. on Tue, 19 May 2026 16:04:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/spamhaus%40infosec.exchange">@<span>spamhaus</span></a></span> yeah this has been going on for a while, and Microsoft has done seemingly nothing to combat the issue.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/InfosecFemthing/statuses/116602089644478413</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/InfosecFemthing/statuses/116602089644478413</guid><dc:creator><![CDATA[infosecfemthing@infosec.exchange]]></dc:creator><pubDate>Tue, 19 May 2026 16:04:50 GMT</pubDate></item><item><title><![CDATA[Reply to ❗ We’ve observed a scammer clearly abusing Microsoft&#x27;s &#x27;msonlineservicesteam@microsoftonline[. on Tue, 19 May 2026 12:58:47 GMT]]></title><description><![CDATA[<p><span><a href="/user/spamhaus%40infosec.exchange">@<span>spamhaus</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> yep that one has been going on for months.  It's this: <a href="https://abnormal.ai/blog/system-notification-abuse-microsoft-phishing" rel="nofollow noopener"><span>https://</span><span>abnormal.ai/blog/system-notifi</span><span>cation-abuse-microsoft-phishing</span></a></p><p>Entra ID tenant branding.  I've been trying to get Microsoft to do something about it for most of the year.</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/GossiTheDog/statuses/116601358089649843</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/GossiTheDog/statuses/116601358089649843</guid><dc:creator><![CDATA[gossithedog@cyberplace.social]]></dc:creator><pubDate>Tue, 19 May 2026 12:58:47 GMT</pubDate></item></channel></rss>