Scammers have been exploiting a major system loophole for several months to send malicious spam and phishing links directly from an official Microsoft email address, leveraging user trust in the tech giant’s security notifications.
How Scammers Hijacked Trusted Microsoft Alerts
The ongoing abuse targets an internal email address, msonlineservicesteam@microsoftonline.com, which Microsoft officially uses to distribute critical security updates, two-factor authentication codes, and account alerts. By registering new Microsoft accounts under the guise of legitimate corporate clients, bad actors have bypassed standard filters to dispatch deceptive emails that appear entirely authentic to unsuspecting recipients.
The crudely made messages vary in their deceptive tactics. Some subject lines mimic urgent alerts warning of fraudulent financial transactions, whilst others bait users with claims of a “private message” waiting for them via an external hyperlink embedded in the text.

Cybersecurity Watchdogs Sound the Alarm
The Spamhaus Project, an international anti-spam non-profit organisation, confirmed the exploit in a social post on Tuesday. The watchdog group revealed that this specific Microsoft notification vector has been actively abused for several months and has urged the company to rectify the flaw.
“Automated notification systems should not allow this level of customisation,” Spamhaus stated, confirming they had officially reported the vulnerability to Microsoft’s security team.
Microsoft’s Response and Investigation
Following initial silence, Microsoft addressed the issue through Emelia Katon, representing the company via an external public relations agency. The tech giant confirmed that an active investigation is underway to mitigate the security threat.
“We are actively investigating and taking action against these phishing reports to help keep customers protected,” the statement read. “This includes further strengthening our detection and blocking mechanisms, while removing accounts that violate our Terms of Use.”
A Growing Trend in Corporate Brand Exploitation
This incident is part of a broader, highly concerning trend where threat actors compromise legitimate corporate delivery channels to bypass traditional email security protocols. Earlier this year, hackers compromised a communication platform utilised by fintech firm Betterment to blast fraudulent notifications promising to triple cryptocurrency deposits—a classic digital asset drainer scam.
Similarly, in 2023, cybercriminals similarly abused access to Namecheap’s mailing systems to launch highly targeted phishing campaigns designed to harvest user credentials.
Reports on social media platforms indicate that Microsoft is not the only enterprise facing this issue, as users observe similar spam campaigns originating from other reputable corporate domains, indicating a systemic vulnerability in automated transactional email setups across the industry.
