Cybercriminals have discovered a new method to send extortion emails: They do this by abusing the Microsoft 365 admin portal. This trick allows them to bypass spam filters and land directly in their victims’ inboxes.
In addition, the whole thing seems extremely realistic and, according to the initial reports, the approach to the victims is also well done, unlike other blackmail emails. The sophisticated scam is currently making the rounds. Cyber criminals have found a way to abuse the Microsoft 365 admin portal for their own purposes. With this method, they send so-called “sextortion” emails, which end up directly in the recipient’s inbox due to their apparent legitimacy.
The fraudsters achieve this by directly using the message center of the Microsoft 365 Admin Portal, which is actually intended for official notifications about services and functions.
Like the IT news site Bleeping computers According to reports, the criminals cleverly bypass the usual spam filters. The reason: The messages are sent from a trustworthy Microsoft address (o365mc@microsoft.com). This means that security systems classify them as legitimate and do not screen them out. The cybercriminals simply use the “Share” feature to spread their fraudulent messages. These emails then appear to come directly from Microsoft, which makes them particularly dangerous.
The content of these emails follows a familiar pattern:
To make the claims appear credible, criminals often include personal information such as dates of birth in their messages. This information often comes from previous data leaks and increases the pressure on victims because the whole thing looks even more realistic with lots of real data. Computer crime: Where cyberattacks originate
Microsoft has confirmed that they are investigating the issue, but so far no server-side checks have been implemented to block such messages. The scammers appear to be exploiting a vulnerability in the “Personal Message” field of the Microsoft 365 Message Center. Although this field is actually limited to 1000 characters, they get around this limitation by manipulating the HTML code.
Those affected should first understand that, despite the impression of being “official”, it is only an attempted fraud. Microsoft recommends the following steps:
This scam shows how creative cyber criminals are when developing their fraud attempts. They specifically exploit vulnerabilities in trustworthy systems to deceive their victims. This makes it increasingly difficult for users to distinguish legitimate from fraudulent emails.
The creativity of cybercriminals knows no bounds. It’s a constant race between security experts and fraudsters. An anonymous IT security expert
Digital marketing enthusiast and industry professional in Digital technologies, Technology News, Mobile phones, software, gadgets with vast experience in the tech industry, I have a keen interest in technology, News breaking.
After Windows Patch Day in July 2026, reports of problems with the Windows Server Update…
The payment service provider PayPal is apparently facing a large-scale takeover. Two investors have submitted…
A new mod for GTA San Andreas lets players play two older parts of the…
With the increasing spread of autonomous robotaxis, not only the technical capabilities of the vehicles…
From 2028, electric car drivers in the UK will have to pay a distance-based levy.…
Shortly before the next Unpacked event on July 22nd, official promo images of the new…