Microsoft slammed for sending out hack email warnings that look an awful lot like spam and phishing attacks

A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
(Image credit: weerapatkiatdumrong / Getty Images)

Microsoft has recently been sending out email notifications warning some customers of a data breach that might have impacted their personal information. However, the way the company did it drew heavy criticism, with some people saying Microsoft’s emails looked like spam at best - and phishing at worst.

Cybersecurity researcher (and former Microsoft employee) Kevin Beaumont took to LinkedIn recently to explain to his followers that they’re not being targeted with phishing, and that it was just Microsoft communicating poorly:

“Microsoft had a breach by Russia impacting customer data and didn’t follow the Microsoft 365 customer data breach process. The notifications aren’t in the portal, they emailed tenant admins instead.” Beaumont said. “The emails can go into spam — and tenant admin accounts are supposed to be secure breakglass accounts without email. They also haven’t informed orgs via account managers. You want to check all emails going back to June. It is widespread.”

Scanning the url

One of the key issues, TechCrunch noted, is that Microsoft added a “secure link” to the email - which leads to a domain seemingly unrelated to Microsoft: “purviewcustomer.powerappsportals.com.” 

“Basically, the critical alert looks like a phishing attack,” one of the recipients said on X.

Many of the people receiving this email thought the same, TechCrunch further suggests, since the link got submitted to urlscan.io “more than a hundred times.” URL Scan is a service that can tell if a website is malicious or not. 

What’s more, Microsoft’s support portal has a few posts where customers were looking for clarification if the emails they’re getting are legitimate or not. 

“This email has several red flags for me, the request for the TenantID and essentially admin or high level email addresses, the powerapps page being barebones, and some quick Googling not finding anything related to the title of this email or it’s [sic] contents,” one person wrote. “Can anyone confirm this is a legit Microsoft email request?”

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft authentication system spoofed via phishing attack
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
A padlock resting on a keyboard.
Massive botnet is targeting Microsoft 365 accounts across the world
Microsoft Teams
Microsoft Teams is finally introducing a spam and phishing alert - here’s what you need to know
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Phishing
Russian cyberattackers spotted hitting Microsoft Teams with new phishing campaign
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does