Scammers are abusing an internal Microsoft account to send spam links
techcrunch.com May 21, 2026

Scammers are abusing an internal Microsoft account to send spam links

AI-summarised brief · reviewed before publication

Scammers have been exploiting a loophole in Microsoft's internal email system to send spam emails from a legitimate-looking Microsoft address. The emails, which appear to be from Microsoft's "msonlineservicesteam@microsoftonline.com" account, contain links to scam sites and may trick recipients into thinking they are genuine. The issue has been ongoing for several months, with Microsoft yet to address the problem. The Spamhaus Project, an anti-spam non-profit, has notified Microsoft of the issue, but the company has not commented.

💡 Why It Matters

  • · The abuse of Microsoft's internal email system highlights a broader vulnerability in automated notification systems, which can be exploited by scammers to trick unsuspecting customers.
  • · This issue is not isolated to Microsoft, as other companies' email addresses are also being used to send out spam, suggesting a systemic problem that requires a more comprehensive solution.