Hackers are abusing Microsoft business notifications to target enterprises
Briefly

Windows users are warned about a sophisticated scam using genuine Microsoft emails to trick victims. Scammers insert fake content into real thank-you messages from Microsoft 365, making it appear legitimate. This leads employees to contact their 'support' number, where they are manipulated into installing malicious software. The attackers gain access to sensitive information, leveraging fears of unnecessary purchases. The method of how scammers send these notifications remains a mystery, adding to the urgency for users to remain vigilant.
One would be hard-pressed to imagine an email address with a more trusted reputation, so the message easily gets past any email server filters.
They prey on a common employee fear: making an expensive, unnecessary purchase could cause trouble at work.
Read at www.itpro.com
[
|
]