Phishing From Microsoft's Own Mail

Security Insights  /  Phishing From Microsoft's Own Mail

Jake Marchese | SOC Analyst | 20 August 2026

Attackers are making Microsoft send their phishing emails for them, and the lures have been localised for Australia.

Over the last two weeks, Fortian has observed a campaign matching research recently published by Abnormal AI, in which threat actors abuse Entra ID tenant branding to inject social engineering lures directly into legitimate Microsoft security notifications. The emails arrive from msonlineservicesteam@microsoftonline.com, pass SPF, DKIM and DMARC - because they are genuine Microsoft emails.

How it works

A subject line from the samples we observed:

Dràmà Rèèlš šübšçrïptïön rènèwèd 349.99 AUD TRX ÏD NBÜDYŠ87 Ünàpprövèd ördèr Vèrïfy wïth PÏN ör çàll 61 (02) 7258-0712 account email verification code

Note the localisation. Where the publicly reported samples used a US callback number and a Bitcoin or PayPal pretext, this one uses AUD, a fabricated transaction reference and a Sydney landline. The number is also formatted inconsistently, combining the country code with the domestic trunk prefix. This is something no legitimate Australian sender would do.

Why this defeats most controls

The samples we observed are commodity fraud, a fake subscription renewal designed to funnel victims into a callback scam. But the delivery mechanism is the story, not necessarily the payload itself. The orchestration methods such as a disposable tenant, injected branding, legitimate Microsoft infrastructure as the mail relay, is available to any threat actor with a credit card and five minutes. A more capable adversary using this for targeted credential harvesting or BEC against a specific organisation looks very different, because the lure arrives from a sender your mail gateway already trusts, inside a notification template your users already expect, with no URL or attachment to detonate. No link to click, no attachment to sandbox, and your gateway already trusts the sender.

Durable artefacts worth hunting on

What we recommend

Microsoft won't be the last platform abused this way. Any SaaS product that reflects user controlled metadata into an outbound notification template is a candidate. If your detection logic stops at "the sender authenticated correctly", this walks straight through. The technique is freely available to anyone who can register a trial tenant, and the next campaign to use it may not be aiming at individuals.

CONTACT US

Sign up or speak with a Fortian Security Specialist

Request a consultation with one of our security specialists today or sign up to receive our monthly newsletter via email.

Get in touch