Monday, August 3, 2026

Apps & Consumer

Scammers exploit Microsoft notification loophole

Scammers are exploiting a loophole in Microsoft’s internal email notification system to send spam, though the exact method of abuse remains unclear.

Scammers exploit Microsoft notification loophole

Scammers are currently exploiting a loophole in Microsoft’s internal email notification system to send spam emails from an internal Microsoft email address. It is not clear how the scammers are abusing the system to send these messages, which mimic official alerts. Microsoft does not yet appear to have resolved the issue. The loophole allows unauthorized actors to send messages from an address typically reserved for official notifications, such as two-factor authentication codes, potentially tricking recipients into believing the emails are genuine. This activity was observed firsthand last week, when multiple spam emails containing subject lines and links to scammy sites were received across different accounts.

The Spamhaus Project, an anti-spam nonprofit organization, observed the abuse and notified Microsoft of the issue. On Tuesday, the organization posted about the activity on social media, noting that the abuse has been occurring for several months. In its public assessment, the group pointed out a structural flaw in how these automated alerts are configured, warning that allowing high levels of customization poses ongoing security risks. “Automated notification systems should not allow this level of customization,” the organization stated, emphasizing that it has already alerted Microsoft to the ongoing vulnerability.

In response to the reports, Microsoft representative Emelia Katon, who represents the company via a third-party public relations agency, stated that the company is actively investigating and taking action against these phishing reports to help keep customers protected. Katon explained that Microsoft’s ongoing response includes further strengthening its internal detection and blocking mechanisms, alongside removing the specific accounts that violate the company’s Terms of Use.

This incident follows a broader pattern of security compromises where malicious actors exploit trusted corporate communication channels. Earlier this year, hackers broke into a platform used by fintech firm Betterment to send out fraudulent notifications that purported to triple the value of any cryptocurrency users sent in. Similarly, in 2023, hackers abused access to an email account run by domain registrar and web hosting company Namecheap to send out phishing emails.

Why it matters

This incident highlights a recurring vulnerability where hackers exploit trusted corporate notification systems to deceive users, underscoring the need for tighter security controls on automated alerts.