Cyber firm warns companies to beware of scam email campaigns
ISLAMABAD: A leading cyber security company on Thursday warned Pakistani companies to beware of scam email campaigns involving attackers who send emails through Microsoft service links. According to a report of the company issued here, Kaspersky experts have identified a scam email campaign. Attackers send emails that contain legitimate Microsoft service links to redirect users to fraudulent…
A leading cyber security firm in Pakistan has issued a warning to businesses to stay vigilant against scam email campaigns involving attackers who use Microsoft service links to lure victims. According to Kaspersky, an estimated 31,000 emails with such malicious links were blocked between August 1 and September 18. The company noted that earlier this year, they had detected a phishing campaign where attackers were abusing Microsoft’s authentication mechanism.
Now, Kaspersky experts have revealed how cybercriminals are leveraging a similar technique by using a different bait: sending victims emails that appear to be official Microsoft communications, urging them to update their credentials or sign electronic documents. The spammers alter the name field on the Overview page, create fake user accounts with fabricated email addresses, display names, and passwords.
Once they gain access to the Microsoft My Account portal using the credentials of the newly created bogus user, they set the victim's real email address as a backup mailbox for password reset messages. To effectively defend against these threats, organizations should invest in strong email security solutions.
Written by urgent.news from Business Recorder's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.