Skip to content

At The Identity Organisation, we're here to help!

    Your privacy is important to us, and we want to communicate with you in a way which has your consent and which is in line with UK Law on data protection. As a result of a change in UK law on 25th May 2018, by providing us with your personal details you consent to us processing your data in line with current GDPR requirements.

    Here is where you can review our Privacy & GDPR Statement

    To remove consent at any time, please e-mail info@tidorg.com with the word "unsubscribe" as the subject.

    +44 (0) 1628 308038 info@tidorg.com

    Unusual sign-in activity mail goes phishing for Microsoft account holders

    Phishing

    We’ve received an interesting spam email which (deliberately or not) could get people thinking about the current international crisis. Being on your guard will pay dividends over the coming days and weeks, as more of the below is sure to follow.

    Unusual sign-in activity detected?

    The email’s subject line, “Microsoft account unusual sign-in activity”, is always guaranteed to attract some attention. It continues:

    Unusual sign-in activity

    We detected something unusual about a recent sign-in to the Microsoft account

    Sign-in details

    Country/region: Russia/Moscow

    IP address:

    Date: Sat, 26 Feb 2022 02:31:23 +0100

    Platform: Kali Linux

    Browser: Firefox

    A user from Russia/Moscow just logged into your account from a new device, If this wasn’t you, please report the user. If this was you, we’ll trust similar activity in the future.

    Report the user

    Thanks,

    The Microsoft account team

    The mail provides a button to “report the user”, and an unsubscribe option. Should the recipient click the button, they’re not forwarded to a report page. Instead, it’s a Mailto: URI which opens a fresh email with a pre-filled message to be sent to a specific email account.

    In this case, the email’s subject line is “Report the user”, while the phisher’s mail address claims to be some form of Microsoft account protection. They also managed to spell account wrong – “acount”. 

    Don’t reply: report and delete

    People sending a reply will almost certainly receive a request for login details, and possibly payment information, most likely via a bogus phishing page. It’s also entirely possible the scammers will keep everything exclusively to communication via email. Either way, people are at risk from losing control of their account to the phishers. The best thing to do is not reply, and delete the email.

    Is this mail deliberately or accidentally referencing world events?

    We have to be very clear here that anybody could have put this mail together, and may well not have anything to do with Russia directly. This is the kind of thing anyone anywhere can piece together in ten minutes flat, and mails of this nature have been bouncing around for years.

    But, given current world events, seeing “unusual sign-in activity from Russia” is going to make most people do a double take, and it’s perfect spam bait material for that very reason.

    While the mail explicitly targets Microsoft account holders, Outlook is flagging this missive and dropping it directly into the spam box. This probably isn’t something the mail creators need, quite frankly. However, this is great news for everybody else.

    With thanks to the Cyber Defence Alliance and Malwarebytes. The full story is here: https://blog.malwarebytes.com/scams/2022/03/unusual-sign-in-activity-mail-goes-phishing-for-microsoft-account-holders/

    Free Phishing Security Test

    Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

    PST Results

    Here’s how it works:

    • Immediately start your test for up to 100 users (no need to talk to anyone)
    • Select from 20+ languages and customize the phishing test template based on your environment
    • Choose the landing page your users see after they click
    • Show users which red flags they missed, or a 404 page
    • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
    • See how your organization compares to others in your industry

    PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/phishing-security-test-partner?partnerid=001a000001lWEoJAAW

    Sign Up to the TIO Intel Alerts!

    Back To Top