A new and sophisticated phishing scam has been uncovered, leveraging Microsoft 365 domains to trick users into compromising their PayPal accounts.
The attack exploits legitimate-looking sender addresses and URLs, making it harder for victims to recognize the phishing attempt.
Security experts, including Chief Information Security Officers (CISOs), have raised alarms about the growing menace, urging caution and vigilance, shared by Fortinet.
Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free
This phishing campaign uses Microsoft 365’s free trial domains to craft authentic-looking email addresses.
Once a scammer registers a trial domain, they set up deceptive distribution lists with obscure addresses resembling legitimate ones.
For example, an email might appear to originate from “Billingdepartments1[@]gkjyryfjy876.onmicrosoft.com,” which at first glance might look credible to unsuspecting users. Here’s the scam’s modus operandi step-by-step:
The cleverness of this attack lies in its leveraging of legitimate technologies. By using free Microsoft 365 test domains, the scammers bypass conventional detection systems.
The distribution list feature further obfuscates the true sender, creating plausible deniability. Even PayPal’s phishing detection instructions would fail to flag this method.
Most dangerously, the phishing email’s sender address and links appear authentic, and the email passes standard security checks. This raises the stakes, as even tech-savvy users might fall for the scam.
Experts urge vigilance when handling payment requests, even from seemingly legitimate sources. Here are some safety recommendations:
As attackers continue to innovate, staying informed and cautious is vital. PayPal users, especially those handling corporate accounts, must prioritize cybersecurity to avoid falling victim to threats like these.
Find this News Interesting! Follow us on Google News, LinkedIn, and X to Get Instant Updates!
Microsoft Entra ID has introduced a robust mechanism called protected actions to mitigate the risks…
The realm of fault injection attacks has long intrigued researchers and security professionals. Among these,…
IBL Software Engineering has disclosed a significant security vulnerability, identified as CVE-2025-1077, affecting its Visual…
OpenAI, the organization behind ChatGPT and other advanced AI tools, is making significant strides in…
New York Governor Kathy Hochul announced that the state has banned the use of the…
Cybercriminals are capitalizing on the season of love to launch sneaky and deceptive cyberattacks. According…