Kaspersky Blocks More Than 31,000 Scam Emails Exploiting Microsoft Authentication

Kaspersky warns about scam emails exploiting legitimate Microsoft authentication services.
Kaspersky researchers have detected a phishing campaign exploiting legitimate Microsoft authentication services to trick users into visiting fraudulent websites or downloading malware.
Kaspersky said its security solutions blocked more than 31,000 scam emails containing such links between August 1 and September 18.
The campaign uses legitimate Microsoft service links to make fraudulent messages appear more trustworthy. Attackers disguise emails as official Microsoft communications and ask recipients to update their service credentials or sign electronic documents.
How Attackers Exploit Microsoft Authentication
According to Kaspersky, attackers first create a Microsoft account and access the Microsoft entra admin center.
They then register a new application and specify a redirect URI. This address tells Microsoft’s authentication server where to send a user after successful Authorisation.
US Voters Demand Tougher AI Rules as Poll Finds Concerns Over Trump and Congress
Cybercriminals insert a malicious website into the redirect field. They then distribute Microsoft authentication links containing the registered application’s ID and the fraudulent redirect address.
When victims click the links, they can be redirected to websites designed to steal personal information or deliver malicious software.
Fraudulent Messages Add to the Threat
Kaspersky researchers also identified another technique involving legitimate Microsoft notifications.
Attackers can use the Microsoft entra admin center to place fraudulent content into legitimate service notifications. Kaspersky said criminals may purchase a low-cost Licence or use a trial period to gain access to the required services.
The attackers then create fake users with fabricated email addresses, names and passwords. They use these accounts through the Microsoft My Account portal and enter a victim’s real email address as a backup mailbox.
This can cause the victim to receive an unsolicited verification code. The fraudulent message can also appear in the email subject line and signature, making the communication look more credible.
Kaspersky Warns of Sophisticated Phishing
Andrey Kovtun, Email Threats Protection Group Manager at Kaspersky, said attackers are increasingly using legitimate services to deliver fraudulent links and messages.
He said this approach adds credibility to phishing attempts and makes traditional warning signs less effective.
Kovtun urged users to deploy security solutions with strong anti-phishing capabilities to provide automatic protection against sophisticated attacks.
Kaspersky also recommended robust email security for Organisations to defend against advanced mail-borne threats. For individual users, the company highlighted its anti-phishing features designed to reduce exposure to fraudulent websites and messages.
The campaign highlights a broader cybersecurity challenge: legitimate authentication infrastructure can be abused to make malicious communications appear genuine, increasing the risk of successful phishing attacks.
