Phishing Scams Now Abusing Microsoft.com Domains, Warns Chirag Goswami

C

Chirag Goswami

LinkedIn Author

💡 LinkedIn Top Voice💡 || Cyber Security || Cybernara – We’ve Only One Mission: Provide the Best Cyber Security Solution

In a recent LinkedIn post, Chirag Goswami highlights a sophisticated new phishing tactic that leverages Microsoft’s own systems to deceive unsuspecting users. Goswami, a cybersecurity expert, warns that malicious actors are now exploiting Microsoft Entra’s external invitation system to send fraudulent emails that appear to originate from the legitimate Microsoft domain.

Exploiting Trust in Legitimate Domains

The core of this attack, as explained by Goswami, lies in its ability to bypass standard security measures. By using the legitimate invites@microsoft.com address, these phishing emails are authenticated by crucial security protocols like SPF, DKIM, and DMARC. This makes them appear entirely trustworthy to both users and their email spam filters.

Goswami elaborates on the deceptive nature of these emails, noting the specific tactics used to trigger a sense of urgency and panic. Common lures include fake invoices or billing alerts that mimic legitimate Microsoft 365 charges, often accompanied by a seemingly official Microsoft Support phone number.

“Yes, the sender is real. The email is not. Hackers found a way to abuse Microsoft Entra’s external-invitation system.”

This method is particularly effective because it plays on the inherent trust users place in well-known and secure brands like Microsoft. When an email arrives from an official-looking address, especially with urgent financial implications, individuals are more likely to act without critical evaluation.

The Mechanics of the Scam

According to Goswami, the attackers edit the invitation note within the Microsoft Entra system to embed their fraudulent content. This allows them to craft messages that look like genuine communications from Microsoft, creating a false sense of legitimacy.

“You see a ‘Microsoft 365 charge ₹446 / $446.’ You see a ‘Microsoft Support’ phone number. But the number goes straight to the scammer.”

Goswami points out several reasons why this attack is so successful:

  • The email originates from Microsoft’s actual servers.
  • It successfully passes SPF, DKIM, and DMARC authentication.
  • The appearance of the email is completely normal, lacking typical phishing red flags.
  • The content triggers panic, prompting immediate action.

Essential Defense Strategies

To combat this evolving threat, Goswami provides a clear, actionable rule for individuals and teams to follow. He stresses the importance of verifying unexpected billing alerts directly rather than relying on contact information provided within the suspicious email.

“If you get a Microsoft billing alert you weren’t expecting, NEVER call the number inside the email. Go directly to Microsoft.com and check your billing page.”

This advice underscores a fundamental principle of cybersecurity: always independently verify critical information, especially when it involves financial transactions or security alerts. Relying on direct access to official websites or established communication channels, rather than links or numbers in potentially compromised emails, is crucial.

Goswami concludes by emphasizing that real-world attacks are becoming increasingly sophisticated, making it essential for organizations to update their phishing awareness and response protocols. His firm, Cybernara, assists businesses in refining these playbooks to address such advanced threats where malicious emails are virtually indistinguishable from legitimate ones.

“Cybernara helps teams update their phishing playbooks for real-world attacks like these — where the email looks perfect because it is perfect.”

This situation serves as a stark reminder of the constant need for vigilance in the digital realm, as cybercriminals continuously find innovative ways to exploit trusted platforms and systems.

📝 About This Content

This article is based on insights shared by Chirag Goswami on LinkedIn.

📅 Originally posted on December 2, 2025 | View original post on LinkedIn →