Friday, June 24, 2022
CybersecFill
Advertisement
  • Home
  • Events
  • News
  • security tips
  • Article
  • Contact Us
No Result
View All Result
  • Home
  • Events
  • News
  • security tips
  • Article
  • Contact Us
No Result
View All Result
CybersecFill
No Result
View All Result
Home News

Users Beware!!!! Spotting A Microsoft Renewal Scam….

Henrietta Ijenebe by Henrietta Ijenebe
March 31, 2021
in News
0
Users Beware!!!! Spotting A Microsoft Renewal Scam….

ImageSource:https//securityintelligence.com

Share on FacebookShare on Twitter

Hackers have several ways to get users’ attention. A novel scam began when a user received an email impersonating a notification from Microsoft, Abnormal Security observed on Friday, July 17, 2020. The scam arrived after Microsoft had recently taken several steps to deter scammers. Security professionals should be aware of this attack’s methods when on the lookout for new possible problem vectors.

The lookalike Microsoft webpage functioned as a submission form, prompting users to reveal their data, including their physical addresses and payment card information, in the text fields. In the first variant of the attack, a user received an email with the subject line “Reminder for Office Renewal.” This email informed the recipient that they had two days to renew their Office 365 subscription. It then instructed them to visit “office365family[dot]com,” a website hosted via Wix that used “Office 365” in its domain name to convince the user it was an official Microsoft page.

The website also used similar imagery to the official Microsoft website, replicated the Microsoft site’s footer, and leveraged the same official links as the original. Even so, the landing page for this attack implemented different fonts and suffered from many broken header pages — signs it was a fake.

The second variant of the scam was similar to the first. It arrived with “Time to Renew” as its subject line. The email informed the user they had two days to renew their Office 365 subscription. However, this iteration didn’t send the recipient to a landing page. Instead, it used a “Renew Now” link to redirect the user to an authentic PayPal page where they could supposedly renew their subscription to Office 365.

ImageSource:https//dailystar.co.uk

The PayPal page listed “Microsoft Office 1 Year” as the item the user would be paying for. But, the page didn’t provide any additional proof of what the user was buying. When the user submitted their payment card credentials and completed the purchase, they sent over their funds, not to Microsoft but an unknown individual, and subsequently received nothing in return.

Microsoft’s Ongoing Efforts to Deter Scammers

Microsoft recently added several options to cut down on scam messages in its products. In August 2019, for instance, the Verge covered the Redmond-based tech giant’s release of the SMS Organizer app for Android. This program automatically sorted all spam promotional SMS messages received by a user into a “promotions” folder, separating them from legitimate SMS messages.

Two months later, Bleeping Computer reported on the rollout of the new Office 365 feature called “Unverified Sender.” This feature displayed a notice to users when Office 365 spoof intelligence had failed to verify the sender of an incoming email message — a possible sign of bad activity. Additionally, Microsoft announced the public preview of “campaign views” in Office 365 Advanced Threat Protection at the beginning of December 2019. This component provided extra context and visibility into phishing campaigns that had targeted an organization and how their defenses had fared against those efforts.

Near the end of July 2020, Bleeping Computer helped to publicize a feature that first appeared in Microsoft Edge 84. Dubbed “Quiet Notification Requests,” the feature’s design is to help counter website permission requests spam by blocking notifications and Push APIs by default in the Edge browser.

How to Defend Against a Microsoft Renewal Email Scam

Security professionals can help defend their organizations against a Microsoft renewal email scam by investing in a security awareness training program and regularly testing employees’ familiarity with common phishing techniques, including the use of convincing attack domains for landing pages. They should complement this training with email security controls that use AI and machine learning to help spot the signs of a compromised email account, device, or set of credentials.

Conclusion

Hackers do not tire out. Their schemes are never outdated but only go through upgrades and updates. Do not view any form of attack as outdated, because they could use it against you when you least expect it. Please endeavor to stay informed regarding your online safety and security.

Tags: Email ScamMicrosoftMicrosoft Office 365PaypalSecurity Awareness
Henrietta Ijenebe

Henrietta Ijenebe

Another Breed striving to make our cyber.space a better state of existence. CyberContent Writer at Cybersecfill. Cybersecurity Threat Intelligence Analysis... Penetration Testing... I code in Javascript...Python...PHP I convey with HTML I beautify with CSS

Next Post
The Hunter Becomes The Hunted!!!

The Hunter Becomes The Hunted!!!

0 0 votes
Article Rating
Login
guest
guest
0 Comments
Inline Feedbacks
View all comments
  • Trending
  • Comments
  • Latest
CEH_PRACTICAL

CEH PRACTICAL EXAM – TICKET TO CEH MASTER

February 6, 2021
Wireless Access Point

How To Secure Your Wireless Access Point (WAP)

August 3, 2019
Wifi 6 Security

Did Wi-Fi 6 come with an Improvement In Security?

May 13, 2019
credit card cloning

How Credit/Debit Cards are Cloned / Preventing Card Cloning

December 26, 2019
Nationa Cybersecurity Strategy

A Review of the Nigeria National Cybersecurity Strategy

9
Facebook

Facebook’s New Settings Allows Hackers To Easily Pentest Facebook,Instagram Mobile Applications

8
Cybersecurity Jobs

Cybersecurity Jobs – You can create your own Cybersecurity Role

4
open Source intelligence tools

Open Source Intelligence tools – OSINT

4
Suspected Head of Cybercrime Gang Arrested in Nigeria…

Suspected Head of Cybercrime Gang Arrested in Nigeria…

June 17, 2022
Types of Hackers and Hacking Protection Tips….

Types of Hackers and Hacking Protection Tips….

June 6, 2022
Types of Hackers and Hacking Protection Tips…

Types of Hackers and Hacking Protection Tips…

May 31, 2022
Sports Betting…Increase in Cybersecurity and Data Privacy Risks for Companies and Consumers.

Sports Betting…Increase in Cybersecurity and Data Privacy Risks for Companies and Consumers.

May 19, 2022

Recommended

Suspected Head of Cybercrime Gang Arrested in Nigeria…

Suspected Head of Cybercrime Gang Arrested in Nigeria…

June 17, 2022
Types of Hackers and Hacking Protection Tips….

Types of Hackers and Hacking Protection Tips….

June 6, 2022
Types of Hackers and Hacking Protection Tips…

Types of Hackers and Hacking Protection Tips…

May 31, 2022
Sports Betting…Increase in Cybersecurity and Data Privacy Risks for Companies and Consumers.

Sports Betting…Increase in Cybersecurity and Data Privacy Risks for Companies and Consumers.

May 19, 2022

© 2020 CybersecFill. All Rights Reserved.

No Result
View All Result
  • Home
  • Events
  • News
  • security tips
  • Article
  • Contact Us

© 2020 CybersecFill. All Rights Reserved.

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply

Privacy Policy - Terms and Conditions