Microsoft Azure infrastructure hijacked to send phishing alerts
Impersonating: Microsoft
What is this scam?
A sophisticated phishing campaign abuses legitimate Microsoft Azure infrastructure: attackers create Azure accounts, configure automated alert rules, and add victim email addresses as recipients, causing genuine Microsoft system emails to land in inboxes. Because the messages originate from real Microsoft servers they bypass spam filters and carry no obvious signs of spoofing, making them exceptionally difficult to identify as fraudulent without inspecting the embedded links.
Example scam message
Microsoft Azure: An automated alert has been triggered on your subscription. Immediate action is required to prevent service interruption. Verify your account now: azure-account-verify.xyz/login
Red flags to look out for
- The message creates urgency — threatening a fine, missed delivery, or account closure.
- Links lead to unofficial domains that don't match the real company's website.
- You weren't expecting this message and can't verify the event it references.
- It asks you to confirm payment details or personal information via a link.
- The sender's number or email address doesn't match the company's official contact.
What to do if you receive this
- Do not call any numbers or click any links in the message.
- Log in to your account directly via the official website or app to check for any real alerts.
- Forward the message to 7726 or email report@phishing.gov.uk.
- Report it to Action Fraud at actionfraud.police.uk.
Received this message?
Forward it to 7726 (free on all UK networks) to report it to your mobile provider.
You can also report it to Action Fraud
or email the NCSC at report@phishing.gov.uk.
Not sure if your message is a scam?
Check it instantly with our free AI-powered detector.
Check a message nowSource: Action Fraud