Recently, there have been reports of scammers misusing the email address, “[email protected]”, which is frequently used by Microsoft for sending important account notifications such as two-factor authentication codes and security alerts. These scammers have been exploiting Microsoft’s notification system to distribute fake messages that seem genuine.
Numerous social media posts have highlighted instances where individuals have received emails from the official Microsoft email address mentioning topics like Bitcoin investments, unknown websites, or suspicious phone numbers. These fraudulent emails are crafted to closely resemble Microsoft’s usual style and branding, potentially deceiving unsuspecting recipients.
The concerning aspect is that since these emails originate from a legitimate Microsoft-owned email address, they might evade detection by typical spam and phishing filters employed by email service providers. A recent report from cybersecurity company Abnormal in January 2026 revealed that cybercriminals had already been using Microsoft’s notification platform to send phishing emails aimed at extracting personal or financial details from users.
