Cybercriminals Exploit Microsoft Email System to Send Fraudulent Messages
Scammers are using a Microsoft email vulnerability and fake Geek Squad billing notices to steal personal information from consumers.

Cybercriminals have discovered ways to exploit Microsoft's email infrastructure to send fraudulent messages that appear to come from legitimate sources, according to security researchers.
One method involves abusing an internal Microsoft account system that allows scammers to send emails from genuine Microsoft email addresses, typically those used for authentic account notifications. This vulnerability gives fraudulent messages an appearance of legitimacy that can deceive recipients.
Separately, criminals are distributing fake Geek Squad billing emails that use Razorpay payment service branding to pressure consumers into clicking malicious links. These fraudulent messages are designed to trick recipients into providing sensitive personal and financial information.
Security experts warn that these types of attacks exploit consumer trust in familiar brand names and official-looking email addresses. The fake Geek Squad emails specifically target users by creating urgency around supposed billing issues.
The incidents highlight ongoing challenges in email security, where criminals continue to find new ways to circumvent authentication systems and exploit trusted platforms to reach potential victims. Recipients are advised to verify any unexpected billing or account notifications through official company websites rather than clicking links in emails.