Cyber firm warns companies to beware of scam email campaigns
ISLAMABAD: A leading cyber security company on Thursday warned Pakistani companies to beware of scam email campaigns involving attackers who send emails through Microsoft service links.
According to a report of the company issued here, Kaspersky experts have identified a scam email campaign. Attackers send emails that contain legitimate Microsoft service links to redirect users to fraudulent sites or to download malware. From August 1 to September 18, more than 31,000 emails with such links were blocked by Kaspersky solutions.
Earlier this year Kaspersky reported detecting a phishing campaign where attackers abused Microsoft’s authentication mechanism. Now Kaspersky experts explain how cyber criminals are exploiting the same technology, using another bait for the phishing: attackers sent victims emails disguised as an official Microsoft communication, urging them to follow the link to keep their credentials for the service updated or to sign electronic documents.
Spammers put a fake message in the name field on the Overview page, then create bogus users in the Users section with made up email addresses, display names and passwords. Then attackers log into the Microsoft My Account portal with the new credentials of the created bogus user and enter the victim’s real email address as a backup mailbox (used for password reset messages).
To establish a comprehensive defense against such threats, organizations should consider using robust email security solutions.
Copyright Business Recorder, 2026
























Comments