
Scammers are exploiting Microsoft Azure Monitor alerts to distribute callback phishing emails that mimic warnings from Microsoft Security about unauthorized account charges.
Azure Monitor is Microsoft’s cloud service for monitoring and analyzing data from Azure resources, apps, and infrastructure. It allows users to monitor performance, get notified about billing changes, spot problems, and automatically trigger alerts based on certain conditions.
In the last month, many individuals have reported getting Azure Monitor alerts that falsely warn of questionable charges or invoice activity and encourage recipients to call a provided phone number.
“Alert rule description MICROSOFT CORPORATION BILLING AND ACCOUNT SECURITY NOTICE (REF: MS-FRA-6673829-KP). Our system has detected a potentially unauthorized charge on your account. Transaction Details: Merchant: Windows Defender. Transaction ID: PP456-887A-22B. Amount: 389.90 USD. Date: 03/05/2026l,” is what the fake billing alert states.
“For your protection, this transaction has been temporarily placed on hold by our Fraud Detection Team. To prevent possible account suspension or additional fees, please verify this transaction immediately. If you did NOT authorize this payment, contact our 24/7 Microsoft Account Security Support at +1 (864) 347-2494 or +1 (864) 347-4846.”
“We apologize for any inconvenience and appreciate your prompt response. Microsoft Account Security Team.”
Unlike typical phishing attempts, these emails are actually sent through the Microsoft Azure Monitor platform itself, using the genuine [email protected] email address, rather than being spoofed.
Because the emails originate from Microsoft’s valid email systems, they pass email security checks like SPF, DKIM, and DMARC, adding to their credibility.
The attackers are implementing this attack by setting up Azure Monitor alerts for easily triggered events, like new orders, payments, generated invoices, and other billing activities.
When creating the alerts, the attackers are able to insert their callback phishing message within the description field.
These alerts are then configured to email what is thought to be a mailing list managed by the attackers, which then forwards the email to the intended victim(s).
This method also preserves Microsoft’s original email headers and authentication details, which helps the messages evade spam filters and avoid raising user suspicion.
BleepingComputer has identified multiple alert categories employed in this campaign, primarily using invoice and payment themes designed to look like automatic billing notifications:
The attack depends on generating a sense of urgency, in this case, the unexpected $389 Windows Defender charge, to induce users to call the listed phone number.
While BleepingComputer has not contacted the number associated with this scam, similar callback phishing schemes have been previously used to steal login information, commit payment fraud, or deploy remote access software.
Because these emails have a corporate feel, they likely aim to gain a foothold into corporate networks for future attacks.
Users should be wary of any Azure or Microsoft alert that contains a phone number or makes urgent requests about resolving billing problems.
#alerts #azure #callback #exploits #monitor #news #phishing — News
© Bulletproof Servers. All rights reserved.