M
Microsoft
Convincing Microsoft 365 "Action Required" and "Security Alert" emails remain the most common entry point for business email compromise.
Official indicators
M
Microsoft<account-security-noreply@accountprotection.microsoft.com>
To: you@example.com
For your security, please Sign in to your Microsoft account to complete this action.
Original URL: https://login.microsoftonline.com/. Click or tap if you trust this link.
What real Microsoft messages look like
- Security alerts come from
@accountprotection.microsoft.com,@email.microsoft.com, or@office365.microsoft.com - Official links often use the
aka.msshortener - Microsoft will not proactively reach out to provide unsolicited PC or technical support
- Security alerts will never ask you to call a phone number
Common spoof patterns
- "Your account has been locked" phishing emails leading to fake login portals
- "Action Required: Update your security settings" lures harvesting credentials
- Fake "Voicemail" or "Document Shared" notifications with malicious attachments

