Fake Microsoft warning lands in your inbox
A Microsoft-branded phishing email is circulating, using a scare tactic about data deletion to push you into clicking before you think.
You might receive an email with the subject line "Final notice: Your data is at risk and will be deleted!" that appears to be tied to Microsoft. It is designed to look urgent, with Microsoft branding, a prominent warning banner, and a message that tries to pressure you into taking action straight away to supposedly protect your data. If it lands in your inbox, it will look like an account warning rather than obvious spam.
What gives it away is that the message is coming from anzmi.petrotecnica.com.mx, not Microsoft. While some of the technical checks appear to pass, that does not make it trustworthy. In this case the sending setup can still make the email look more legitimate than it is, even though it is impersonating a completely different organisation. The domain also does not match the brand being presented, which is your clearest practical red flag.
The attacker is trying to get you to click, trust the message, and likely hand over your Microsoft credentials or other account details through a fake follow-up page. If you engage, your business email account could be taken over, giving the attacker access to mail, contacts, files, and internal conversations they can use for further fraud.
This campaign has been observed across multiple organisations in the last day, which means you should treat any unexpected Microsoft warning email with urgency, but not trust it at face value. Verify account alerts by going directly to Microsoft through your usual sign-in page, not through links in the email.
The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Check: Review any recent Microsoft warning emails carefully and confirm whether they came from an official Microsoft domain before taking action.
- Do not: Click links or enter your password from urgent account deletion or data loss emails, even if they use familiar branding.
- Report: Send suspicious messages to your IT provider or security team so the sender domain and message can be blocked or investigated.
- Protect: If anyone clicked or entered credentials, reset the password immediately and review sign-in activity for the affected Microsoft account.
- Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.
See what a genuine Microsoft message looks like, the real sender domain, the real link destination, and where to report a fake.

