Fake Microsoft warning wants your login
A Microsoft 365 themed phishing email is circulating across NZ, warning that your files will be deleted unless you act urgently.
You could receive an email that looks like it comes from Microsoft 365, using the subject line "Last Reminder: Your Files Will Be Permanently Deleted !" and a bold warning that your subscription has been suspended. It pushes you to take urgent action before deletion, using Microsoft 365 branding and a final-chance message designed to make you click before you think.
What gives it away is the sender. The email is coming from portal-office365-nz.inyer.com.mx, service-office365-portal.inyer.com.mx, service-update-nzbill.inyer.com.mx, or update-serviceoffice365-nz.inyer.com.mx which are not a Microsoft domain, even though the message is dressed up to look legitimate. Some of the usual technical checks appear to pass, which can make it seem trustworthy at first glance, but the sending record does not line up cleanly and that is a warning sign. In plain terms, parts of the email look legitimate enough to slip past basic trust checks, while the real sender still does not match the brand it claims to represent.
This is most likely after your Microsoft 365 login details. If you click through and sign in, you could hand over access to your email, files, contacts, and any connected Microsoft 365 services. That can lead to account takeover, internal phishing from your mailbox, and wider compromise across your business.
The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.
Practical steps you or your IT provider can take to reduce the risk from this kind of threat.
- Check: Inspect any Microsoft 365 warning emails carefully, especially if they threaten deletion or suspension and create urgency.
- Verify: Confirm the real sender domain before you click anything. Microsoft services should not be asking you to sign in from an unrelated domain.
- Do not: Enter your Microsoft 365 password after following links from unexpected emails, even if the branding looks genuine.
- Report: Send suspicious messages to your IT provider or security team so the sender and any linked pages can be blocked quickly.
- Contact Decision1: If you believe your business has been targeted, contact the Decision1 team immediately.
See what a genuine Microsoft message looks like, the real sender domain, the real link destination, and where to report a fake.

