Technology newsroom
MFA might not be enough! Detect fake emails that secretly steal Microsoft 365 accounts
Learn how to check for phishing emails that claim to be from Microsoft 365 to prevent data and account theft, even if multi-factor authentication (MFA) is enabled.
💻 Scammers always have new ways to trick and steal our Microsoft 365 accounts, even with multi-factor authentication (MFA). They use fake emails that look very convincing, causing many people to fall victim. Let's look at some basic ways to check for safety.
1. Check the sender's email: Pay close attention to the sender's email name to see if it is really an official Microsoft domain (@microsoft.com). If the email is long, strange, or misspelled, be suspicious.
2. Watch for hurried content: Scam emails often create a sense of urgency, such as notifying you that your account will be suspended or your information will be deleted, to pressure you into following their instructions quickly.
3. Don't click yet! Try hovering the mouse: Before clicking any link, try hovering the mouse over the link to see a preview of the URL. If it is an unfamiliar website or not a Microsoft site, do not click at all.
4. Check spelling and grammar: Emails from large organizations are usually well-reviewed. If you find messages that look strange or have spelling errors, it may be a warning sign.
⚠️ The most important thing is never to enter your password or personal information on a webpage opened from a suspicious email link, even if the page looks like the real one.
If you are unsure about any email, forward it to the company's IT department for consultation. Do not risk clicking on links or opening attachments at all. The security of your account is the most important.