Reddit Scam Pattern
Compromised professional accounts delivering Microsoft credential phishing
3 reports · first seen 13 July 2026 · last seen 13 Aug 2026
Attackers hijack trusted professional email accounts — such as lawyers or business contacts — to send convincing phishing messages containing fake encrypted documents or shared links. Recipients are directed to spoofed Microsoft login pages where credentials are harvested, often aided by real email history to establish legitimacy.
How the scam works
Trusted-account compromise used to deliver malicious document or sharing links redirecting to spoofed Microsoft 365 OAuth login pages for credential capture.
Brands impersonated
Member posts on Reddit (3)
- Possible Microsoft 365 account compromise / sophisticated phishing email
A highly convincing phishing email arrived from a known professional contact's compromised Microsoft 365 account, embedding a real historical email chain alongside a malicious eDoc link.
reddit · 11 Aug 2026 · phishing
- [UK] [microsoft-noreply@microsoft.com] Did i seriously just get scammed?
UK victim receives a convincing Microsoft phishing email, logs in via biometric, then changes password using a link provided in the phishing email.
reddit · 11 Aug 2026 · phishing
- Encrypted pdf scam, clicked link
A victim clicked a link in a fake encrypted PDF from their hacked lawyer's email and entered Microsoft login credentials on a spoofed login page.
reddit · 9 July 2026 · phishing