A cybersecurity analyst examines a monitor showing a login flow and warning icons signaling phishing threats.
An email can link to a real Microsoft address and still send you to a criminal's website. Kaspersky says that is what more than 31,000 recent scam emails did, and it named two ways attackers are using Microsoft Entra to make their phishing look official.

Kaspersky published the findings on October 8, 2026. Nigeria Communications Week and Business Recorder reported them the next day. The attackers send emails that contain legitimate Microsoft service links to redirect users to fraudulent sites or to download malware. From August 1 to September 18, more than 31,000 emails with such links were blocked by Kaspersky solutions. Business Recorder wrote the story as a local warning. It said the firm warned Pakistani companies to beware of scam email campaigns involving attackers who send emails through Microsoft service links.

The 31,000 figure needs some context. It counts emails that Kaspersky's products blocked over about seven weeks. It is not a count of victims, successful compromises or every message the attackers sent. Kaspersky did not give a geographic breakdown, so the campaign should not be read as limited to Pakistan or Nigeria. No Microsoft statement or independent check of the number was available.

A cybersecurity analyst examines a monitor showing a login flow and warning icons signaling phishing threats. The lure: credential updates and documents to sign​

The emails used familiar bait. Attackers sent victims emails disguised as an official Microsoft communication, urging them to follow the link to keep their credentials for the service updated or to sign electronic documents.

Kaspersky says this builds on earlier research. Earlier this year Kaspersky reported detecting a phishing campaign where attackers abused Microsoft's authentication mechanism. The new emails use different bait to get people to click. The 31,000 count covers only the August–September activity.

Summary: The lures are routine phishing, but the links point to real Microsoft infrastructure. That makes the usual "check the link" advice much less reliable.

Technique one: a malicious redirect URI​

The first method uses ordinary app registration in Microsoft Entra. Kaspersky describes these steps:

  1. The attackers first create a Microsoft account and log into the Microsoft Entra admin center.
  2. In the application‑registration section the fraudsters create a new application.
  3. When registering the application, the service allows specifying a redirect URI (Uniform Resource Identifier) – the address to which the Microsoft Entra authentication server sends the user after successful authorization. In this field, the attackers add a link to their malicious site.
  4. Then the fraudsters send messages with Microsoft redirect links, containing Application ID of the registered app and the specified redirect URI.

The result: by clicking on the link users get to a resource aimed at stealing personal data or downloading malicious software.

Microsoft's own developer documentation helps explain why this works. Microsoft defines a redirect URI as the place where the Entra authentication server sends a user after authorization. It also says the login servers will only redirect to URIs added to the app registration. That rule protects legitimate apps from having users sent somewhere else. It does not help when the attacker owns the registration and chose the destination.

Kaspersky does not call this a Microsoft vulnerability, and nothing in the reporting shows a software flaw. The attackers are using a standard identity feature exactly as designed, just for a malicious purpose.

This kind of abuse has been reported before. Earlier in 2026, The Register reported that Microsoft has warned organizations about ongoing OAuth abuse scams that use phishing emails and URL redirects to infect victims' machines with malware and take over their devices. According to that report, criminals can abuse the feature by creating URLs with Microsoft Entra ID, Google Workspace, or another identity provider that redirect users to attacker-controlled landing pages where they unknowingly download malware. That earlier warning concerned separate activity and does not confirm Kaspersky's numbers. It does show that both Microsoft and Kaspersky have now flagged redirect abuse through identity providers.

Summary: No exploit is needed. The attacker registers an app, enters their own site as the redirect URI, and sends a Microsoft-hosted link that leads there.

Technique two: scam text inside real Microsoft notifications​

The second method gets the attackers' text into emails that Microsoft itself sends. Using the Microsoft Entra admin center, attackers also discovered a way to embed their malicious content into the service's legitimate notifications. Most likely, they have to purchase the cheapest license or start a trial period.

The steps Kaspersky describes:

  • Write the lure into the tenant name. Spammers put a fake message in the name field on the Overview page, then create bogus users in the Users section with made up email addresses, display names and passwords.
  • Make the victim a recovery contact. Then attackers log into the Microsoft My Account portal with the new credentials of the created bogus user and enter the victim's real email address as a backup mailbox (used for password reset messages).
  • Microsoft sends the message. As a result, the victim receives an unsolicited verification code and scammers' fraudulent message appears in the email's subject and signature.

This works because the email really does come from Microsoft. Sender checks pass, and the verification code is real. Only the text the attackers wrote into the tenant name is fake. Kaspersky does not suggest that Microsoft wrote or approved that text.

Summary: If you get an unexpected Microsoft verification code with odd wording in the subject line or signature, treat the wording as a possible lure.

What Kaspersky says, and how to read it​

Andrey Kovtun, Email Threats Protection Group Manager at Kaspersky, said in the company's statement that sending fraud through official services "adds a dangerous layer of credibility, making the scam harder to spot." He added that traditional phishing cues don't apply well in these cases.

He is right about the problem. Readers should also know that Kaspersky's release ends by recommending Kaspersky's own mail-server and consumer products. Kaspersky sells email security, so its findings come with a recommendation to buy email security. That doesn't make the technical findings wrong, and the mechanics match Microsoft's own description of how redirect URIs work. But you don't need any one vendor's product to defend against this. The steps below apply whatever email filtering you use.

A practical checklist for admins and users​

These recommendations combine Microsoft's published guidance on redirect URIs with general phishing defence practice. They are not a detection procedure specific to this campaign.

For end users and helpdesk staff:

  • Look at where you end up and what you're asked for, not just the sender. A link starting with a Microsoft sign-in address shows where the trip begins, not where it ends. If a "Microsoft" page asks you to download a file or sign a document after a redirect, stop.
  • Navigate to the service yourself. For credential updates or document-signing requests, type the service address or use a bookmark instead of clicking the link.
  • Be suspicious of verification codes you didn't request. A code you didn't ask for, especially with unusual text in the subject or signature, matches the second technique Kaspersky describes. Don't act on the text, and report the message.

For Entra and Microsoft 365 administrators:

  • Look after your own app registrations. Microsoft's guidance is to keep redirect URI lists as short as possible, separate development and production registrations, and avoid wildcard redirect URIs. Wildcards are allowed only for work-or-school-only apps, and Microsoft strongly advises against them. This won't stop attackers using their own tenants, but it keeps your tenant from adding to the problem.
  • Use the Report button and review what users submit. Microsoft 365's built-in phishing reporting gives your security team early signals from users. Microsoft says the related report needs audit logging, which is on by default.
  • Update awareness training. Many training decks still say "hover over the link and check the domain." This campaign is built to pass that check, so the training needs to cover it.

Summary: No patch is coming, because there is no bug to fix. What helps is changed user habits, sensible app-registration practice and email filtering that inspects where redirects lead.

The bigger picture​

Phishing is moving from fake sender addresses to real services. Researchers have described this repeatedly over the past year, and Kaspersky now adds two Microsoft Entra methods to the list. When attackers can open a tenant with a trial or cheap license and use Microsoft's own systems to send or relay their lures, signals like "real domain" or "passed authentication" stop telling users much.

Some questions remain open. Kaspersky's figures don't say how many of the 31,000 emails used each technique, how many would have reached inboxes without filtering, or whether the activity continued after September 18. Microsoft has not commented on this campaign. It is fair to ask whether Microsoft could make abuse harder, for example through stricter checks on tenant names or rate limits on adding backup email addresses, without breaking legitimate use. Nothing public says whether such changes are planned.

Until then, the practical lesson is that a real Microsoft link only shows where a click starts. Users should judge an email by where the link finally leads and what the page asks them to do.

 

References

  1. Firm Detected over 31,000 Scam Emails Abusing Microsoft Authentication System in Seven Weeks - Nigeria Communications Week Nigeria Communications Week 2026-10-09T23:00:00+00:00
  2. Redirect URI (reply URL) best practices and limitations - Microsoft identity platform | Microsoft Learn learn.microsoft.com
  3. Kaspersky detected over 31,000 scam emails abusing Microsoft authentication system in seven weeks me-en.kaspersky.com