Key Takeaways
- Kaspersky experts have identified a scam email campaign targeting Pakistani companies.
- Attackers use legitimate Microsoft service links to redirect users to fraudulent sites or download malware.
- More than 31,000 such emails were blocked by Kaspersky solutions between August 1 and September 18.
A leading cybersecurity firm, Kaspersky, has issued a warning to Pakistani businesses to be vigilant against scam email campaigns. These campaigns involve attackers sending emails that contain legitimate Microsoft service links, which can redirect users to fraudulent websites or download malware.
According to Kaspersky, from August 1 to September 18, more than 31,000 emails with such links were blocked by their solutions. This highlights the scale and frequency of the threat.
Kaspersky experts have noted that these attackers are exploiting Microsoft’s authentication mechanism by sending emails that appear to be official Microsoft communications. The emails urge recipients to follow the link to update their credentials or sign electronic documents.
The attackers create fake messages in the name field on the Overview page and then create bogus users in the Users section with made-up email addresses, display names, and passwords. They then log into the Microsoft My Account portal using these new credentials and enter the victim’s real email address as a backup mailbox.
This method allows attackers to gain unauthorized access to the victim’s account and potentially steal sensitive information.
To protect against such threats, organizations are advised to use robust email security solutions. Kaspersky recommends that businesses remain cautious and verify the legitimacy of any unexpected emails, especially those containing links.
The company also suggests that businesses should regularly update their security measures and educate their employees about phishing tactics to prevent falling victim to these scams.
Kaspersky’s warning underscores the importance of staying informed about the latest cybersecurity threats and taking proactive steps to safeguard business operations and sensitive data.





