untrappable.Check

Microsoft email scam: is that account alert real?

Yes — this is a scam. Microsoft never sends account alerts from “micros0ft-security[.]info”.

Exhibit · Email

Unusual sign-in activity — your account will be locked in 24 hours
M
Microsoft account team
no-reply@micros0ft-security[.]info
8:02 AM
We detected a sign-in from an unrecognized device in another country. To keep your account active, verify your identity now or it will be permanently suspended: micros0ft-verify[.]info/secure-login
Verify my account

Other versions you might get: A fake “your password expires today,” an Office 365 storage-full warning, or a “your subscription failed — update payment” notice.

Reported versions of this message

Each source below documented a email. Web addresses are defanged, and identifying values may be redacted; the remaining wording follows the source. Similar wording is a reason to check independently, not proof that two messages came from the same sender.

  • “Subject: Microsoft account unusual sign-in activity — Unusual sign-in activity We detected something unusual about a recent sign-in to the Microsoft account Sign-in details Country/region: Russia/Moscow IP address: Date: Sat, 26 Feb 2022 02:31:23 +0100 Platform: Kali Linux Browser: Firefox A user from Russia/Moscow just logged into your account from a new device, If this wasn't you, please report the user. If this was you, we'll trust similar activity in the future. Report the user Thanks, The Microsoft account team”
  • “Subject: Verify your account, please! — Your Microsoft account has been added to the list of accounts that are scheduled to be deactivated because the account holder in question has transferred, retired, or graduated. However, the data indicates that you are still in service, so please confirm this request; if not, we will have grounds to deactivate your university account. To prevent deactivation, Check Here Please verify your account right away.”

What to do right now

  1. Don't click the link or button, and don't enter your password anywhere it sends you.
  2. Check your real account — type microsoft.com yourself or open the app. Any genuine alert will be there.
  3. Report it. In Outlook, use the Report > Report phishing button, or forward it to phish@office365.microsoft.com, then file at reportfraud.ftc.gov.
  4. Delete it and mark it as phishing.
  5. If you already entered your password, change it now at microsoft.com, sign out of all devices, and turn on two-step verification.

Reduce the risk of another scam

Do not use the message’s link to check the claim. Open the real service yourself. If you paid or shared account details, start with what to do after a scam. Blocking and reporting can reduce unwanted contact, but they cannot stop every attempt or tell you how the sender found you.

● Public service · free steps first

Take the free protection steps first

A suspicious message does not tell us how someone found your details. If you shared personal information, start with the official recovery guidance. You can also freeze your credit for free.

Decide what protection you need

Start with the free controls above. Compare what a paid service would add only after deciding which problem remains.

Frequently asked

Is the “Microsoft account team” email a scam?
Microsoft identifies @accountprotection.microsoft.com for its account-team notices, but that is not a universal list for all Microsoft products and messages. Sender addresses can also be spoofed. Open the relevant Microsoft account independently and ask official support about anything unclear.
Is the Microsoft Defender / Microsoft 365 renewal email a scam?
An unexpected renewal notice with a callback number can be a refund-scam pattern, but a number or invoice alone is not proof. Check subscriptions and payment records independently, and do not grant remote access or send a separate refund to an unverified agent.
How do I report a fake Microsoft email?
In Outlook, use Report > Report phishing. From any other email app, send the message as an attachment to phish@office365.microsoft.com — Microsoft needs the original headers, so forwarding the text alone doesn't help. You can also report unsolicited “Microsoft” contact at reportfraud.microsoft.com and file it at reportfraud.ftc.gov.
I clicked the link but didn't type my password — am I still at risk?
You're in much better shape than someone who typed something in, but don't just move on. The FTC's instruction for exactly this case: if you think you clicked a link or opened an attachment that downloaded harmful software, update your computer's security software, then run a scan and remove anything it flags. Do the same on a phone by installing any pending system update. Then open microsoft.com yourself, check recent sign-in activity, and enable stronger authentication, which reduces risk but does not prevent every compromise. If you did enter something — a password, a card number, your Social Security number — treat it as gone: change that password everywhere you reused it, and start at IdentityTheft.gov for a step-by-step recovery plan.

Sources

  1. 01Can I trust email from the Microsoft account team?— Microsoft
  2. 02Protect yourself from phishing— Microsoft
  3. 03How To Recognize and Avoid Phishing Scams— Federal Trade Commission
  4. 04How To Recognize and Avoid Phishing Scams— consumer.ftc.gov
  5. 05What To Do if You Were Scammed— consumer.ftc.gov

Pass it on

Help protect someone else

If this could have fooled you, it can fool someone you know — a parent, a friend, the family group chat. It's safe to forward, and stands on its own as a record for a bank or the police.