untrappable

Microsoft email scam: is that account alert real?

Editorially reviewed · Last updated July 21, 2026

Yes — this is a scam. Microsoft never sends account alerts from "micros0ft-security.info".

Unusual sign-in activity — your account will be locked in 24 hours
M
Microsoft account team
no-reply@micros0ft-security.info
8:02 AM
We detected a sign-in from an unrecognized device in another country. To keep your account active, verify your identity now or it will be permanently suspended: micros0ft-verify.info/secure-login
Verify my account
The Email, as received

Other versions you might get: A fake "your password expires today," an Office 365 storage-full warning, or a "your subscription failed — update payment" notice.

Word-for-word versions going around

Each of these is a real email, quoted exactly as people received it. If yours matches one — even loosely — it’s the same scam.

  • Subject: Microsoft account unusual sign-in activity — Unusual sign-in activity We detected something unusual about a recent sign-in to the Microsoft account Sign-in details Country/region: Russia/Moscow IP address: Date: Sat, 26 Feb 2022 02:31:23 +0100 Platform: Kali Linux Browser: Firefox A user from Russia/Moscow just logged into your account from a new device, If this wasn't you, please report the user. If this was you, we'll trust similar activity in the future. Report the user Thanks, The Microsoft account team
    Documented by ThreatDown (Malwarebytes) · March 2022
  • Subject: Verify your account, please! — Your Microsoft account has been added to the list of accounts that are scheduled to be deactivated because the account holder in question has transferred, retired, or graduated. However, the data indicates that you are still in service, so please confirm this request; if not, we will have grounds to deactivate your university account. To prevent deactivation, Check Here Please verify your account right away.
    Documented by Miami University IT Services · June 2025

What to do right now

  1. Don't click the link or button, and don't enter your password anywhere it sends you.
  2. Check your real account — type microsoft.com yourself or open the app. Any genuine alert will be there.
  3. Report it. In Outlook, use the Report > Report phishing button, or forward it to phish@office365.microsoft.com, then file at reportfraud.ftc.gov.
  4. Delete it and mark it as phishing.
  5. If you already entered your password, change it now at microsoft.com, sign out of all devices, and turn on two-step verification.

How to make sure it never bites you

Phishing reaches you because your email address sits on breached lists, so these alerts keep coming. If you typed your password into the fake page, change it and any account that shares it, then turn on two-step verification. Reduce the blast radius — see how to lock down your accounts.

Untrappable · Public service advisory

Stop the next one at the source

You got this because your details are on lists that get bought, sold, and leaked. You can't unspill that, but you can make it useless to a scammer. Start with the free steps — they do most of the work.

Optional — if you'd rather it was handled for you

If you'd rather have it watched for you, an identity-protection service monitors your accounts, SSN, and the dark web, warns you the moment something new appears, and helps you recover if someone gets through.

See identity protection

Affiliate link — we may earn a commission at no extra cost to you. It never changes our verdicts. Why we can still be trusted.

Keep this · forward it to someone who needs it

Frequently asked

Is the “Microsoft account team” email a scam?
The display name proves nothing — scammers spoof “Microsoft account team” all the time. Check the sender's full domain, not the name. Microsoft says a genuine account email comes from @accountprotection.microsoft.com; anything from another domain (like microsoft-support@outlook.com or a look-alike such as micros0ft-security.info) is phishing. And never trust a link inside the email to “verify” — open your account by typing microsoft.com yourself.
Is the Microsoft Defender / Microsoft 365 renewal email a scam?
If it's an unexpected “your subscription auto-renewed” or “Defender protection expires today” email with an invoice and a phone number to call, treat it as a scam. It's the fake-renewal play: the number connects to a “refund” agent who talks you into remote access to your computer or “confirming” your bank details. Check your real subscription at account.microsoft.com — never call the number in the email.
How do I report a fake Microsoft email?
In Outlook, use Report > Report phishing. From any other email app, send the message as an attachment to phish@office365.microsoft.com — Microsoft needs the original headers, so forwarding the text alone doesn't help. You can also report unsolicited “Microsoft” contact at reportfraud.microsoft.com and file it at reportfraud.ftc.gov.
I clicked the link but didn't type my password — am I still at risk?
You're in much better shape than someone who typed something in, but don't just move on. The FTC's instruction for exactly this case: if you think you clicked a link or opened an attachment that downloaded harmful software, update your computer's security software, then run a scan and remove anything it flags. Do the same on a phone by installing any pending system update. Then open microsoft.com yourself, check recent sign-in activity, and turn on two-step verification so a stolen password alone can't get in. If you did enter something — a password, a card number, your Social Security number — treat it as gone: change that password everywhere you reused it, and start at IdentityTheft.gov for a step-by-step recovery plan.

Sources

A public service

Help protect someone else

Scams spread because people stay quiet about them. If this could have fooled you, it can fool someone you know — a parent, a friend, the family group chat. Passing it on is the easiest good thing you'll do today. It's safe to forward, and stands on its own as a record for a bank or the police.