GlobalGuard's threat detection network has intercepted a new phishing campaign impersonating Microsoft 365, using a fabricated subscription suspension notice to pressure recipients into handing over their card details on a fake payment page.
What the Scam Looks Like
The email carries the subject line "Microsoft 365 Account Suspension Notice - Action Required!" and is built to create urgency from the first line. It claims the recipient's Microsoft 365 subscription has expired, that "all premium cloud services are now suspended," and that OneDrive, SharePoint, Exchange Online, Microsoft Teams, Office apps, and Power BI are all affected. A bright warning banner tells the reader their business data is at "immediate risk of permanent loss," with permanent deletion threatened within three days unless the subscription is "renewed".

Example phishing content shown using Microsoft branding. Not affiliated with Microsoft.
A moving target: rotating sender addresses
Unlike scams that rely on a single spoofed sender, this campaign is being sent from a rotating pool of addresses on the domain phoneryt.co[.]za, all styled to look like an official Microsoft or Office 365 billing notice. We've observed variants including:
Important Notice \www(dot)micro-billing-update-com-au(at)phoneryt(dot)co(dot)za\
-
Last Notice \australia-live-office-update(at)phoneryt(dot)co(dot)za\
-
Last Reminder \au-ms-office-live365(at)phoneryt(dot)co(dot)za
-
Last Reminder \office-micro365-au-nz-update(at)phoneryt(dot)co(dot)za\
-
Last Reminder \<www-office365-live-update-bill-au(at)phoneryt(dot)co(dot)za\>
The sending and display addresses are identical in every case, and none of them belong to Microsoft. The pattern of "micro365," "office365," and "au-nz" strings woven into each address is designed to look plausible at a glance, particularly to a recipient scanning their inbox quickly, without holding up to any real scrutiny.
The Redirect Chain
Clicking through doesn't take the recipient straight to the phishing page. The link first passes through a compromised, legitimate webhost before redirecting to a newly registered phishing domain, teambill-micro(dot)online. Using a compromised legitimate site as an intermediate hop is a deliberate technique: it can help the malicious link slip past security tools that check a link's reputation only at the point it's clicked, since the first destination briefly appears legitimate.
Inside the Fake Payment Page
The landing page mimics a Microsoft 365 billing and payment methods screen, complete with a subscription summary showing a small, plausible monthly charge. It asks the visitor to enter their email address, full card number, expiry date, CVV, name on card, and billing address, everything needed to make an unauthorised charge or resell the details on.

Example phishing content shown using Microsoft branding. Not affiliated with Microsoft.
Submitting the form leads to a "processing" screen showing a fake progress sequence, "secure connection established," "processing payment information," and "finalizing transaction", designed to hold the victim's attention and discourage them from closing the tab while their details are captured in the background.

Example phishing content shown using Microsoft branding. Not affiliated with Microsoft.
Why this Scam is Worth Taking Seriously
A few details make this campaign more convincing than average:
-
The urgency is business-critical, not personal. Threatening the loss of Teams, SharePoint, Exchange, and Office apps targets the tools a business runs on, which raises the pressure on whoever receives it, often someone in finance or admin, to act fast.
-
The compromised-site redirect adds a layer of legitimacy that a single suspicious link wouldn't have.
-
The fake payment flow is detailed and specific, down to a plausible subscription price and a fabricated invoice number, rather than a generic "enter your details" form.
Stay Safe, Know the Signs
GlobalGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses.
Reach out to speak to a GlobalGuard expert about securing your inboxes against advanced, malicious email-borne threats with our AI-powered email security solutions.

COMMENTS