Security

Security bug allows anyone to spoof Microsoft employee emails

Comment

A photo of the icon for the Microsoft email app Outlook.
Image Credits: Jaap Arriens/NurPhoto / Getty Images

A researcher has found a bug that allows anyone to impersonate Microsoft corporate email accounts, making phishing attempts look credible and more likely to trick their targets. 

As of this writing, the bug has not been patched. To demonstrate the bug, the researcher sent an email to TechCrunch that looked like it was sent from Microsoft’s account security team.

Last week, Vsevolod Kokorin, also known online as Slonser, wrote on X (formerly Twitter) that he found the email-spoofing bug and reported it to Microsoft, but the company dismissed his report after saying it couldn’t reproduce his findings. This prompted Kokorin to publicize the bug on X, without providing technical details that would help others exploit it. 

“Microsoft just said they couldn’t reproduce it without providing any details,” Koroin told TechCrunch in an online chat. “Microsoft might have noticed my tweet because a few hours ago they reopen [sic] one of my reports that I had submitted several months ago.”

The bug, according to Kokorin, only works when sending the email to Outlook accounts. Still, that is a pool of at least 400 million users all over the world, according to Microsoft’s latest earnings report

Kokorin said he last followed up with Microsoft on June 15. Microsoft did not respond to TechCrunch’srequest for comment on Tuesday. 

TechCrunch is not divulging technical details of the bug in order to prevent malicious hackers from exploiting it.

“I did not expect my post to get such a reaction. Honestly, I just wanted to share my frustration because this situation made me sad,” Kokorin said. “Many people misunderstood me and think that I want money or something like that. In reality, I just want companies not to ignore researchers and to be more friendly when you try to help them.”

It’s not known if anyone other than Kokorin found the bug, or if it has been maliciously exploited.

While the threat of this bug, at this point, is unknown, Microsoft has experienced several security problems in recent years, prompting investigations by both federal regulators and congressional lawmakers

Last week, Microsoft president Brad Smith testified in a House hearing after China stole a tranche of U.S. federal government emails from Microsoft’s servers in 2023. In the hearing, Smith pledged a renewed effort to prioritize cybersecurity in the company after a slew of security embarrassments. 

Months earlier in January, Microsoft confirmed that a Russian-government linked hacking group had broken into Microsoft corporate emails accounts to steal information about what the company’s top executives knew about the hackers themselves. And last week, ProPublica revealed that Microsoft had failed to heed warnings about a critical flaw that was later exploited in the Russian-backed cyber espionage campaign that targeted tech company SolarWinds.

More TechCrunch

A researcher has found a bug that allows anyone to impersonate Microsoft corporate email accounts, making phishing attempts look credible and more likely to trick their targets.  As of this…

Security bug allows anyone to spoof Microsoft employee emails
Image Credits: Jaap Arriens/NurPhoto / Getty Images

Welcome to TechCrunch Fintech! This week, we’re looking at layoffs at BaaS startup Unit and car insurance company Loop, as well as Brex’s decision to abandon its co-CEO model, Apple…

Unit and Loop lay off staff and Brex ditches co-CEO model

We all know the feeling when we send a funny TikTok video, anticipating a response from a friend, only to receive a basic laughing emoji or, worse, no reaction at…

Meet Seen, a new app for friends to record reactions to TikToks and other content

Butterflies wants to let users create AI personas that then take on their own lives and coexist with others. 

Former Snap engineer launches Butterflies, a social network where AIs and humans coexist

Genspark taps generative AI to write custom summaries in response to search queries.

Genspark is the latest attempt at an AI-powered search engine

Apple is continuing its AI push, this time with its education offering. The company announced on Tuesday that it will train all Apple Developer Academy students and mentors on the…

Apple Developer Academy adds AI training for students and alumni

TechCrunch has learned that the arrested hacker is the alleged leader of the group that masterminded the Twilio hacks in 2022.

UK national accused of hacking dozens of US companies arrested in Spain

Decagon is a generative AI platform that automates various aspects of customer support channels.

Decagon claims its customers service bots are smarter than average

Pok Pok’s growth caught investors’ attention, leading to a $6 million Series A.

Now a Series A startup, kids app and ‘digital toy’ Pok Pok is coming to Android

Series A to B startups — check out the ScaleUp Startups Exhibitor Program at TechCrunch Disrupt 2024! Why Join the ScaleUp Startups Exhibitor Program? Amplify Your ReachShowcase your groundbreaking innovation…

Series A to B startups scale up at Disrupt 2024

SurrealDB, a startup developing a database architecture of the same name, has closed a new round of funding as it readies a managed service.

SurrealDB is helping developers consolidate their databases

The $200 Beam pro looks like an Android phone, but instead it’s a mobile device designed specifically for Xreal’s glasses.

XReal introduces a $200 device that brings Android apps to its AR glasses

Being a solo GP hasn’t slowed Bilimoria a bit. He went on to raise three additional funds and has now closed a new fund to invest in biotech, climate and…

Zal Bilimoria just raised a $50M fourth Refactor Capital fund, and still relishes his solo GP status

Golf has exploded in popularity in recent years thanks to the pandemic and the popularity of Netflix’s Full Swing documentary series. More than 531 million rounds of golf were played…

Loop Golf looks to take the stress out of booking a tee time

Self-driving vehicles rely on many sensors to detect objects and the world around them. The conventional approach is to work with cameras and lidars. But some tech companies and startups…

Bitsensing raises $25M for its high-resolution radar in autonomous driving

Balto Energy hopes to speed the electrification by helping homeowners choose and finance the projects that make the most sense for them.

Dandelion co-founder is back to help you electrify your home for less

SewerAI sells cloud-based, AI-powered subscription products designed to streamline field inspections and data management of sewer infrastructure.

SewerAI uses AI to spot defects in sewer pipes

For the last two decades, Raquel Urtasun, founder and CEO of autonomous trucking startup Waabi, has been developing AI systems that can reason as a human would.  The AI pioneer…

Waabi’s genAI promises to do so much more than power self-driving trucks

Fisker Group Inc., the EV startup founded by famed designer Henrik Fisker, filed for Chapter 11 bankruptcy protection —  a capstone to months of problems with its Ocean SUV that…

EV startup Fisker files for bankruptcy

Meta said today that it finally launched its much-awaited API for Threads so developers can build experiences around it.

Threads finally launches its API for developers

The company says its platform functions like a search engine for materials, enabling the fast evaluation of a “vast number of novel structures.”

CuspAI raises $30M to create a GenAI-driven search engine for new materials

Suse on Tuesday is announcing its AI strategy and SUSE AI solutions, a new vendor- and LLM-agnostic generative AI platform.

SUSE wants a piece of the AI cake, too

Google has released its dedicated AI mobile app Gemini in India — over four months after its debut in the U.S. — with support for nine Indian languages alongside English. The…

Google brings Gemini mobile app to India with support for 9 Indian languages

Finbourne, founded out of London’s financial center, has built a platform to help financial companies organize and use more of their data in AI and other models.

Finbourne taps $70M for tech that turns financial data dust into AI gold 

Featured Article

Can quick commerce leapfrog e-commerce in India?

Even as quick commerce startups are retreating, consolidating or shutting down in many parts of the world, the model is showing encouraging signs in India. Consumers in urban cities are embracing the convenience of having groceries delivered to their doorstep in just 10 minutes. The companies making those deliveries —…

20 hours ago
Can quick commerce leapfrog e-commerce in India?

Hello and welcome back to TechCrunch Space. We’ll have to wait a little longer for the return of Boeing’s Starliner capsule from the International Space Station — the capsule and…

TechCrunch Space: A new era for human spaceflight research

Loop, the car insurance company co-founded by Harlem Capital co-founder John Henry, has laid off staff as the company struggles with fundraising.  Henry took to Instagram to post the email…

After 20 months of trying to raise funds, insurance startup Loop cuts staff

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm since its launch in November 2022. What started as a tool to hyper-charge productivity through writing essays and code…

ChatGPT: Everything you need to know about the AI-powered chatbot

Apple announced at last week’s WWDC 2024 that users would be able to access loans through third-party app Affirm through Apple Pay.

Apple kills Pay Later feature ahead of Affirm integration

Astroscale’s space junk observation satellite has moved within striking distance to a discarded rocket upper stage that’s been floating around Earth for nearly 20 years, taking close-up pictures — preliminary…

Astroscale’s space junk inspection satellite snaps a close-up photo of a discarded rocket stage