Attackers stood up a real Azure subscription and Azure Monitor alert rule to make Microsoft's own mail servers send a fully SPF/DKIM/DMARC-authenticated fake $459.90 Windows Defender billing notice with fraud callback numbers, which a human SOC reviewer cleared as a false positive.
Reviewed by the Social Engineering Examples team.
In a threat-intelligence report published March 21, 2026, email security vendor IRONSCALES documented a callback-phishing (TOAD, Telephone-Oriented Attack Delivery) campaign in which attackers abused legitimate Microsoft Azure infrastructure rather than spoofing it. The attacker created a real Azure subscription, provisioned a resource group named "pay-cbb33c4ab1," and configured an Azure Monitor metric alert rule ("Payment Completion Notice-cbb33c4ab1") so that when it fired, Microsoft's own notification system sent a genuine, fully authenticated email from azure-noreply@microsoft.com (per IRONSCALES' IOC table, sender IP 40.93.194.96). The attacker injected a fraudulent "Windows Defender" billing notice for $459.90 into the standard Azure alert template, instructing the recipient to call one of two attacker-controlled numbers to dispute the charge. Because the message truly originated from Microsoft's mail servers, it passed SPF, DKIM, and DMARC, and the links in the email pointed to Microsoft's legitimate portal.azure.com domain, so it registered as clean to authentication- and URL-based defenses. At the targeted organization (described by IRONSCALES as a global IoT technology company), a human security reviewer examined the message and marked it a false positive, which IRONSCALES frames as the intended outcome: the campaign was built to defeat both automated scanning and human triage. IRONSCALES separately reported a related sample of the same technique (a fake "Your Payment Has Been Received" alert citing the same $459.90 amount, transaction ID PP456-887A-22B) sent to a mid-size U.S. professional services firm, where its own Adaptive AI behavioral detection quarantined the affected mailboxes (4 total) before any recipient engaged; that companion article separately documents sender IP 40.93.14.106 and a relay chain through outbound.protection.outlook.com, details specific to that case. BleepingComputer independently reported a related, distinct in-the-wild variant of the technique (dated 03/05/2026) that mixed elements of both IRONSCALES samples but cited a different charge ($389.90).
The attacker first stood up a legitimate Azure subscription, then created a resource group named "pay-cbb33c4ab1" and an Azure Monitor metric alert rule named "Payment Completion Notice-cbb33c4ab1," configured to fire at severity level 2. When the alert triggered, Microsoft's own Azure Monitor notification pipeline generated and sent the email itself, from azure-noreply@microsoft.com, via Microsoft's genuine outbound mail infrastructure (per IRONSCALES' IOC table for this case, sender IP 40.93.194.96, a permitted Microsoft outbound server). Because the message truly originated on Microsoft's mail servers, it passed SPF, DKIM, and DMARC with a fully valid composite result, and per IRONSCALES' reporting on this specific case, every hyperlink in the body resolved to Microsoft's legitimate portal.azure.com domain (a separate, related IRONSCALES sample additionally cited azure.microsoft.com, go.microsoft.com, and the microsofticm.com unsubscribe endpoint, but those specific domains were documented for that companion case, not this one). The attacker abused the free-text fields available in the Azure Monitor alert template to inject a fraudulent billing paragraph, styled as an official notice ("MICROSOFT CORPORATION BILLING AND ACCOUNT SECURITY NOTICE, REF: MS-FRA-6673829-KP") claiming a $459.90 charge for "Windows Defender," alongside two attacker-controlled callback numbers, +1 (812) 266-1510 and +1 (812) 266-1890, that do not appear on any legitimate Microsoft support page. Because there was no malicious URL or attachment (only genuine Microsoft links), URL reputation scanners and sandbox detonation had nothing to flag; the entire monetization step of the attack (the actual fraud) was pushed off-email into a live phone call, the defining trait of Telephone-Oriented Attack Delivery (TOAD).
The email arrived with the exact subject-line formatting Azure Monitor uses for real action-group alerts ("Azure: Activated Severity: 2 Payment Completion Notice-cbb33c4ab1"), making it visually and structurally indistinguishable from routine cloud-ops noise employees are trained to trust or ignore. Embedded inside that legitimate template was an out-of-place billing/security notice block, complete with a fabricated reference number, a specific dollar charge ($459.90) for "Windows Defender," and urgent instructions to call a phone number "to dispute" the charge. The telltale sign, visible only to a suspicious reviewer, was the mismatch between an infrastructure-monitoring alert and a billing dispute demand, plus callback numbers absent from any official Microsoft support page; everything else (sender domain and authentication) was genuinely Microsoft's.
IRONSCALES' primary case: the email was reviewed by a human security analyst at the target organization and marked a false positive, illustrating that the attack was engineered specifically to survive human triage as much as automated scanning. IRONSCALES does not disclose whether the targeted employee ultimately called the fraudulent number or suffered any loss. In a related, same-technique campaign IRONSCALES also reported (different subject line, "Your Payment Has Been Received," transaction ID PP456-887A-22B, also citing a $459.90 charge, targeting a mid-size U.S. professional services firm), the vendor's Adaptive AI behavioral detection quarantined affected mailboxes (4 total) before any recipient engaged. Separately, BleepingComputer independently documented an in-the-wild variant of the same technique (dated 03/05/2026, citing a $389.90 charge) that was neither of IRONSCALES' two reported samples. No law-enforcement action, monetary loss figure, or named threat actor has been publicly attached to any of these cases.
This case is a clear illustration of "authenticated-infrastructure abuse": SPF/DKIM/DMARC and clean-URL checks, the standard technical gatekeepers most organizations rely on, are structurally incapable of catching an attack where the delivery platform itself is genuinely trustworthy and the payload lives entirely in text plus a phone call. It also shows TOAD's dual-path resilience: a recipient who calls the number can be defrauded, while a reviewer who clears the alert as a false positive removes the one remaining chance of detection, so the campaign succeeds either way. For defenders, it underscores that email authentication is a necessary but no longer sufficient signal, and that SOC analysts need training and tooling that flag content/context anomalies (a billing dispute demand inside an infrastructure-monitoring alert) rather than relying on sender-domain trust. It also underscores a documentation hazard for analysts consuming vendor threat-intel: near-duplicate companion write-ups from the same source can have distinct technical indicators (IPs, relay chains, domain lists) that must not be merged across cases.
IRONSCALES' writeup recommends moving past authentication-only and URL/attachment-scanning verdicts (SPF/DKIM/DMARC pass and "no malicious link" are necessary but insufficient signals) toward behavioral/content-anomaly detection that flags injected billing text inside a legitimate service template, plus community threat-intel sharing. For end users and reviewers: never call a number embedded in an unsolicited billing alert (even from a verified sender domain); look the vendor's support number up independently; treat "urgent charge, call to dispute" language as a red flag regardless of authentication status; and train SOC reviewers not to auto-clear tickets solely because headers pass, since this campaign was explicitly designed to read as a false positive.
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an…