Case Library / Phishing / Azure Monitor Alert Abuse TOAD Scam: Fake $459.90 Windows Defender Billing Notice Cleared as a False Positive

Azure Monitor Alert Abuse TOAD Scam: Fake $459.90 Windows Defender Billing Notice Cleared as a False Positive

Attackers stood up a real Azure subscription and Azure Monitor alert rule to make Microsoft's own mail servers send a fully SPF/DKIM/DMARC-authenticated fake $459.90 Windows Defender billing notice with fraud callback numbers, which a human SOC reviewer cleared as a false positive.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In a threat-intelligence report published March 21, 2026, email security vendor IRONSCALES documented a callback-phishing (TOAD, Telephone-Oriented Attack Delivery) campaign in which attackers abused legitimate Microsoft Azure infrastructure rather than spoofing it. The attacker created a real Azure subscription, provisioned a resource group named "pay-cbb33c4ab1," and configured an Azure Monitor metric alert rule ("Payment Completion Notice-cbb33c4ab1") so that when it fired, Microsoft's own notification system sent a genuine, fully authenticated email from azure-noreply@microsoft.com (per IRONSCALES' IOC table, sender IP 40.93.194.96). The attacker injected a fraudulent "Windows Defender" billing notice for $459.90 into the standard Azure alert template, instructing the recipient to call one of two attacker-controlled numbers to dispute the charge. Because the message truly originated from Microsoft's mail servers, it passed SPF, DKIM, and DMARC, and the links in the email pointed to Microsoft's legitimate portal.azure.com domain, so it registered as clean to authentication- and URL-based defenses. At the targeted organization (described by IRONSCALES as a global IoT technology company), a human security reviewer examined the message and marked it a false positive, which IRONSCALES frames as the intended outcome: the campaign was built to defeat both automated scanning and human triage. IRONSCALES separately reported a related sample of the same technique (a fake "Your Payment Has Been Received" alert citing the same $459.90 amount, transaction ID PP456-887A-22B) sent to a mid-size U.S. professional services firm, where its own Adaptive AI behavioral detection quarantined the affected mailboxes (4 total) before any recipient engaged; that companion article separately documents sender IP 40.93.14.106 and a relay chain through outbound.protection.outlook.com, details specific to that case. BleepingComputer independently reported a related, distinct in-the-wild variant of the technique (dated 03/05/2026) that mixed elements of both IRONSCALES samples but cited a different charge ($389.90).

How the Attack Worked

The attacker first stood up a legitimate Azure subscription, then created a resource group named "pay-cbb33c4ab1" and an Azure Monitor metric alert rule named "Payment Completion Notice-cbb33c4ab1," configured to fire at severity level 2. When the alert triggered, Microsoft's own Azure Monitor notification pipeline generated and sent the email itself, from azure-noreply@microsoft.com, via Microsoft's genuine outbound mail infrastructure (per IRONSCALES' IOC table for this case, sender IP 40.93.194.96, a permitted Microsoft outbound server). Because the message truly originated on Microsoft's mail servers, it passed SPF, DKIM, and DMARC with a fully valid composite result, and per IRONSCALES' reporting on this specific case, every hyperlink in the body resolved to Microsoft's legitimate portal.azure.com domain (a separate, related IRONSCALES sample additionally cited azure.microsoft.com, go.microsoft.com, and the microsofticm.com unsubscribe endpoint, but those specific domains were documented for that companion case, not this one). The attacker abused the free-text fields available in the Azure Monitor alert template to inject a fraudulent billing paragraph, styled as an official notice ("MICROSOFT CORPORATION BILLING AND ACCOUNT SECURITY NOTICE, REF: MS-FRA-6673829-KP") claiming a $459.90 charge for "Windows Defender," alongside two attacker-controlled callback numbers, +1 (812) 266-1510 and +1 (812) 266-1890, that do not appear on any legitimate Microsoft support page. Because there was no malicious URL or attachment (only genuine Microsoft links), URL reputation scanners and sandbox detonation had nothing to flag; the entire monetization step of the attack (the actual fraud) was pushed off-email into a live phone call, the defining trait of Telephone-Oriented Attack Delivery (TOAD).

The Lure & the Tell

The email arrived with the exact subject-line formatting Azure Monitor uses for real action-group alerts ("Azure: Activated Severity: 2 Payment Completion Notice-cbb33c4ab1"), making it visually and structurally indistinguishable from routine cloud-ops noise employees are trained to trust or ignore. Embedded inside that legitimate template was an out-of-place billing/security notice block, complete with a fabricated reference number, a specific dollar charge ($459.90) for "Windows Defender," and urgent instructions to call a phone number "to dispute" the charge. The telltale sign, visible only to a suspicious reviewer, was the mismatch between an infrastructure-monitoring alert and a billing dispute demand, plus callback numbers absent from any official Microsoft support page; everything else (sender domain and authentication) was genuinely Microsoft's.

Outcome

IRONSCALES' primary case: the email was reviewed by a human security analyst at the target organization and marked a false positive, illustrating that the attack was engineered specifically to survive human triage as much as automated scanning. IRONSCALES does not disclose whether the targeted employee ultimately called the fraudulent number or suffered any loss. In a related, same-technique campaign IRONSCALES also reported (different subject line, "Your Payment Has Been Received," transaction ID PP456-887A-22B, also citing a $459.90 charge, targeting a mid-size U.S. professional services firm), the vendor's Adaptive AI behavioral detection quarantined affected mailboxes (4 total) before any recipient engaged. Separately, BleepingComputer independently documented an in-the-wild variant of the same technique (dated 03/05/2026, citing a $389.90 charge) that was neither of IRONSCALES' two reported samples. No law-enforcement action, monetary loss figure, or named threat actor has been publicly attached to any of these cases.

Why It Matters

This case is a clear illustration of "authenticated-infrastructure abuse": SPF/DKIM/DMARC and clean-URL checks, the standard technical gatekeepers most organizations rely on, are structurally incapable of catching an attack where the delivery platform itself is genuinely trustworthy and the payload lives entirely in text plus a phone call. It also shows TOAD's dual-path resilience: a recipient who calls the number can be defrauded, while a reviewer who clears the alert as a false positive removes the one remaining chance of detection, so the campaign succeeds either way. For defenders, it underscores that email authentication is a necessary but no longer sufficient signal, and that SOC analysts need training and tooling that flag content/context anomalies (a billing dispute demand inside an infrastructure-monitoring alert) rather than relying on sender-domain trust. It also underscores a documentation hazard for analysts consuming vendor threat-intel: near-duplicate companion write-ups from the same source can have distinct technical indicators (IPs, relay chains, domain lists) that must not be merged across cases.

Defenses

IRONSCALES' writeup recommends moving past authentication-only and URL/attachment-scanning verdicts (SPF/DKIM/DMARC pass and "no malicious link" are necessary but insufficient signals) toward behavioral/content-anomaly detection that flags injected billing text inside a legitimate service template, plus community threat-intel sharing. For end users and reviewers: never call a number embedded in an unsolicited billing alert (even from a verified sender domain); look the vendor's support number up independently; treat "urgent charge, call to dispute" language as a red flag regardless of authentication status; and train SOC reviewers not to auto-clear tickets solely because headers pass, since this campaign was explicitly designed to read as a false positive.

Sources
  • Someone Filed a False Positive on This Azure TOAD Scam. Here's Why That's the Whole Point.. IRONSCALES Primary. Primary vendor writeup (published 2026-03-21) documenting the $459.90 lure, the pay-cbb33c4ab1 resource group / Payment Completion Notice alert rule, full SPF/DKIM/DMARC pass, sender IP 40.93.194.96 per its own IOC table, links resolving only to portal.azure.com, and the human reviewer's false-positive determination at a global IoT technology company. This article's own MITRE citation mislabels T1566.001 as 'Spearphishing Attachment via Service.' Verified live 2026-07-29.
  • The Azure Alert That Billed You $459: When Microsoft's Own Infrastructure Delivers the Phish. IRONSCALES Primary. Companion primary IRONSCALES writeup (published 2026-03-21) on the same Azure Monitor abuse technique, describing a related sample (professional services firm, transaction ID PP456-887A-22B) that also cited a $459.90 charge and was quarantined by IRONSCALES' Adaptive AI/behavioral detection (Themis), with four affected mailboxes, before recipient engagement. Documents sender IP 40.93.14.106, the outbound.protection.outlook.com relay chain, and links to azure.microsoft.com/go.microsoft.com/microsofticm.com, details specific to this companion case, not the primary one. Correctly cites MITRE T1566.003 (Spearphishing via Service). Verified live 2026-07-29.
  • Microsoft Azure Monitor alerts abused for callback phishing attacks. BleepingComputer Secondary. Independent secondary reporting (2026-03-21) corroborating the Azure Monitor alert-abuse callback-phishing pattern; describes a distinct in-the-wild example (dated 03/05/2026) combining the primary case's reference number (MS-FRA-6673829-KP) with the companion case's transaction ID (PP456-887A-22B) but citing a $389.90 charge and different callback numbers (+1 (864) 347-2494 and +1 (864) 347-4846): a third variant, not a figure IRONSCALES reported for either of its two documented samples. Verified live 2026-07-29.
  • In-Depth Analysis: Azure Monitor Alerts Phishing Campaign and BazarCall Techniques. IPSIP Secondary. Secondary technical analysis situating the campaign within the broader BazarCall/TOAD callback-phishing technique family. Verified live 2026-07-29.
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and targeting: Not directly documented by any source, but consistent with this attack class, the operation likely began with selecting target organizations or mailing lists (per BleepingComputer, delivery ran through a mailing list the attacker controlled) and studying the genuine formatting conventions of Azure Monitor action-group alert emails (subject-line pattern, sender address, template structure) closely enough to inject convincing fraudulent text into them.
Countering Stage 1: There is little a defender can do to stop an attacker from studying publicly visible Azure Monitor alert formatting, since that structure is intentionally public and documented by Microsoft; the realistic control sits at Stage 2, where the fraudulent resource construction itself becomes detectable.
2
Attacker infrastructure setup: The attacker created a real Azure subscription and, within it, a resource group ("pay-cbb33c4ab1" in the primary case) and an Azure Monitor metric alert rule with a billing-themed name, then used the free-text description field that Azure Monitor exposes for alert rules to inject a fabricated "Windows Defender" billing dispute notice, complete with a fake reference number, dollar amount, and attacker-controlled callback numbers.
Countering Stage 2: IPSIP's writeup recommends Azure-configuration/cloud-governance monitoring, auditing changes to Action Groups and Alert Rules for keywords like "invoice," "payment," or "billing" appearing in rules created by unrecognized principals, and enforcing MFA-gated, least-privilege access to who can create or modify alert rules and their free-text fields, whether on an organization's own tenant or as a pattern Microsoft itself could monitor for at the platform level.
3
Weaponized delivery: The attacker triggered the alert rule so that Microsoft's own Azure Monitor notification pipeline generated and sent the email itself, from the genuine azure-noreply@microsoft.com address through Microsoft's outbound mail servers, producing a message with a fully passing SPF/DKIM/DMARC result because it truly originated on Microsoft's infrastructure.
Countering Stage 3: Because the message is genuinely SPF/DKIM/DMARC-authenticated and delivered through Microsoft's real mail infrastructure, standard sender-authentication controls cannot block delivery at this stage; IRONSCALES' own reporting frames this as the central lesson, that authentication verifies who sent a message, not whether its content is safe.
4
Automated-defense evasion: Because the email carried no malicious link or attachment, only genuine Microsoft domains (portal.azure.com and related) and a fraudulent paragraph of text plus a phone number, URL-reputation scanners and attachment/sandbox detonation had nothing to flag, and sender-authentication checks affirmatively vouched for the message.
Countering Stage 4: Deploy behavioral or content-anomaly detection, such as IRONSCALES' own Adaptive AI (Themis) engine, that flags the mismatch between an infrastructure-monitoring template and injected billing/payment language, first-time-sender-to-recipient anomalies, and community threat-intelligence patterns, rather than relying solely on URL- or attachment-scanning verdicts.
5
Human/SOC triage decision point: A security reviewer (in the primary case) or an automated behavioral system (in the companion case) evaluated the alert. In the primary case, seeing a genuine Microsoft sender with fully passing authentication and no flagged links, the human reviewer classified the message as a false positive rather than a phishing attempt.
Countering Stage 5: Train SOC reviewers and end users not to auto-clear a ticket as a false positive solely because authentication headers pass; give reviewers an explicit rule that a billing dispute demand with a call-to-action phone number, embedded inside an unrelated infrastructure-monitoring alert, is itself the indicator, regardless of sender legitimacy.
6
Voice-channel monetization (TOAD callback): The intended final step, for any recipient who called one of the attacker-controlled numbers, was a live phone conversation in which the attacker would attempt to extract payment-card details, account credentials, or induce installation of remote-access software under the pretext of "verifying" or "disputing" the fake charge; neither IRONSCALES case discloses whether a recipient actually completed this step.
Countering Stage 6: Treat any callback number embedded in an unsolicited billing or security alert as an unverified indicator and look up the vendor's real support number independently rather than dialing the number in the message; this end-user step is the last available control once delivery and triage have both failed to stop the message.
Quick Facts
Victim
An unnamed security reviewer/employee at a global IoT technology company (per IRONSCALES' primary case); a related same-technique sample separately targeted a mid-size U.S. professional services firm. Both organizations are vendor-anonymized in IRONSCALES' reporting and have not been independently identified or confirmed.
Location
Not publicly disclosed for the primary case (described only as "a global IoT technology company"); a related same-technique sample hit a mid-size U.S. professional services firm. Both organizational descriptions are vendor-anonymized in IRONSCALES' reporting and have not been independently identified or confirmed. Callback phone numbers used a U.S. (Indiana, area code 812) area code.
Date
2026-03-21 (IRONSCALES publication date; underlying campaign observed shortly before)
Impact
No confirmed financial loss has been publicly disclosed for either IRONSCALES case. The primary lure demanded a disputed charge of $459.90 (framed as a "Windows Defender" billing item). IRONSCALES' companion sample (professional services firm, transaction ID PP456-887A-22B) cited the identical $459.90 figure, not a different "$389.90 variant" as earlier summarized. The $389.90 figure instead belongs to a third, distinct in-the-wild example that BleepingComputer independently observed and reported: a lure combining the primary case's reference number (MS-FRA-6673829-KP) with the companion case's transaction ID (PP456-887A-22B) and a transaction date of 03/05/2026, but with different callback numbers and a $389.90 charge. That figure is BleepingComputer's own finding, not a value IRONSCALES reported for either of its two documented samples. Because the primary email was marked a false positive by a human reviewer and IRONSCALES does not report a completed callback or fraud outcome for that case, whether the targeted employee called the number or lost money is not documented in the public record. The companion sample was quarantined by IRONSCALES' AI/behavioral detection before any recipient engagement (4 mailboxes affected, no reported loss).
Status
Confirmed
Case Type
Real-World Incident
Sector
Professional & Business Services, Technology & Software
Related

Related Cases

Standard Bank Teen Loses R438,900 Education Fund in 20-Minute Vishing Scam

A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to…

Incident 2026Read →

Singapore Businessman Loses S$4.9 Million to Deepfake Zoom Call Impersonating PM Lawrence Wong

A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…

Incident 2026Read →

SCI Engineered Materials $898,325 Imposter Scam / Bank Fraud (2026)

A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an…

Incident 2026Read →