Microsoft Help Desk Phishing Attempt

Roger Grimes | Nov 6, 2025

blog.knowbe4.comhubfsSocial Image RepositoryEvangelist Blog Social GraphicsEvangelists-Roger GrimesI received this email the other day to my personal email account. It is a “Security Alert” from “Microsoft Helpdesk.” Oh, my!

Not only is Microsoft holding five emails headed to me, but my “subscription” is expiring on the same day.

KnowBe4 Blog - Microsoft Helpdesk Phish (1)

The “Unsubscribe” link was just a graphic, no URL. The URL to the main button, “Review All Held Messages results” was linked to the following path (shown below):

KnowBe4 Blog - Microsoft Helpdesk Phish (2)
That is clearly not Microsoft or microsoft.com. I clicked on it. It took me to:
KnowBe4 Blog - Microsoft Helpdesk Phish (3)I immediately got what looked like a legitimate CAPTCHA message: 

KnowBe4 Blog - Microsoft Helpdesk Phish (4)

I am not sure if it was “real” or not, but I answered it. This led to another fake “CAPTCHA” check:

KnowBe4 Blog - Microsoft Helpdesk Phish (5)

I am not sure why I am getting this second CAPTCHA check, but it was the first time a phish has asked me to prove that I was human. Some of the programming code seemed to be exploring if I was fully patched, but it was changed faster than I could get a copy of it, and I was not shown it again when I visited the website again. 

Answering the second (fake) CAPTCHA took me to this link:

KnowBe4 Blog - Microsoft Helpdesk Phish (6)

This took me to the standard fake O365 login to get my 0365 credentials:

KnowBe4 Blog - Microsoft Helpdesk Phish (7)

Ultimately, this phishing attempt was mostly to steal 0365 credentials, one of the most popular phishing scams in existence.

I decided to write about this to share what happens with a large percentage of phishing emails, but also, whatever phishing list I am on, they appear to know that my private email domain is handled by Microsoft 0365 (or it could have been a random phishing connection). 

I get so many fake 0365 login phishing emails to my personal account that I must be on some phishing list that sells or lists this particular attribute, but I am just speculating.  


Stop Advanced Phishing Attacks with KnowBe4 Defend

KnowBe4 Defend takes a new approach to email security by addressing the gaps in M365 and Secure Email Gateways (SEGs). Defend helps you respond to threats quicker, dynamically improve security and stop advanced phishing threats. It reduces admin overhead, enhances detection and engages users to build a stronger security culture.

Image UpdatedWith KnowBe4 Defend you can:

  • Reduce risk of data breaches by detecting threats missed by M365 and SEGs
  • Free up admin resources by automating email security tasks
  • Educate users with color-coded banners to turn risks into teachable moments
  • Continuously assess and dynamically adapt security detection reducing admin overhead
  • Leverage live threat intelligence to automate training and simulations

Request a Demo

PS: Don't like to click on redirected buttons? Cut and paste this link in your browser:

https://www.knowbe4.com/products/defend-demo



Subscribe to Our Blog


Gartner Magic Quadrant




Get the latest insights, trends and security news. Subscribe to CyberheistNews.