Am I being scammed?

Late yesterday I found my MSOutlook (hotmail e-mail) session had been closed. There was an error message saying

You need to sign in. Your session has expired. You may need to enable pop-ups in your browser for this site. Sign in to continue.

I don’t recall ever seeing this before and since it has a Sign In button and will, of course, ask for my e-mail password again I was suspicious. So I didn’t try to sign in.

I’ve just fired up my laptop and tried to log in to the hotmail account from there and access is blocked on that machine too. They’re asking me to enter a phone number so they can SMS me a verification code which will allow me to log back in to my hotmail.

If these are Bad Guys somehow coming at me via different attempts (by me) to log in to my e-mail then I’m reluctant to give them my phone number as well. But if they really are Microsoft then maybe I have to ?

Does any of this make sense ?

I don’t think I’ve ever registered a phone number with Microsoft for account recovery. But I have registered an alternative e-mail address.

Unlikely a scam but update windows and then run a defender (or AV) scan before doing anything else

Do you see a lock icon by the URL, or a similar symbol to indicate at least that it’s a secure connection? You can also check for https vs http at the beginning of the URL. That will at least tell you if you’re on the right domain.

MS will certainly try to steer you towards having some degree of 2-Factor Authentication set up, which is generally via a phone number.

Yup, the padlock is closed and the URL starts Microsoft account

Thanks, I’ll do that.

That’s normal, my account kept getting locked out by MS due to hacking attempts so I went ballistic and switched on passwordless security and MFA etc

If you have a fingerprint scanner on your laptop you can use this as a MFA ‘passkey’

I’d recommend the MS authenticator app as it will prompt you to approve the sign in and is easy to use

2 Likes

Yeah, I find my Microsoft account constantly being bombarded with login attempts. you can see it on the account page.

Like Chris, I have moved to using the Authenticator app.

1 Like

Well the process seems to have worked. I updated the laptop and logged into hotmail, having jumped through MS’s version of Captcha and entered their SMS’d code, and now my e-mail is accessible again.

Thanks for the help and reassurance everyone.

1 Like

Me too.

I just walked face-first into something that looked completely plausible but was actually very hostile.

No harm done I think but it took a while and a bit of knowledge to kill it off.

Annoying. Getting old.

1 Like

We move our money around using systems which are fundamentally insecure. The people who built (for want of a better word) them do put some effort into rectifying their flaws. But if you wanted a secure means of establishing the bona fides of the people you’re dealing with you wouldn’t start with what we have now.

I received this today…

Addressed to me, I was fooled for a while until I actually thought about it: the rate is just too good. Then I checked the domain - created last month.

Shame, I’ve had to use a normal bank and got far less interest. Impressed that they invested a stamp though; even second class cost a fortune nowadays.

2 Likes

The systems are incredibly secure, the people using them are the ones being fooled.

Yep, best 1 year fixed deals atm are around 4.5%.

More concerning would be if you are actually a Metro bank customer and they have had a data breach, as opposed to the scammers buying a random address file that contains you.

I was, but am no longer.

I also had a fairly sophisticated one where my emails to my financial adviser were intercepted. My financial adviser ended up replying to the scammers and gave them a lot of my personal info!

You’ll need to have them killed by your security adviser.

1 Like

Have you got an identity guard app that searches the dark web and data breaches for any of your personal details?

Yeah, although I’m not sure what actions I could take: there’s some factually correct info there, and no passwords I currently use. I have 2FA and authenticators wherever I can.

It’s a minefield really. When I bought my car I got a call from “Tesla” saying that their servers were down and so I should make payment over the phone.

Quite a lot of effort has been spent on trying to scam me, and they have, fortunately, failed every time!

I was using the word ‘system’ very, very much more generally.

My mate was expecting a four-figure invoice from someone who’d done some building work for him. The invoice duly came by e-mail, attached as a PDF. The scammers had somehow intercepted this and altered details in the PDF. So he makes the payment he’s expecting to make but sends the money to the scammers’ account.

e-mail - it’s insecure (at least, insecure enough for this to happen), but it’s a part of today’s billing system.

Always do a trial token payment to a new payee :+1:

3 Likes