Microsoft Dynamics Customer Voice Phishing Scam

Microsoft Dynamics Customer Voice Phishing Scam

In the interest of collective security, we are letting you know about an email scam we have seen in the wild recently.

It’s a phishing attempt where the email contains a link that appears legitimate (using the microsoft.com domain), however it abuses a Microsoft service to redirect users to a page where credentials can be stolen. See https://blog.checkpoint.com/research/microsoft-dynamics-365-customer-voice-phishing-scam/ for more information.

Currently, you can control link rendering behaviour through:

  • Profile > Project Mapping > Format > Rich Formatting > Link

We have added a backlog feature JEMHC-5572 for more fine grained allow/blocking of link rendering based on link domain and/or sender domain.