MailGuard's threat detection network has intercepted a new phishing campaign impersonating Microsoft 365, using a fabricated subscription suspension notice to pressure recipients into handing over their card details on a fake payment page.
The email carries the subject line "Microsoft 365 Account Suspension Notice - Action Required!" and is built to create urgency from the first line. It claims the recipient's Microsoft 365 subscription has expired, that "all premium cloud services are now suspended," and that OneDrive, SharePoint, Exchange Online, Microsoft Teams, Office apps, and Power BI are all affected. A bright warning banner tells the reader their business data is at "immediate risk of permanent loss," with permanent deletion threatened within three days unless the subscription is "renewed".
Unlike scams that rely on a single spoofed sender, this campaign is being sent from a rotating pool of addresses on the domain phoneryt.co[.]za, all styled to look like an official Microsoft or Office 365 billing notice. We've observed variants including:
• Important Notice \www(dot)micro-billing-update-com-au(at)phoneryt(dot)co(dot)za\
• Last Notice \australia-live-office-update(at)phoneryt(dot)co(dot)za\
• Last Reminder \au-ms-office-live365(at)phoneryt(dot)co(dot)za\
• Last Reminder \office-micro365-au-nz-update(at)phoneryt(dot)co(dot)za\
• Last Reminder \<www-office365-live-update-bill-au(at)phoneryt(dot)co(dot)za\>
The sending and display addresses are identical in every case, and none of them belong to Microsoft. The pattern of "micro365," "office365," and "au-nz" strings woven into each address is designed to look plausible at a glance, particularly to a recipient scanning their inbox quickly, without holding up to any real scrutiny.
Clicking through doesn't take the recipient straight to the phishing page. The link first passes through a compromised, legitimate webhost before redirecting to a newly registered phishing domain, teambill-micro(dot)online. Using a compromised legitimate site as an intermediate hop is a deliberate technique: it can help the malicious link slip past security tools that check a link's reputation only at the point it's clicked, since the first destination briefly appears legitimate.
The landing page mimics a Microsoft 365 billing and payment methods screen, complete with a subscription summary showing a small, plausible monthly charge. It asks the visitor to enter their email address, full card number, expiry date, CVV, name on card, and billing address, everything needed to make an unauthorised charge or resell the details on.
Example phishing content shown using Microsoft branding. Not affiliated with Microsoft.
Why this Scam is Worth Taking Seriously
A few details make this campaign more convincing than average:
The urgency is business-critical, not personal. Threatening the loss of Teams, SharePoint, Exchange, and Office apps targets the tools a business runs on, which raises the pressure on whoever receives it, often someone in finance or admin, to act fast.
The compromised-site redirect adds a layer of legitimacy that a single suspicious link wouldn't have.
Stay Safe, Know the Signs
MailGuard advises all recipients of these emails to delete them immediately without clicking on any links. Responding or providing personal details can lead to identity theft, data breaches, and financial losses.
Avoid emails that:
Many businesses turn to MailGuard after a near miss or incident. Don't wait until it's too late. Reach out to our team for a confidential discussion by emailing expert@mailguard.com.au or calling 1300 30 44 30.
All that it takes to devastate your business is a cleverly worded email message that can steal sensitive user credentials or disrupt your business operations. If scammers can trick one person in your company into clicking on a malicious link or attachment, they can gain access to your data or inflict damage on your business.
For a few dollars per staff member per month, you can protect your business with MailGuard's specialist AI-powered, zero-day email security. Special Ops for when speed matters! Our real-time zero-day, email threat detection amplifies our client’s intelligence, knowledge, security and defence. Talk to a solution consultant at MailGuard today about securing your company's inboxes.
Stay up-to-date with MailGuard's latest blog posts by subscribing to free updates. Subscribe to weekly updates by clicking on the button below.