08/31/2026
What if the phishing email really did come from Microsoft?
That’s exactly what happened in a recent phishing attack uncovered by IRONSCALES.
Attackers abused a legitimate Microsoft Clarity feature to send a fake PayPal transaction notice. The email:
→ Was genuinely sent by Microsoft
→ Passed SPF, DKIM, and DMARC authentication
→ Contained a legitimate Microsoft link
→ Still led the recipient toward a scam
There was no suspicious domain or malicious attachment to give it away.
The red flag was context.
A Microsoft analytics platform sending a PayPal billing notice simply didn’t make sense—and the recipient recognized it and reported the message.
It’s an important reminder that modern phishing attacks increasingly exploit the platforms and trust signals organizations rely on every day.
Technology matters. But so do context, employee awareness, and a layered approach to cybersecurity.
➡️ Read the full attack breakdown from IRONSCALES: https://ironscales.com/threat-intelligence/microsoft-clarity-project-title-abuse-authenticated-paypal-btc-scam