
Security researchers have uncovered a new criminal service called Forg365 that makes it dangerously easy for scammers to send fake emails impersonating Microsoft. What makes Forg365 different is that it uses artificial intelligence to craft messages that are far more polished and believable than typical spam — with fewer spelling mistakes, correct branding, and a tone that sounds genuinely official. The goal is to trick you into clicking a link and typing in your Microsoft 365 username and password on a fake login page.
If a scammer gets your Microsoft 365 credentials, they can read your emails, access files stored in OneDrive, impersonate you to colleagues or family members, and lock you out of your own account. Microsoft 365 is used by hundreds of millions of people for personal email (Outlook), cloud storage, and office apps — making it an attractive target. The good news is that a few simple habits make this type of attack far less likely to succeed.
How to check if you’re affected
Affected versions include all Microsoft 365 subscription plans (Personal, Family, and Business). If you use any Microsoft account — Outlook.com, Hotmail, or a work or school Microsoft 365 account — you are in scope.
Here is what to check right now:
- Turn on two-step verification. Go to account.microsoft.com/security and enable “Two-step verification.” Even if a scammer gets your password, they cannot log in without the second step.
- Be suspicious of urgent emails. Forg365 messages often claim your account will be suspended or that you missed a payment. Pause before clicking any link.
- Check the sender address carefully. Hover over the “From” name to reveal the real email address — legitimate Microsoft emails come from
@microsoft.com, not look-alike domains like@microsoft-support.net. - Review your recent sign-in activity. At account.microsoft.com/security, look under “Recent activity” for any logins from unfamiliar locations.
