Suspicious
Phishings targeting Microsoft
Suspicious and active websites
Phishings targeting Microsoft
Suspicious and active websites
Active
51
New (7d)
21
Trend (7d)
↑600%
Possible campaigns
3 of these are in a suspected cluster
40bef666f218
3 of these are in a suspected cluster 1dedcfa35d5a
2 of these are in a suspected cluster df3aee70a9d3
1 of these is in a suspected cluster 555474fbaa6d
Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.
| Last check (UTC) | First seen (UTC) ▾ | URL | Screenshot | Flags | Details |
|---|---|---|---|---|---|
| 2026-08-03 07:30 | 2026-08-02 16:01 | ![]() |
PhishTank | Details | |
| 2026-08-03 07:30 | 2026-08-02 16:01 | ![]() |
PhishTank | Details | |
| 2026-08-03 07:30 | 2026-08-02 05:46 | ![]() |
GSB | Details | |
| 2026-08-03 07:30 | 2026-08-02 05:43 | ![]() |
urlscan | Details | |
| 2026-08-03 07:30 | 2026-08-01 06:19 | ![]() |
urlscan | Details | |
| 2026-08-03 07:30 | 2026-08-01 01:01 | ![]() |
PhishTank | Details | |
| 2026-08-03 07:30 | 2026-07-31 05:46 | ![]() |
GSB | Details | |
| 2026-08-03 07:30 | 2026-07-31 05:46 | ![]() |
GSB | Details | |
| 2026-08-03 07:30 | 2026-07-29 13:03 | ![]() |
OpenPhish urlscan | Details | |
| 2026-08-03 07:30 | 2026-07-29 05:48 | ![]() |
GSB | Details | |
| 2026-08-03 07:30 | 2026-07-28 18:07 | ![]() |
TweetFeed | Details | |
| 2026-08-03 07:30 | 2026-07-28 18:06 | ![]() |
TweetFeed | Details | |
| 2026-08-03 07:30 | 2026-07-28 18:06 | ![]() |
TweetFeed | Details | |
| 2026-08-03 07:30 | 2026-07-28 18:06 | ![]() |
TweetFeed | Details | |
| 2026-08-03 07:30 | 2026-07-28 18:05 | ![]() |
TweetFeed urlscan | Details | |
| 2026-08-03 07:30 | 2026-07-28 03:04 | ![]() |
TweetFeed | Details | |
| 2026-08-03 07:30 | 2026-07-27 16:03 | ![]() |
TweetFeed | Details | |
| 2026-08-03 07:30 | 2026-07-27 16:03 | ![]() |
TweetFeed | Details | |
| 2026-08-03 07:30 | 2026-07-27 16:03 | ![]() |
TweetFeed | Details | |
| 2026-08-03 07:30 | 2026-07-27 05:05 | ![]() |
TweetFeed | Details | |
| 2026-08-03 07:30 | 2026-07-27 05:04 | ![]() |
TweetFeed | Details | |
| 2026-08-03 07:30 | 2026-07-23 12:01 | ![]() |
TweetFeed urlscan | Details | |
| 2026-08-03 07:30 | 2026-07-23 01:01 | ![]() |
OpenPhish | Details | |
| 2026-08-03 07:30 | 2026-07-22 01:02 | ![]() |
GSB OpenPhish | Details | |
| 2026-08-03 07:30 | 2026-07-19 08:11 | ![]() |
urlscan | Details | |
| 2026-08-03 07:30 | 2026-07-14 21:00 | ![]() |
TweetFeed | Details | |
| 2026-08-03 07:30 | 2026-07-14 13:03 | ![]() |
OpenPhish urlscan | Details | |
| 2026-08-03 07:30 | 2026-07-12 15:41 | ![]() |
GSB | Details | |
| 2026-08-03 07:30 | 2026-07-12 15:41 | ![]() |
GSB | Details | |
| 2026-08-03 07:30 | 2026-06-28 01:03 | ![]() |
GSB OpenPhish urlscan | Details | |
| 2026-08-03 07:30 | 2026-06-27 01:01 | ![]() |
OpenPhish | Details | |
| 2026-08-03 07:30 | 2026-06-26 01:01 | ![]() |
OpenPhish urlscan | Details | |
| 2026-08-03 07:30 | 2026-06-25 13:01 | ![]() |
OpenPhish urlscan | Details | |
| 2026-08-03 07:30 | 2026-06-25 13:01 | ![]() |
OpenPhish | Details | |
| 2026-08-03 07:30 | 2026-06-25 13:01 | ![]() |
OpenPhish | Details | |
| 2026-08-03 07:30 | 2026-06-25 05:54 | ![]() |
urlscan | Details | |
| 2026-08-03 07:30 | 2026-06-17 01:06 | ![]() |
OpenPhish | Details | |
| 2026-08-03 07:30 | 2026-06-08 13:01 | ![]() |
OpenPhish urlscan | Details | |
| 2026-08-03 07:30 | 2026-06-06 11:32 | ![]() |
urlscan | Details | |
| 2026-08-03 07:30 | 2026-06-06 01:02 | ![]() |
OpenPhish urlscan | Details | |
| 2026-08-03 07:30 | 2026-05-15 13:01 | ![]() |
GSB OpenPhish urlscan | Details | |
| 2026-08-03 07:30 | 2026-05-13 13:05 | ![]() |
GSB OpenPhish urlscan | Details | |
| 2026-08-03 07:30 | 2026-05-12 01:01 | ![]() |
GSB OpenPhish urlscan | Details | |
| 2026-08-03 07:30 | 2026-05-10 09:44 | ![]() |
urlscan | Details | |
| 2026-08-03 07:30 | 2026-05-05 13:02 | ![]() |
OpenPhish urlscan | Details | |
| 2026-08-03 07:30 | 2026-04-20 23:54 | ![]() |
urlscan | Details | |
| 2026-08-03 07:30 | 2026-04-20 01:01 | ![]() |
OpenPhish | Details | |
| 2026-08-03 07:30 | 2026-04-09 00:00 | ![]() |
PhishTank urlscan | Details | |
| 2026-08-03 07:30 | 2026-03-30 13:01 | ![]() |
GSB OpenPhish urlscan | Details | |
| 2026-08-03 07:30 | 2026-03-28 13:01 | ![]() |
OpenPhish | Details | |
| 2026-08-03 07:30 | 2026-03-28 01:01 | ![]() |
OpenPhish urlscan | Details |
Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.
| URL | Screenshot | Details |
|---|---|---|
| https://microsoft-107185login…
PhishTank |
![]() |
Details |
| https://outlook-update-109103…
PhishTank |
![]() |
Details |
| https://micros0ft.tech
GSB |
![]() |
Details |
| https://microsoftuk.co
urlscan |
![]() |
Details |
| https://edge-microsoft-zh.com…
urlscan |
![]() |
Details |
| https://admin-outlook-ngc-cbe…
PhishTank |
![]() |
Details |
| https://microsoft-sharepoint.…
GSB |
![]() |
Details |
| https://onedrive-cf-index-ng-…
GSB |
![]() |
Details |
| http://secure-server-page--mi…
OpenPhish urlscan |
![]() |
Details |
| https://microsoft365updates.c…
GSB |
![]() |
Details |
| http://microsoftteams24.com
TweetFeed |
![]() |
Details |
| http://outlookmail.social
TweetFeed |
![]() |
Details |
| http://microsoftteam.info
TweetFeed |
![]() |
Details |
| http://microsoftsupport.pro
TweetFeed |
![]() |
Details |
| http://office365licensingsupp…
TweetFeed urlscan |
![]() |
Details |
| http://microsoft.berlin
TweetFeed |
![]() |
Details |
| http://microsoft365businessba…
TweetFeed |
![]() |
Details |
| http://helpsecurity-microsoft…
TweetFeed |
![]() |
Details |
| http://securityhelp-microsoft…
TweetFeed |
![]() |
Details |
| http://security-help-microsof…
TweetFeed |
![]() |
Details |
| http://microsoftteamsonline.c…
TweetFeed |
![]() |
Details |
| http://microsoftmailsupports.…
TweetFeed urlscan |
![]() |
Details |
| http://emailnotifications.m36…
OpenPhish |
![]() |
Details |
| http://outlookmailwww.webcind…
GSB OpenPhish |
![]() |
Details |
| https://microsoftai.pl
urlscan |
![]() |
Details |
| http://microsoft.updata.net.cn
TweetFeed |
![]() |
Details |
| https://0utl00k-chek-clip.ice…
OpenPhish urlscan |
![]() |
Details |
| https://click6.microsoftsuppo…
GSB |
![]() |
Details |
| https://click5.microsoftsuppo…
GSB |
![]() |
Details |
| https://login.microsoftonline…
GSB OpenPhish urlscan |
![]() |
Details |
| http://ctia-outlook-2026.s1.y…
OpenPhish |
![]() |
Details |
| https://onedrive.at-us.therel…
OpenPhish urlscan |
![]() |
Details |
| https://cb85df97.onedrive-1mr…
OpenPhish urlscan |
![]() |
Details |
| https://outlook.verifytoken.c…
OpenPhish |
![]() |
Details |
| http://microsoft-login-securi…
OpenPhish |
![]() |
Details |
| https://microsoftjk.eu.org
urlscan |
![]() |
Details |
| https://office365.rricrosoft-…
OpenPhish |
![]() |
Details |
| https://programme-hup.m365-mi…
OpenPhish urlscan |
![]() |
Details |
| https://onedriveauthorization…
urlscan |
![]() |
Details |
| http://security.m365-microsof…
OpenPhish urlscan |
![]() |
Details |
| https://microsoft.authorised-…
GSB OpenPhish urlscan |
![]() |
Details |
| https://microsoft.account.tru…
GSB OpenPhish urlscan |
![]() |
Details |
| http://microsoftquarantine.au…
GSB OpenPhish urlscan |
![]() |
Details |
| https://microsoft-se.us
urlscan |
![]() |
Details |
| https://outlook.webaccess-ale…
OpenPhish urlscan |
![]() |
Details |
| https://hotmail.com.es
urlscan |
![]() |
Details |
| http://reactivar-microsoft-li…
OpenPhish |
![]() |
Details |
| https://outlook36validar.webc…
PhishTank urlscan |
![]() |
Details |
| https://security.email-micros…
GSB OpenPhish urlscan |
![]() |
Details |
| http://support.m365-microsoft…
OpenPhish |
![]() |
Details |
| https://office365.internal-al…
OpenPhish urlscan |
![]() |
Details |
AIHow to verify a real Microsoft URL
- Legitimate Microsoft URLs always end in
microsoft.com(e.g.www.microsoft.com,account.microsoft.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like.xyz/.top/.vip— is not Microsoft. - The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
- If you got the link from email, SMS, or social media, do not click it. Open
microsoft.comfrom your browser bookmark or type the domain manually. - Real Microsoft pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.












































