Home › Knowledgebase › KB-575

How to recognise and safely handle a fake 'Microsoft 365 subscription renewal' or fake invoice scam email

Summary

This guide helps you troubleshoot and resolve: How to recognise and safely handle a fake 'Microsoft 365 subscription renewal' or fake invoice scam email. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Scam emails impersonating Microsoft 365 subscription renewals or fake invoices are among the most common phishing attempts targeting Australian small businesses and home offices. These messages are designed to look legitimate, often using Microsoft branding, urgent language, and realistic invoice numbers to trick you into clicking a link, opening an attachment, or calling a fraudulent support number. Knowing how to recognise the warning signs and handle these emails safely is essential to protecting your account, your data, and your finances.

Common Warning Signs of a Fake Renewal or Invoice Email

Before taking any action on a message claiming to be from Microsoft, pause and check for these red flags:

If any of the above apply, treat the email as suspicious. Do not click any links, do not open any attachments, and do not call any phone numbers listed in the message.

Quick Fix Steps

  1. Do not click any links or open any attachments in the suspicious email.
  2. Verify your actual subscription status by signing in to account.microsoft.com directly through your web browser.
  3. Report the email to Microsoft using the built-in reporting tool in Outlook.
  4. Delete the email from your inbox and your Deleted Items folder.
  5. If you have already clicked a link or entered credentials, change your Microsoft 365 password immediately and contact your IT support.

Detailed Instructions

Verify the Email Without Clicking Anything

The safest way to confirm whether a renewal notice is genuine is to check your subscription independently.

  1. Open a new browser window and type account.microsoft.com directly into the address bar. Do not copy the address from the email.
  2. Sign in with your usual Microsoft 365 credentials.
  3. Navigate to Services & subscriptions to view your active subscriptions, renewal dates, and billing history.
  4. If no renewal is due, or the details do not match the email, the message is a scam.
Genuine Microsoft invoices will always appear in your account under Billing & payment history. If the invoice is not listed there, it is not real.

Report the Email in Outlook (Web or Desktop)

Reporting helps Microsoft block the scam for other users.

  1. Select the suspicious message in your inbox without opening it.
  2. From the toolbar, click Report, then choose Report phishing. In classic Outlook, look for the Report Message add-in.
  3. If you are using Outlook on the web (outlook.office.com), click the three dots (...) at the top of the message and select Report > Report phishing.
  4. Confirm the report when prompted. The message will be moved to your Deleted Items folder.

Report Directly to Microsoft

For additional reporting, forward the suspicious email to Microsoft's abuse team:

  1. Create a new email and address it to [email protected].
  2. Forward the suspicious message as an attachment. In Outlook, select More actions (the three dots) and choose Forward as attachment.
  3. Do not add any commentary in the body of the forwarded email.
  4. Send the email and then delete it from your Sent Items folder.

Block the Sender

Prevent further messages from the same scammer reaching your inbox.

  1. Open the suspicious email in Outlook.
  2. Click the three dots (...) at the top of the message.
  3. Select Block > Block sender.
  4. Confirm the block when prompted.

Permanently Delete the Email

  1. Go to your Deleted Items folder.
  2. Locate the reported message.
  3. Right-click the message and select Delete, or select it and press Shift + Delete to remove it permanently.
  4. Empty the Deleted Items folder if prompted.

If You Already Clicked or Responded

Take these steps immediately to limit any potential damage.

  1. Change your Microsoft 365 password by signing in at account.microsoft.com and navigating to Security > Password.
  2. Enable multi-factor authentication (MFA) under Security > Advanced security options if it is not already active.
  3. Review your recent sign-in activity at account.microsoft.com under Security > Sign-in activity and sign out of any unfamiliar sessions.
  4. Check your bank or credit card statement for any unauthorised transactions and contact your financial institution if needed.
  5. Run a full antivirus scan on the device you used to open the email or click the link.
  6. Inform colleagues or team members so they can be alert for similar messages and avoid falling for the same scam.
If you entered payment details or shared sensitive information, contact your bank straight away and consider placing a fraud alert on your credit file through IDCARE (the Australian identity and cyber support service).

Preventing Future Scam Emails

If you are unsure whether an email is genuine, or if your business has been affected by a phishing attack, our security team can help. Open a Ticket and we will assist you promptly.

Related Articles

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket