How to recognise and safely handle a fake 'Microsoft 365 subscription renewal' or fake invoice scam email
Summary
This guide helps you troubleshoot and resolve: How to recognise and safely handle a fake 'Microsoft 365 subscription renewal' or fake invoice scam email. Follow the steps below to fix the issue.
Common Causes
Scam emails impersonating Microsoft 365 subscription renewals or fake invoices are among the most common phishing attempts targeting Australian small businesses and home offices. These messages are designed to look legitimate, often using Microsoft branding, urgent language, and realistic invoice numbers to trick you into clicking a link, opening an attachment, or calling a fraudulent support number. Knowing how to recognise the warning signs and handle these emails safely is essential to protecting your account, your data, and your finances.
Common Warning Signs of a Fake Renewal or Invoice Email
Before taking any action on a message claiming to be from Microsoft, pause and check for these red flags:
- The sender's email address does not end in
@microsoft.comor a recognised Microsoft billing domain. Look closely — scammers often use addresses like@microsoft-365-billing.comor@account-microsoft.net. - The email creates a sense of urgency, such as "Your subscription will be cancelled in 24 hours" or "Immediate payment required to avoid service disruption."
- You are asked to pay using unusual methods such as cryptocurrency, gift cards, or wire transfer.
- The invoice lists products or subscription counts you do not recognise, or a renewal date that does not match your records.
- Links in the email do not point to
microsoft.com. Hover over them (without clicking) to preview the actual destination. - You are asked to call a phone number to "confirm" or "cancel" a charge. Microsoft does not send unsolicited phone numbers in billing emails.
- The greeting is generic, such as "Dear Customer" or "Dear User," rather than addressing you by name.
- There are spelling or grammatical errors, or the layout looks slightly off compared to genuine Microsoft communications.
Quick Fix Steps
- Do not click any links or open any attachments in the suspicious email.
- Verify your actual subscription status by signing in to
account.microsoft.comdirectly through your web browser. - Report the email to Microsoft using the built-in reporting tool in Outlook.
- Delete the email from your inbox and your Deleted Items folder.
- If you have already clicked a link or entered credentials, change your Microsoft 365 password immediately and contact your IT support.
Detailed Instructions
Verify the Email Without Clicking Anything
The safest way to confirm whether a renewal notice is genuine is to check your subscription independently.
- Open a new browser window and type
account.microsoft.comdirectly into the address bar. Do not copy the address from the email. - Sign in with your usual Microsoft 365 credentials.
- Navigate to Services & subscriptions to view your active subscriptions, renewal dates, and billing history.
- If no renewal is due, or the details do not match the email, the message is a scam.
Report the Email in Outlook (Web or Desktop)
Reporting helps Microsoft block the scam for other users.
- Select the suspicious message in your inbox without opening it.
- From the toolbar, click Report, then choose Report phishing. In classic Outlook, look for the Report Message add-in.
- If you are using Outlook on the web (
outlook.office.com), click the three dots (...) at the top of the message and select Report > Report phishing. - Confirm the report when prompted. The message will be moved to your Deleted Items folder.
Report Directly to Microsoft
For additional reporting, forward the suspicious email to Microsoft's abuse team:
- Create a new email and address it to
[email protected]. - Forward the suspicious message as an attachment. In Outlook, select More actions (the three dots) and choose Forward as attachment.
- Do not add any commentary in the body of the forwarded email.
- Send the email and then delete it from your Sent Items folder.
Block the Sender
Prevent further messages from the same scammer reaching your inbox.
- Open the suspicious email in Outlook.
- Click the three dots (...) at the top of the message.
- Select Block > Block sender.
- Confirm the block when prompted.
Permanently Delete the Email
- Go to your Deleted Items folder.
- Locate the reported message.
- Right-click the message and select Delete, or select it and press
Shift + Deleteto remove it permanently. - Empty the Deleted Items folder if prompted.
If You Already Clicked or Responded
Take these steps immediately to limit any potential damage.
- Change your Microsoft 365 password by signing in at
account.microsoft.comand navigating to Security > Password. - Enable multi-factor authentication (MFA) under Security > Advanced security options if it is not already active.
- Review your recent sign-in activity at
account.microsoft.comunder Security > Sign-in activity and sign out of any unfamiliar sessions. - Check your bank or credit card statement for any unauthorised transactions and contact your financial institution if needed.
- Run a full antivirus scan on the device you used to open the email or click the link.
- Inform colleagues or team members so they can be alert for similar messages and avoid falling for the same scam.
Preventing Future Scam Emails
- Always access Microsoft 365 billing by typing
account.microsoft.comdirectly into your browser rather than following email links. - Keep multi-factor authentication enabled on your Microsoft account at all times.
- Train staff to recognise phishing emails and establish a clear process for reporting suspicious messages.
- Use the built-in spam and phishing filters in Microsoft 365, and ensure your organisation's Exchange Online Protection settings are configured correctly.
- Regularly review your subscription and billing details so you know what legitimate communications should look like.
Related Articles
Still Having Issues?
💻 Open a Ticket