Watch out for suspicious Microsoft Azure Monitor alerts – it could be this shifty new callback phishing attack
- Phishing campaign abuses Microsoft Azure Monitor alerts
- Fake “suspicious charges” emails bypass protections using legitimate domain
- Attackers craft alerts with custom messages, similar to past Google Tasks and PayPal abuse
Microsoft Azure Monitor is the latest in the long line of legitimate tools being abused in phishing attacks. If you are used to getting notifications from this platform, be careful, as the emails are quite convincing and relatively difficult to spot.
Microsoft Azure Monitor is a cloud-based service that collects and analyzes data from applications and infrastructure, helping users monitor performance, detect issues, and respond to problems in real time.
In recent times, users have been getting emails directly from this platform, notifying them of “suspicious charges” and “invoice activity”.
Article continues below
Using mailing lists
The emails encourage the recipients to call the phone number provided in the alert, to sort the “problem” out. Many also state that the accounts are temporarily suspended, or that the funds are being placed on hold.
Since they are coming directly from Microsoft Azure Monitor, using a legitimate, trusted domain, these alerts largely bypass email protection services and land directly into people’s inboxes.
But these are not “real” alerts. As explained by BleepingComputer, who’s seen these campaigns in action, anyone can create alerts in Azure Monitor for “easily triggered conditions” such as new orders, payments, generated invoices, and other billing alerts. Whoever creates the alerts can also create the message to be sent in the description field, and that is where the fake warning is usually placed.
Finally, the attackers can set up the alert to be sent out to people on specific mailing lists. In this case, these lists are owned by the attackers, as well.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
So, the MO is like this: set up an alert, trigger it, and send the notification to everyone on a predefined mailing list.
It is a simple and effective technique that we’ve seen being used before. In late February, TechRadar Pro reported on a similar campaign abusing Google Tasks, and before that, PayPal.
Via BleepingComputer

The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!
And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.
Phishing campaign abuses Microsoft Azure Monitor alerts Fake “suspicious charges” emails bypass protections using legitimate domain Attackers craft alerts with custom messages, similar to past Google Tasks and PayPal abuse Microsoft Azure Monitor is the latest in the long line of legitimate tools being abused in phishing attacks. If you…
Recent Posts
- EveryPlate Meal Kit Review (2026): Low Cost, Simplicity, Flavor
- I’m a dad and these are the tech gifts and gadgets I’d love my kid to buy me for Father’s Day 2026
- Google experiments with sending Chrome searches straight to AI
- LG Promo Codes and Coupons for June 2026
- 30% Off Canon Promo Codes | June 2026
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023