5. Microsoft

Brand imposter · Big TechJuly 2026

Well over 70% of US households have products that run on Microsoft, and a Microsoft account anchors both work and home life — Windows, Office, Outlook, OneDrive, Xbox — which is why Check Point ranks Microsoft the most-phished brand on earth (22% of all brand-impersonation attempts in Q1 2026). In consumer submissions to Scamwise, Microsoft impersonation is less about stealing work logins and more about fear: fake invoices and scary pop-ups.

How Microsoft is being impersonated

Popular impersonation lures to pay attention to:

Defender and 365 renewal invoices

An official-looking receipt says your subscription auto-renewed for $300–$500, with a number to call for a refund. The refund call leads to remote access and drained accounts.

Password-expiry and account-alert emails

"Your password expires today" messages that harvest Microsoft account credentials on pixel-perfect fake login pages.

Fake security pop-ups

A webpage takes over the browser, plays an alarm, declares the PC infected, and displays a "Microsoft support" number. The support agent's real product is remote access to your computer.

Second channel checks

When you want to be sure

  1. 1

    Check your real subscriptions.

    Type account.microsoft.com into your browser and open Services & subscriptions. If there's no charge there and nothing on your card statement, the invoice is fiction.

  2. 2

    Treat unsolicited “support” as a scam by default.

    Microsoft doesn't cold-call, and real Windows warnings never include a phone number. If a pop-up locks your browser, don't call — close it via Ctrl+Alt+Del → Task Manager, or restart.

  3. 3

    Never grant remote access you didn't initiate.

    No legitimate Microsoft process starts with you installing AnyDesk or TeamViewer for a caller. If you already have, disconnect from the internet and call your bank from the number on your card.

Similar impersonated brands