5. Microsoft
Well over 70% of US households have products that run on Microsoft, and a Microsoft account anchors both work and home life — Windows, Office, Outlook, OneDrive, Xbox — which is why Check Point ranks Microsoft the most-phished brand on earth (22% of all brand-impersonation attempts in Q1 2026). In consumer submissions to Scamwise, Microsoft impersonation is less about stealing work logins and more about fear: fake invoices and scary pop-ups.
How Microsoft is being impersonated
Popular impersonation lures to pay attention to:
Defender and 365 renewal invoices
An official-looking receipt says your subscription auto-renewed for $300–$500, with a number to call for a refund. The refund call leads to remote access and drained accounts.
Password-expiry and account-alert emails
"Your password expires today" messages that harvest Microsoft account credentials on pixel-perfect fake login pages.
Fake security pop-ups
A webpage takes over the browser, plays an alarm, declares the PC infected, and displays a "Microsoft support" number. The support agent's real product is remote access to your computer.
Second channel checks
When you want to be sure
- 1
Check your real subscriptions.
Type account.microsoft.com into your browser and open Services & subscriptions. If there's no charge there and nothing on your card statement, the invoice is fiction.
- 2
Treat unsolicited “support” as a scam by default.
Microsoft doesn't cold-call, and real Windows warnings never include a phone number. If a pop-up locks your browser, don't call — close it via Ctrl+Alt+Del → Task Manager, or restart.
- 3
Never grant remote access you didn't initiate.
No legitimate Microsoft process starts with you installing AnyDesk or TeamViewer for a caller. If you already have, disconnect from the internet and call your bank from the number on your card.