Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Malicious Exploitation of Microsoft 365 Admin Portal's Personal Message Field: A Vulnerability to Sextortion Scams



Microsoft 365 Admin Portal has been found vulnerable to abuse by scammers, who use its Personal Message feature to send extortion-themed emails to unsuspecting users. These scams can bypass email security filters due to a limit of 1,000 characters in personal messages, which can be circumvented using browser developer tools. As Microsoft takes steps to prevent such incidents, it is essential for users to remain cautious and report any suspicious activity.

  • Malicious actors have exploited a vulnerability in Microsoft 365's Personal Message field to send extortion-themed emails.
  • Sextortion scams, which claim to possess compromising images or videos of an individual, are being sent via the compromised Personal Message field.
  • The vulnerability was discovered due to the Personal Message field having a character limit of only 1,000 characters, which scammers have found ways to bypass using browser developer tools.
  • Microsoft has confirmed receipt of reports about these scams and is taking steps to prevent similar incidents in the future.
  • Users are urged to remain vigilant and report any suspicious emails or messages to the relevant authorities to mitigate this threat.



  • Microsoft Corporation, a leading provider of productivity software and services, has recently been the subject of criticism for its handling of security vulnerabilities in its popular Microsoft 365 suite. In this latest development, a group of malicious actors has successfully exploited the Personal Message field within the Microsoft 365 Admin Portal to send extortion-themed emails to unsuspecting users. These emails are part of a broader trend of sextortion scams that have gained notoriety online in recent years.

    Sextortion scams typically involve scammers claiming that they possess compromising images or videos of an individual, and threatening to share them publicly unless the victim agrees to pay a hefty sum for their "release." The emails often appear to be legitimate communications from Microsoft itself, making it difficult for recipients to discern between genuine messages and those sent by malicious actors.

    The source of these extortion emails lies in the Microsoft 365 Admin Portal's Personal Message feature. This feature allows users to send personalized messages to others via email, which can include links or attachments. However, a recent discovery revealed that the Personal Message field has a character limit of only 1,000 characters. Scammers have found ways to bypass this restriction by utilizing browser developer tools to manipulate the