In the world of cyber security, trust is both the most valuable asset and the most exploited vulnerability. Criminals have always understood that the easiest way past a firm’s defences is not to break through them, but to walk through a door that someone holds open willingly. The latest evolution of that principle is now landing in business inboxes across the country and it is catching out firms that would otherwise consider themselves well-protected.

A new phishing campaign is using Microsoft Azure Monitor, a legitimate and widely used cloud monitoring tool, to deliver scam emails that look and feel entirely authentic. Unlike traditional phishing, these messages are not crudely spoofed or sent from suspicious domains. They originate from within Microsoft’s own infrastructure, which means they pass standard email authentication checks and arrive without the usual warning flags.

For regulated professional service firms: solicitors, accountants, mortgage brokers, independent financial advisers and insurance professionals; this represents a particularly acute threat. These businesses handle sensitive client data daily, operate under strict regulatory obligations and cannot afford the reputational fallout of a data breach. Understanding how this scam works, and what to do about it, is no longer optional.

How Azure Monitor Works and How Attackers Are Exploiting It

Microsoft Azure Monitor is a platform tool designed to track the health and performance of cloud-hosted systems. It monitors infrastructure, identifies anomalies and sends automated alert notifications when predefined conditions are met. For example, a spike in resource usage, a failed service or a billing event.

The alerts it sends are expected and routine for any organisation using Azure. Staff in IT, finance and operations are accustomed to receiving these notifications and acting on them promptly. That familiarity is precisely what attackers are now weaponising.

Here is how the scam operates: criminals gain access to an Azure tenant (or create one) and configure alert rules with intentionally misleading content. They craft alert messages that warn of fabricated billing discrepancies, unexpected charges, account suspensions or suspicious activity. Because the alert system allows custom message content, the attacker can write whatever they choose and the resulting email is sent through Microsoft’s legitimate notification infrastructure.

The email arrives from a genuine Microsoft domain. It passes SPF, DKIM and DMARC checks. It lands in the primary inbox rather than the junk folder. For the recipient, there is no immediately obvious reason to distrust it. This is not a case of a poorly designed replica hoping to fool the inattentive. It is a message delivered through the real system, crafted to trigger urgency and compel action. Firms that rely on compliance-driven governance processes should recognise that this tactic exploits the very trust structures they depend upon. As we explored in our recent post on whether your data security is truly keeping pace with your business, the gap between perceived protection and actual vulnerability is often wider than firms assume.

 

Why Traditional Email Filters Are Not Enough

Most businesses invest in email security: spam filters, malware scanning, link analysis and domain reputation checks. These tools are essential and they do stop a significant volume of threats. However, they are largely designed to catch emails that exhibit known indicators of compromise: suspicious sender domains, mismatched authentication records, known malicious URLs or recognised payload signatures.

The Azure Monitor scam sidesteps these controls entirely. Because the email is sent through Microsoft’s own infrastructure, it does not trigger domain-based alerts. Because the content is a genuine Azure notification (albeit with attacker-crafted text), it does not match the patterns that filters associate with phishing. Because the call to action is typically a phone number rather than a malicious link, URL scanning has nothing to flag.

This is the fundamental challenge: the delivery mechanism is legitimate, even though the intent is fraudulent. It is analogous to receiving a forged letter on genuine company stationery, posted through the official mail system. The envelope is real; the message inside is not.

For regulated firms, this has significant implications. Compliance frameworks, whether imposed by the SRA, FCA, ICAEW or other regulators, increasingly require demonstrable cyber resilience. A breach caused by a phishing attack that “should have been caught” can lead to regulatory censure, client notification obligations and material reputational harm. The fact that traditional filters would not have stopped this particular vector does not remove the obligation to have controls in place that would.

The Anatomy of the Attack (What to Watch For)

Understanding the specific characteristics of these fraudulent alerts is the first step towards defending against them. The emails typically share several common features:

  • Fabricated urgency: The message will almost always create a sense of time pressure. It may warn of an impending account suspension, an overdue invoice, an unrecognised charge or a security flag that requires immediate resolution. The language is designed to bypass rational assessment and provoke a reactive response.
  • A phone number rather than a link: Unlike many phishing campaigns that direct recipients to a fake login page, these scams often instruct the reader to call a support number. This is a deliberate choice. A phone call allows the attacker to engage in real-time social engineering, extracting credentials, payment details or remote access permissions through conversation.
  • Professional presentation: Because the email is generated by Azure Monitor, the formatting, structure and sender details are consistent with genuine Microsoft communications. There are no obvious typographical errors, no misaligned logos and no suspicious attachments.
  • Targeted distribution: Attackers configure the alert to send to specific email addresses or mailing lists they control or have obtained. This means the scam can be targeted at particular organisations or roles within a firm, increasing its effectiveness.

The combination of these elements makes this a high-confidence phishing attack, one where the recipient has very little surface-level reason to doubt its authenticity. This is closely related to the broader trend of phishing sophistication. Your team’s ability to recognise evolving threats matters more than ever, and it is worth reviewing how much sensitive information your browser may be exposing as part of a wider security awareness effort.

A Pattern of Exploitation Using Trusted Platforms as Attack Vectors

This is not the first time criminals have co-opted trusted platforms to deliver phishing content. Similar techniques have been documented using PayPal invoicing, Google Forms, Calendly invitations and even SharePoint sharing notifications. The underlying strategy is always the same: exploit a platform that recipients already trust, use its legitimate sending infrastructure to bypass security controls and craft a message that blends seamlessly with expected communications.

What makes the Azure Monitor variant particularly dangerous is the enterprise context. Azure is a core infrastructure platform for many professional service firms. Alerts from Azure Monitor are not marketing emails that can be casually ignored, they relate to the operational health of business-critical systems. An alert suggesting a billing anomaly or service disruption demands attention, and that demand is exactly what attackers are counting on.

For firms in regulated sectors, the intersection of operational dependency and compliance obligation creates a high-pressure environment in which these scams thrive. The recipient knows that ignoring a genuine alert could have consequences and that fear of inaction is exploited to drive the very action the attacker wants.

What Every Regulated Firm Should Do Right Now

Defending against this type of attack requires a layered approach that combines technical controls, procedural discipline and human awareness. No single measure is sufficient on its own.

  1. Establish a verification protocol for all system alerts

Any email that requests action, whether it involves calling a number, clicking a link, making a payment or sharing credentials; should be verified independently before any action is taken. For Azure-related alerts, this means logging into the Azure portal directly through the browser (never via a link in the email) and checking for corresponding notifications there. If the alert is genuine, it will appear in the portal. If it does not, the email should be treated as suspicious and reported immediately.

  1. Brief your team specifically on this threat

General phishing awareness training is valuable, but it must be supplemented with specific, timely briefings on emerging threats. Staff who handle billing, IT administration or account management are the most likely targets. They need to understand that legitimate-looking Azure alerts can now be fraudulent, and they need clear guidance on what to do when one arrives.

  1. Review and strengthen your email security stack

While traditional filters may not catch this specific attack, advanced email security solutions that incorporate behavioural analysis, anomaly detection and contextual assessment can provide an additional layer of protection. Speak to your IT support provider about whether your current setup is adequate for this class of threat.

  1. Implement and enforce multi-factor authentication (MFA)

Even if an attacker obtains credentials through a phone-based social engineering call, MFA ensures that those credentials alone are not sufficient to gain access. For regulated firms, MFA should be enforced across all Microsoft 365 and Azure services without exception. Credential hygiene is a foundational pillar of compliance, and as we discussed in our recent article on why AI is the wrong tool for generating passwords, shortcuts in this area can introduce vulnerabilities that undermine your entire security posture.

  1. Conduct a tabletop exercise

Walk through a scenario in which a member of staff receives one of these fraudulent alerts and responds to it. Trace the potential consequences: what data could be exposed, what regulatory notifications would be required, what client communications would need to be issued. This exercise is not theoretical, it is precisely the kind of incident that regulators expect firms to have planned for.

  1. Report suspicious emails

If your firm receives a suspected phishing email, report it both internally and to the National Cyber Security Centre (NCSC) via their suspicious email reporting service. Collective reporting helps security organisations identify and disrupt active campaigns more quickly.

The Governance Dimension, Why This Is a Board-Level Issue

For partners, directors and senior leaders in regulated firms, this is not purely an IT matter. It is a governance issue. Regulatory bodies are increasingly clear that cyber resilience is a leadership responsibility, not something that can be delegated entirely to the IT department or an external provider.

The SRA’s guidance on cyber security, the FCA’s operational resilience framework and the ICAEW’s technology guidance all emphasise that firms must be able to demonstrate appropriate controls, staff awareness and incident response capability. A successful phishing attack that compromises client data, particularly one using a known and documented technique, would raise serious questions about whether adequate measures were in place.

Beyond the regulatory dimension, there is the matter of client confidence. Professional service clients entrust their advisers with highly sensitive financial, legal and personal information. A breach erodes that trust in a way that is difficult to rebuild. The cost is not limited to fines or remediation, it extends to: client attrition, reputational damage and competitive disadvantage. As we noted when exploring whether anyone is truly controlling AI use at work, the challenge for regulated firms is that new risks emerge faster than policies are updated and the firms that thrive are those that build adaptable, audit-ready security cultures.

Building a Culture of Healthy Scepticism

The most resilient firms are those that cultivate a culture where questioning unexpected communications is not seen as an inconvenience but as a professional responsibility. When a member of staff pauses to verify an alert rather than responding immediately, that is not a delay, it is a control functioning as intended.

This cultural shift requires leadership endorsement. If partners and directors model the behaviour they expect: asking questions, following verification procedures, reporting suspicious messages; it normalises careful practice throughout the firm. Conversely, if senior staff bypass security protocols in the name of efficiency, that attitude filters down and creates the very gaps that attackers exploit.

Phishing is no longer a problem that can be solved by telling people to “look for spelling mistakes.” The threat has evolved, and the defensive posture must evolve with it. Layered technical controls, clear procedural guidance, regular and specific training, and a culture that values verification over speed; these are the hallmarks of a firm that takes its obligations seriously.

How Absolutely PC Can Help

At Absolutely PC, we work with regulated professional service firms across Bristol and the surrounding region to build, maintain and continuously improve their cyber defences. From advanced email security and multi-factor authentication to staff awareness programmes and incident response planning, we provide the layered protection that modern threats demand.

If you are not completely confident that your current security setup would catch a threat like this, or if you would like a no-obligation review of your firm’s email security and verification procedures, we are here to help. Get in touch with our team today.

What next?

One of my passions is helping businesses to succeed and if I can help you save some money as well – even better. You can fill out our contact form, phone us or click on the appointment button below and let’s start a conversation to see if I can help your business. Our guarantee:

  • There are no hidden charges – this is a 100% free 15 minute consultation with no hidden charges.
  • We will never spam you or sell on your contact details.
  • We will treat your information with absolute confidentiality.
AI, Best Practice
An illustration depicting an emergency stop concept for artificial intelligence in a business setting, representing AI governance, risk control and compliance readiness for professional firms.

How Would You Stop AI in an Emergency?

If an AI tool in your firm did something it shouldn't: sent incorrect advice, exposed client data or triggered a compliance breach; could you intervene quickly and explain what happened to a regulator? For most professional firms, the honest answer is not confidently. This post explores why AI governance is now as critical as any other risk framework in your business, and what you can do about it today.

0

Best Practice, Cyber Security
Dark background with cascading green digital code characters and bold white text asking Is Your Data less secure than you think, with the word less highlighted in orange, representing the hidden gap between perceived and actual data security in business

Is Your Data Security Keeping Pace With Your Business?

Most professional service firms believe their data security is under control — but confidence and compliance readiness are not the same thing. As cloud platforms, legacy systems and AI tools increase complexity beneath the surface, the gap between perceived security and actual governance grows. This post examines the questions every regulated firm should be asking about where data lives, who has access, and whether the answers would satisfy an auditor.

0

AI
Business professional reviewing Microsoft Copilot features on a Windows 11 screen in a professional office environment evaluating AI productivity tools for regulated firms

Is Microsoft Copilot Really the Top Productivity App in Windows 11?

Microsoft has declared Copilot the number one productivity app in Windows 11. For regulated firms handling sensitive client data and strict compliance requirements, bold marketing claims deserve careful scrutiny. Real productivity for professional services teams depends on solid foundations: organised files, reliable processes, and proper governance, not just a new AI assistant. Before adopting any tool, the smarter question is where does your team actually waste time?

0