SCAM: YES

Risk:High — Attackers are targeting Microsoft 365 and Signal accounts to seize business communications, impersonate trusted users and enable fraudulent transfers.

Install the app:Open the app and verify suspicious content in one scan.

Account Takeover Threats Hitting Small Businesses

A message arrives claiming that your Signal account needs verification. It directs you to a page that says, “Enter the verification code sent to your Signal account” or asks for your account PIN. That information does not verify your identity to a colleague—it can help an attacker take over the account. For a sole trader or small firm, the compromised profile may then appear credible when discussing invoices, customer data or payments.

Two account takeover themes

Current public threat intelligence identifies a broad campaign against Microsoft Entra ID and Microsoft 365 using TeamFiltration, password spraying and HTTP client tools. Password spraying tests commonly used passwords across multiple accounts, while automated HTTP clients can generate sign-in activity outside normal interactive browser use. A separate campaign linked to Russian intelligence targets commercial messaging apps such as Signal. Its phishing attempts manipulate victims into disclosing verification codes or account PINs. These themes can place both sides of a small company’s communications at risk: Microsoft 365 may hold email and administrator access, while Signal may contain trusted conversations with staff, customers or suppliers.

Why small firms are exposed

One compromised administrator account can affect several mailboxes or business services. A stolen messaging identity can also preserve the tone and context of an existing conversation, making a later payment request appear genuine. Before any transfer, verify the request through a previously known phone number or an established approval process. Do not use contact details supplied in the message being checked.

Break the takeover sequence

  1. Never disclose a Signal verification code or PIN in response to a message or linked page.
  2. Review Microsoft Entra sign-in records for password spraying, repeated failures across accounts and HTTP client activity.
  3. Revoke suspicious sessions and reset affected credentials from a trusted device.
  4. Protect administrator accounts with strong, unique passwords and multifactor authentication.
  5. Pause payment or bank-detail changes until a second authorized person confirms them independently.

Most common warning signals

What to do now

  1. Stop any transfer connected to an unexpected message or account change.
  2. Do not share Signal verification codes or account PINs with anyone.
  3. Revoke suspicious Microsoft 365 sessions and reset affected passwords from a trusted device.
  4. Review Microsoft Entra sign-in records for password spraying and automated HTTP client activity.
  5. Check Signal linked devices and remove any device you do not recognize.
  6. Require independent confirmation for payment and bank-detail changes.

Install ScamBuster AI

Open the app and verify suspicious content in one scan.

Install ScamBuster AI

Sources

Further reading

FAQ

What should I do if a page asks for my Signal code?

Do not enter the code or PIN. Close the page, check Signal directly, review linked devices and remove any device you do not recognize.

How can I spot Microsoft 365 password spraying?

Password spraying commonly appears as failed sign-ins spread across multiple accounts rather than repeated attempts against only one user. Review Entra sign-in records and investigate unexpected HTTP client activity.

Can I trust a payment request from a compromised Signal account?

No. Treat messages from the account as untrusted until the owner confirms control through a previously known contact method, especially if money or changed bank details are involved.