logo
search
Suspicious Login Issues

How to Identify and Report a Microsoft Copilot Phishing Scam

Maira MehtabMaira Mehtab Sep 28, 2026 869 views

Question details

Users are receiving unexpected emails claiming to be from Microsoft Copilot support, often accompanied by the creation of support tickets, raising concerns about potential phishing or account compromise.

Product
Microsoft 365
Device & OS
not provided
Scenario
Receiving suspicious support emails or unexpected support tickets related to Microsoft Copilot.
Observed behavior
Unexpected support tickets are generated and users receive suspicious emails asking for credentials or action, indicating possible phishing, account abuse, or a compromised Microsoft 365 tenant.
Before you start

Do not click on any links, download attachments, or provide your login credentials in response to unexpected support emails, even if they reference a seemingly legitimate support ticket number.

Solution 1Recommended

Report the Suspicious Email and Secure Your Tenant

Take immediate action to report the phishing attempt to Microsoft and alert your IT administrators to investigate potential compromises in your Microsoft 365 environment.

Scammers often create real support tickets to make their phishing emails appear legitimate. Relying solely on the existence of a ticket is not enough to verify the authenticity of an email.

1
Report via Outlook Add-in

Select the suspicious email in Outlook and click the Report Message add-in on your toolbar to flag the message as phishing.

2
Report to Microsoft Directly

Open your web browser and navigate to https://microsoft.com/reportascam to officially report the scam to Microsoft's security team.

3
Notify Your Administrator

Contact your Microsoft 365 tenant administrator immediately to inform them of the phishing attempt.

4
Review Security Logs

Administrators should review tenant audit logs, recent account sign-ins, support requests, and administrator roles for any indicators of compromise or unauthorized access.

Support Tickets Do Not Guarantee Authenticity: The existence of a support ticket alone does not prove that an email is legitimate. Treat all unexpected communications requesting credentials as highly suspicious.
Free Microsoft Office alternative

Looking for a Secure and Free Alternative to Microsoft Office?

If you are concerned about cloud security issues, phishing scams, or the complexities of managing Microsoft 365, consider switching to WPS Office. It provides a highly compatible, secure, and lightweight alternative for your everyday document needs.

  1. 1. Download WPS Office: Visit the official WPS website and click the download button for your operating system.
  2. 2. Install the Software: Run the downloaded installer and follow the simple on-screen instructions.
  3. 3. Open Your Documents: Launch WPS Office and open your existing Microsoft Office files directly without losing any formatting.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats.Secure local document editing to minimize cloud-based phishing and tenant compromise risks.Lightweight design for fast startup and smooth operation.Free to use with a familiar, easy-to-navigate user interface for seamless migration.
microsoft office alternative - wps office

Frequently Asked Questions

How can I tell if a Microsoft Copilot support email is a phishing scam?

Look for unexpected requests for passwords, suspicious sender email addresses, poor grammar, or a false sense of urgency. Remember that a legitimate-looking support ticket number does not guarantee the email's authenticity.

What should I do if I already clicked a link in a phishing email?

Immediately change your Microsoft 365 passwords, ensure two-factor authentication (MFA) is enabled, and contact your IT administrator right away so they can secure your account and review audit logs for unauthorized activity.

Why would scammers create a real support ticket?

Scammers sometimes exploit automated ticketing systems to generate real ticket numbers. This tactic is used to make their phishing emails appear more credible, thereby tricking users into trusting the malicious message.