Invoices Following Email Hack

Sheala Browning 0 Reputation points
2026-10-02T19:05:36.68+00:00

Why did a company get invoices from Microsoft following a hack on one of the company's emails?

Microsoft 365 and Office | Subscription, account, billing | For business | Other

2 answers

Sort by: Most helpful
  1. Ryan-N 16,095 Reputation points Microsoft External Staff Moderator
    2026-10-02T19:26:43.2733333+00:00

    Hi Sheala,

    Welcome to the Microsoft Q&A forum.

    Based on your description, I understand that an email account in your company has been compromised, and your company has subsequently been receiving invoices from Microsoft.

    If I have misunderstood your situation, please provide some additional information so I can assist you more accurately and effectively.

    To better understand the issue, could you please provide the following information:

    1. Does the compromised account have an administrator role (admin role) assigned in the tenant?
    2. How many invoices have you received from Microsoft? Has your company previously used the products or services listed on these invoices, or have these charges only appeared recently?

    At the same time, I recommend that you reset the password and reset MFA for the account suspected of being compromised.

    After doing so, this account will be signed out of all devices. When signing in again, the user will be guided to create a new password and set up MFA again to help secure the account and your tenant.

    You can refer to the following documentation for instructions on how to reset a user's password and MFA in your tenant:

     Reset passwords - Microsoft 365 admin | Microsoft Learn

    Manage authentication methods for Microsoft Entra multifactor authentication - Microsoft Entra ID |…

    I hope this information is helpful.

    If you have any questions or need further assistance, please feel free to share them in the comments on this post so I can continue to support you.

    I look forward to continuing the conversation.


    If the answer is helpful, please click "Yes" and kindly upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

  2. AI answer

    2026-10-02T19:05:50.6333333+00:00

    Possible reasons include:

    • The compromised email account was the Bill To contact on a Microsoft licensing contract. Microsoft sends volume licensing invoices by email to the Bill To contact or participant named on the contract.
    • The hacked mailbox may also have had access to invoice data because invoice visibility is limited to users who are the Bill To contact or who have the Invoice Reader role.
    • If the invoices were unexpected rather than legitimate contract invoices, they may have been scam messages sent through legitimate Microsoft systems. A known pattern is that attackers create or share Azure/KQL resources so Microsoft-generated notification emails carry attacker-written content that looks like billing or payment notices.

    For a business tenant, the practical checks are:

    1. In Microsoft 365 admin center, verify whether the mailbox owner is listed as the Bill To contact under Contracts > View contract details > Contacts.
    2. Check whether that account had the Invoice Reader role.
    3. Review whether the messages were true invoices tied to an actual billing period, or notification/scam emails containing urgent payment language or phone numbers.
    4. If account compromise is suspected, run a full malware scan before changing the password, then reset the password and review account settings such as connected accounts, forwarding, and automatic replies.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.