Microsoft 365 features that help users manage their subscriptions, account settings, and billing information.
Possible reasons include:
- The compromised email account was the Bill To contact on a Microsoft licensing contract. Microsoft sends volume licensing invoices by email to the Bill To contact or participant named on the contract.
- The hacked mailbox may also have had access to invoice data because invoice visibility is limited to users who are the Bill To contact or who have the Invoice Reader role.
- If the invoices were unexpected rather than legitimate contract invoices, they may have been scam messages sent through legitimate Microsoft systems. A known pattern is that attackers create or share Azure/KQL resources so Microsoft-generated notification emails carry attacker-written content that looks like billing or payment notices.
For a business tenant, the practical checks are:
- In Microsoft 365 admin center, verify whether the mailbox owner is listed as the Bill To contact under Contracts > View contract details > Contacts.
- Check whether that account had the Invoice Reader role.
- Review whether the messages were true invoices tied to an actual billing period, or notification/scam emails containing urgent payment language or phone numbers.
- If account compromise is suspected, run a full malware scan before changing the password, then reset the password and review account settings such as connected accounts, forwarding, and automatic replies.