Microsoft 365 phishing and fake Outlook quota

First assess what is being requested, which channel was used and what has already happened. Do not use the received link or imposed phone number as the verification channel.

Information updated : 2026-09-10

Editorial Trust

Last update
2026-09-10
Sources checked
2026-09-17
Content status
information published with visible sources and clear limits
Official sources cited
6
Editorial responsibility
StopArnaques

StopArnaques is an independent Belgian service. It is not a public authority and does not speak on behalf of the organisations cited.

Report a correction

Why this page exists

  • A compromised email account can then be used to divert invoices and internal conversations; the login domain must be checked before entering any password.

Common situations

  • Microsoft 365 quota exceeded
  • Outlook password expires
  • mailbox storage phishing
  • Office 365 session suspended

What the fraudster is trying to obtain

  • In cases linked to the Microsoft 365 quota message, the goal is usually to make you act before you have time to check: click, pay, share a code, or open access to an account.
  • Urgency, fear of losing access, and impersonation of a known organisation are used to lower your attention. None of these elements proves the request is genuine.

Check through an independent channel

  • Do not start from the message you received. Open the official site or app yourself, or use a number already shown on a reliable document.
  • Compare the sender, the exact domain, the beneficiary and the action requested. One matching detail is not enough if the rest of the process leaves the official channel.

What to do now

  • Do not use the link you received.
  • Check with the administrator.
  • Review sessions and forwarding rules if a password has been entered.

If you have already interacted

  • Stop the exchange. Change the credentials you entered through the official app or site and enable two-factor authentication where available.
  • Contact your bank quickly if a payment, card, IBAN, code or validation is involved. Keep useful evidence for a report.

Scope of this hub

  • This hub covers fake quotas, expiry notices and Outlook or Office 365 portals.
  • Fake technical support is a separate case when control of the device is requested.

Triage and urgency level

  • Check the login domain, the administrator and the actual storage status.
  • A compromised account requires checking sessions, forwarding rules and recovery methods.

Limit of this classification

  • This hub does not confirm the identity or reliability of a contact. For this type of case, the first check remains: Check the login domain, the administrator and the actual storage status.
  • A situation may fall into more than one category. Go to the file whose risky action matches the real case: fake technical support is separate when control of the device is requested.

Limits of this page

  • This page does not prove that a message is safe and does not replace your bank, the police, Safeonweb, a platform or a public service.
  • A scam may be new, very well written or described with too little context. Use the result as decision support, not as absolute certainty.
  • Before taking a final action, checking through the official channel matters more than the appearance of the received message.

Check through an official channel

  • Type the service address yourself or open the official app. Do not use a phone number, link or QR code from the suspicious message to verify the situation.
  • When money, card details, a code or account access are involved, the safety action comes first. The analysis can then help organise the evidence.

How to read the result

  • A low number of signals does not mean that everything is safe. It only means that this page or analysis did not find decisive evidence with the information available.
  • Focus on the requested action: paying, sharing a code, installing an app, approving a bank action or leaving an official platform. That action matters more than a logo, sender name or polished wording.
  • If the situation feels urgent, step away from the received message first. Then check calmly through a channel you already trusted before the message arrived.

Belgian reading of this situation

  • For the Microsoft 365 quota message, focus on the relevant Belgian next step: open the official channel yourself, contact the bank, use Safeonweb or preserve evidence.
  • The right decision for the Microsoft 365 quota message depends on what has already happened. Reading a message is not the same as clicking, paying, sharing a code or granting remote access.

What to do now without panic

  • If the Microsoft 365 quota message worries you, choose the next step from the requested action: clicking, paying, sharing a code, installing an app, sending a document or approving account access. Do not rely only on the logo or sender name.
  • When the Microsoft 365 quota message involves an urgent, financial or hard-to-undo action, StopArnaques treats the situation as something that must be checked first. Polished wording, a familiar brand or a realistic amount does not make the request reliable by itself.
  • If you already acted in a case involving the Microsoft 365 quota message, the order matters more than the label: contact the bank, platform or official service first, preserve evidence next, then compare the situation with similar campaigns.

What can be legitimate

  • For the Microsoft 365 quota message, some notifications can be real: a delivery, invoice, administrative document, payment request, security alert or platform message. This is why this page does not claim that every similar message is automatically a scam.
  • The difference in a the Microsoft 365 quota message case is verification. A real request should be visible through the app, portal, customer area or phone number that you open yourself, not only through a link, QR code or number included in the suspicious message.
  • If the official environment does not show the same request about the Microsoft 365 quota message, amount, reference or beneficiary, it is safer to stop and report or verify the case before continuing.

Limits and responsibility

  • For the Microsoft 365 quota message, StopArnaques helps explain signals and choose safer actions, but it does not replace your bank, the police, Safeonweb, the FPS Economy, a platform or the organisation concerned.
  • A result about the Microsoft 365 quota message may remain uncertain when the text is too short, when context is missing or when the fraud uses a new variant. In that situation, slow down, verify independently and avoid any irreversible action.
  • If the Microsoft 365 quota message involves a payment, code, card, identity document, itsme approval, banking app or remote access, the protective action comes first. Do not wait for a perfect label if harm may already be possible.

Keep evidence and report

  • For the Microsoft 365 quota message, keep the message, date, channel, visible sender, neutralised link and useful screenshots. Do not publish personal data or clickable suspicious links on social media.
  • Report the Microsoft 365 quota message to the relevant channel when appropriate, for example Safeonweb for suspicious messages, the platform for account abuse and your bank when money or payment details are involved.
  • This evidence about the Microsoft 365 quota message can also help link a campaign to a case later without storing raw personal data. That matters if the system is to improve without exposing users unnecessarily.

Frequently asked questions

How can I recognise the Microsoft 365 quota message?

A compromised email account can then be used to divert invoices and internal conversations; the login domain must be checked before entering any password. Pay close attention to the action requested, the channel used, and any pressure to act quickly.

Can I check the message without opening its link?

Yes. Copy only the text, number or address shown in the detector. Do not open the link and do not scan the QR code to carry out the check.

What if the message seems to come from a real brand?

Go back to the service using your own means. The displayed name, the logo and even the apparent number can be copied. Only a check in the official channel can confirm the request.

Useful official sources

Test a SMS, email, call or link