23.06.2026 - Last week, the NCSC received a higher than usual number of reports about a scam involving fake voicemail messages sent via email. The scammers imitate the design of well-known Microsoft services, aiming either to lure victims to phishing sites or to trick them into installing malware.
Scam emails claiming to contain voice messages are currently circulating in greater numbers. At first glance, they look like official notifications from Microsoft 365 or OneDrive for Business, using familiar logos and formatting to appear trustworthy. They claim that the recipient has received a new voicemail and include invented details such as the supposed date of receipt, the sender's phone number and the length of the message to make the email seem more convincing. In one particularly brazen case, the scammers even used the subject line "Death notice" to create a sense of urgency and emotional pressure, prompting recipients to open the message without thinking.
Two ways the scam works
In one version of the scam, the attackers try to trick the victim into running malware. The email has a compressed file attached to it, for example a ZIP file called "audio_Y6CEKNH8OE.zip". The criminals hope that the victim will open the attachment to listen to the supposed message inside. However, anyone who extracts and runs the file will unknowingly install malware, such as an infostealer, onto their system.
In the second version, the scammers are after the victim's passwords. The link contained in the supposed voicemail notification, or the HTML file attached to the email, leads to a professionally forged Microsoft login page. The phishing page displays what looks like an audio player, complete with a playback bar. To listen to the supposed message, victims are asked to click on a blue button labelled "Play voicemail as guest". A fake login page is then displayed in an attempt to steal the victim's Microsoft login details, such as their email address and password.
From a single case to a chain of attacks
A successful cyberattack rarely ends with just one compromised account. Stolen Microsoft 365 login details give attackers access to emails, OneDrive, SharePoint and Teams, thereby gaining access to a large part of an organisation’s internal communications. The compromised mailbox is then often used to send phishing emails to all of the victim’s contacts ("chain phishing"). As these emails appear to come from a familiar sender and often refer to existing conversations, recipients are much more likely to fall for them than they are with conventional phishing emails.
At the same time, the attackers monitor business communications. By reading these messages, they can piece together information about ongoing projects, payment arrangements, and internal hierarchies. This information can then be used for targeted CEO fraud or business email compromise (BEC). A fake payment request sent from a real employee's email address at exactly the right moment can be very difficult for the accounts department to recognise as fraudulent. If the device is infected with malware such as an infostealer, any login details, cookies or wallet information harvested by the malware may also be resold on the dark web. In some cases, this information only resurfaces weeks or months later in targeted follow-up attacks, making it harder to link them back to the original incident.
Recommendations
- Check attachments carefully. Never open unexpected ZIP attachments. Genuine voice messages or voicemails from telephone systems are usually sent as audio files, such as .wav or .mp3, rather than as ZIP archives.
- Never click on links or buttons in unexpected notifications.
- Never enter your Microsoft login details, or any other login details, on pages accessed via a link in an email.
- If your organisation uses Microsoft services (such as Teams), always check incoming voice messages directly in the official app rather than via an email notification.
Current statistics
Last week's reports by category:
Last modification 23.06.2026



