Microsoft creates fake Azure tenants to pull phishers into honeypots
ID: 40ebe0e3-733e-5ce0-8d4d-8ae54fa90718
STIX ID: report--40ebe0e3-733e-5ce0-8d4d-8ae54fa90718
Feed Name: Bleeping Computer
Microsoft operates a deception program that spins up realistic Azure tenant honeypots (custom domains, ~20k user accounts) and actively submits credentials to phishing sites to lure attackers in; when adversaries log in (about 5% of seeded sites), Microsoft logs detailed activity (IPs, browsers, behavior, phishing kits) to map infrastructure, attribute actors, and improve Defender protections, claiming thousands of blocked connections and an ability to waste attackers' time while gathering intelligence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
