Code of Conduct Email Scam Steals Work Sessions

An email says your employer has opened a code of conduct case. It looks like a routine compliance notice, right down to the case details and the attached PDF. The message asks you to review the material before a deadline.

For someone worried about work, ignoring it can feel riskier than clicking. That pressure was the point.

In the code of conduct email scam, the PDF did not contain an ordinary workplace case file. It was the beginning of a journey toward a sign-in request.

Sample fake code of conduct review email documented by Microsoft

Overview

The accusation makes a routine-looking email urgent

The code of conduct email scam was a broad phishing campaign, not a quarrel about a real employer policy. Microsoft’s security researchers observed it reach more than 35,000 users across more than 13,000 organizations in 26 countries between April 14 and 16, 2026.

Messages impersonated internal compliance or regulatory teams. Names such as “Internal Regulatory COC,” “Workforce Communications,” and “Team Conduct Report” were chosen to sound administrative. Some subjects said an internal case log had been opened; others said a non-compliance case required attention.

The email could include an organization name and a carefully formatted “authorized internal channel” claim. That appearance did not make it an employer communication. A criminal can type the name of your organization into a template.

The attachment is an instruction sheet, not evidence

Each message included a PDF that talked about the supposed case and offered a “Review Case Materials” link. The PDF was meant to bridge the gap between a worrying email and an external website. It did not establish that any allegation was real.

Microsoft found that the link led through a CAPTCHA and other staging pages. Those steps can feel like careful security, but a criminal can place a CAPTCHA in front of a phishing flow. Passing a challenge only shows that the page accepted your response.

  • The sender name claims internal authority.
  • The alleged conduct case creates anxiety and a deadline.
  • A PDF makes the process feel formal.
  • A “Review Case Materials” button moves the reader out of the mailbox.
  • CAPTCHA and document pages add a sense of controlled access.
  • A final sign-in flow seeks control of the work account session.

The aim is a live account session

The confirmed final stage was adversary-in-the-middle phishing, often shortened to AiTM. The attacker placed a system between the user and a genuine sign-in experience and could capture authentication tokens from that live session. That can let an attacker access an account even when the person completed a conventional multifactor prompt.

Microsoft noted that one intermediate page resembled device-code phishing, but said it could only confirm the AiTM portion of this campaign. We are not treating an unconfirmed device-code stage as a fact.

Our EvilTokens report explains a separate, confirmed device-code scam. It should not be mistaken for the conduct-case email examined here.

The 35,000 figure counts users targeted by messages, not 35,000 confirmed account takeovers. Microsoft did not publish an individual victim list or a complete number of compromised accounts in the report.

The Small Details That Make the Email Feel Official

The email did not use the usual vague line about a mailbox being full. It claimed a workplace conduct review had been logged. That is personal, potentially embarrassing, and hard to discuss with a colleague. The criminal benefits if the recipient acts alone.

Its design reinforced the story. The sample Microsoft published had boxes labeled like a case-management system, a review status, a timestamp, and instructions to open the attachment. It also claimed linked materials had been approved for secure access.

One version included a green banner invoking Paubox, a legitimate service associated with encrypted communications. That banner was a credibility cue inside the scam email, not independent proof that Paubox sent or approved the message.

The PDF added another layer. Many organizations do send policy documents as attachments, so opening it can seem less risky than following a bare link. But the dangerous step was the link inside the attachment that carried the reader into a page controlled by the campaign.

Some recipients would see a Cloudflare CAPTCHA after clicking. A familiar CAPTCHA brand can make a site feel mainstream. Here, Microsoft assessed that the challenge also helped screen out automated analysis before the later stages appeared.

After that came a page saying the document was encrypted and required authentication. The page in the second image is one of the actual intermediate screens researchers captured. Its verification code and “Review & Sign” button push the user forward without ever showing a verifiable employer case record.

The final page asked the person to schedule a discussion about the case and sign in with Microsoft. By then, several small steps had made sign-in feel like the natural next action. That is the real function of the long journey.

A legitimate HR process should have an independent route for checking it. You can open your employer’s known HR portal or ask the relevant team using a number or address already in your directory. The PDF’s button is not the only possible way to respond to a real concern.

How the Code of Conduct Email Scam Works

Step 1: A compliance notice lands in the inbox

The sender display name appears to come from an internal office. The email says a case has been logged and gives the impression that the recipient must review details promptly. The message may include the organization’s name, which makes a mass campaign feel tailored.

Microsoft traced a large wave across many employers and industries. That breadth is another reason not to read the wording as evidence that your own HR department opened a case.

Step 2: The PDF supplies the next click

The attached file provides a summary of the alleged review and a “Review Case Materials” link. The file can be opened like an ordinary PDF, which may lower suspicion. The link, however, leaves the document and starts the phishing route.

Do not assume a PDF is safe just because it does not ask you to enable a macro. A document can be used to carry a convincing link and social pressure without installing any software.

Step 3: A CAPTCHA and review page slow the reader down

The link sends the user to a site with a CAPTCHA. After the challenge, an intermediate page says a protected document needs account authentication. These stages make the flow look structured and may reduce the chance that simple scanners reach the credential stage.

The “Review & Sign” button is not an employer approval step. It is another transition. In the observed campaign, the sequence included further email and image-selection prompts before a final sign-in invitation.

Step 4: The final sign-in can hand over a session

The campaign’s last page asked users to sign in with Microsoft. Microsoft confirmed an AiTM authentication flow. In plain language, the attacker can sit in the path of an otherwise familiar sign-in and capture a token that represents a successful login.

A standard one-time code or authenticator approval may not stop this kind of attack if the person voluntarily completes it in the attacker-directed flow. That is why the best defense begins before entering credentials: verify the case independently.

Step 5: A stolen session can outlive the email

If an attacker obtains a usable session token, deleting the phishing message will not necessarily end the account risk. An organization’s security team may need to revoke sessions, review sign-ins, and inspect mailbox rules or other changes.

That does not mean every recipient was compromised. The response depends on how far you got: received the email, opened the PDF, clicked the link, entered an address, or completed the sign-in.

Intermediate fake document review page with verification code and Review and Sign button

Check the Case Without Using the Email

Do not reply to the sender to ask whether the notice is real. A reply can go to the campaign’s mailbox. Do not call a number in the PDF or enter a code because the intermediate page asks for one.

Instead, use a channel you knew before the message arrived. Open your organization’s HR or compliance portal from a saved bookmark, find the office in the internal directory, or ask your manager how formal conduct notices are delivered. You do not need to disclose the alleged accusation to an unknown website to perform that check.

If the message looks suspicious, send it to your IT or security team using the organization’s established reporting method. Forwarding it to coworkers to ask “is this real?” may spread the dangerous link. A proper report lets defenders search for similar mail and warn others.

If you work in IT, examine the full message headers and the exact attachment link in a controlled environment. A display name alone proves very little. Microsoft noted that the campaign used legitimate email delivery services and attacker-controlled domains, so routine-looking mail infrastructure did not make the sender authorized.

Be careful with generic advice to “look for HTTPS.” Phishing pages can have valid HTTPS too. The question is whether the request originated from your employer’s real process and whether the sign-in was initiated from a verified destination.

Company, Address, and Fulfillment Checks

The alleged department is not proof of identity

“Workforce Communications” or “Internal Regulatory COC” is a display name the attacker can choose. It is not a legal identity or evidence of a connection to your employer. Confirm the sender through internal channels rather than the wording of the title.

The website address is outside the case record

The PDF link led to attacker-controlled pages, not a verified employer portal. Microsoft documented several domains in the campaign, but domain names can rotate. The useful distinction is an external path introduced by the unsolicited message versus a case found in the employer’s known system.

A “support” reply can keep you in the trap

If you ask the message sender for clarification, that person can simply repeat the need to sign in. Use your company’s previously known security or HR contact. For an urgent workplace issue, a genuine team can direct you from a trusted internal directory.

No workplace case was verified by the attachment

The PDF and page only made claims. They did not prove that an actual conduct complaint existed. If your employer confirms a real case through its own process, handle it there. This report concerns the documented phishing campaign, not the merits of any real HR matter.

Why a Password Change Alone May Not Be Enough

Traditional phishing steals a password and hopes it still works. AiTM phishing can capture a token produced after the user finishes authentication. That token may represent a live session rather than a reusable password.

Changing your password is still sensible after a suspicious sign-in, but your IT team may also need to revoke active sessions or tokens. Tell them exactly what happened, including whether you approved a multifactor request or clicked “Sign in with Microsoft.”

Check for unusual mail forwarding rules, sent messages, app permissions, and sign-ins if your organization gives you access to those controls. A compromised work account can be used to reach coworkers, documents, or customers. The exact scope depends on the account’s privileges.

If you opened only the email or PDF but did not follow the link, report it and let IT assess it. Do not automatically assume your account was taken over. The observed flow required further interaction before the token-capture stage.

What to Do if You Have Fallen Victim to This Scam

  1. Tell your IT or security team immediately. Use a known internal contact, not the reply button. Say whether you opened the PDF, clicked the link, entered your address, and completed Microsoft sign-in or multifactor prompts.
  2. Ask for session revocation. If you signed in through the campaign page, have the security team end active sessions and review authentication tokens. A password change alone may not cut off a stolen live session.
  3. Reset credentials from a trusted route. Open the organization’s real account portal independently. Change the password if directed and review recovery methods and registered authenticators with IT.
  4. Check for account changes. Look for unexpected sent mail, inbox rules, forwarding, app permissions, and unusual access to files. Your security team can inspect logs that you cannot see.
  5. Preserve the evidence. Keep the email, PDF, timestamps, and screenshots. Do not forward the active link broadly; submit it through the official phishing-report channel.
  6. Scan if anything was downloaded or run. The confirmed campaign was a sign-in attack, not a documented malware installer. If you downloaded additional files, a Malwarebytes scan can help check the device, but it does not revoke stolen cloud sessions.
  7. Reduce repeat exposure. AdGuard can help block known malicious pages and advertisements, although it cannot decide whether a conduct notice is genuine. The independent HR check remains essential.
  8. Watch for follow-up approaches. An attacker may send a second message claiming to fix the case or recover access. Treat new instructions from the same sender as part of the risk until verified internally.

Frequently Asked Questions

Was the code of conduct email scam sent to many organizations?

Yes. Microsoft observed messages targeting more than 35,000 users at over 13,000 organizations in 26 countries during the April 2026 wave. Those are targets, not a count of confirmed compromised accounts.

Does opening the PDF infect my computer?

The documented PDF carried a link into the phishing flow. The report did not describe it as an installer. Opening a file and following its link are different actions; report what you actually did to your IT team.

Was the Cloudflare CAPTCHA proof that the page was safe?

No. A CAPTCHA can be used by criminals to make a page look normal and to delay automated scanners. It says nothing about whether the alleged workplace case exists.

Did Microsoft confirm device-code phishing in this campaign?

No. Microsoft said an intermediate page had some hallmarks of that technique but confirmed the AiTM part of the attack chain. That distinction matters when describing what was observed.

Can multifactor authentication still be bypassed?

A real-time AiTM flow can capture a session after a user completes some forms of multifactor authentication. Phishing-resistant methods provide better protection, but verifying the request before signing in is still important.

How can I check a genuine HR notice?

Use the HR portal or contact details your employer already gave you, preferably from an internal directory or bookmarked site. Do not use the email’s attachment link as the sole way to verify the case.

The Bottom Line

The code of conduct email scam borrowed the appearance of an internal review to lead workers into a staged sign-in. The anxiety was deliberate; the PDF and CAPTCHA were stepping stones.

Verify any alleged case through your employer’s existing channels. If you completed the sign-in, tell IT promptly so it can address the session itself, not just the password.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Fake Indeed Interview App Can Hijack Android

Next

Crypto Swap Bonus Scam Hijacks Real Checkouts