{"id":403723,"date":"2026-08-19T18:28:56","date_gmt":"2026-08-19T18:28:56","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=403723"},"modified":"2026-08-19T18:28:56","modified_gmt":"2026-08-19T18:28:56","slug":"accountant-voicemail-exposed-fake-microsoft-365-play-button","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/accountant-voicemail-exposed-fake-microsoft-365-play-button\/","title":{"rendered":"Accountant Voicemail EXPOSED: Fake Microsoft 365 Play Button"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The subject is already doing the work. New voicemail from Accountant. You open it because tax season never really ends, because payroll is due, because the person who handles your books does not usually leave a 1 min, 12 sec message unless something is off. The card in the mail looks like Microsoft 365. There is a blue button that says PLAY VOICEMAIL. The date on the lure is 17 August 2026.<\/p><div id=\"mwtad3392942385\" class=\"gas_fallback-ad_309684--placement_400588\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<figure class=\"wp-block-image size-full mt-screenshot\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/accountant-voicemail-email.png\" alt=\"Fake Microsoft 365 voicemail email with a Play Voicemail button from Accountant dated 17 August 2026\" class=\"wp-image-403724\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/accountant-voicemail-email.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/accountant-voicemail-email-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/accountant-voicemail-email-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><figcaption class=\"wp-element-caption\">How the fake accountant voicemail is built. The Play button is the trap.<\/figcaption><\/figure>\n\n\n\n<div id=\"mwtad789756086\" class=\"gas_fallback-ad_309747-ad_309691-placement_400589\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The trap is a fake Microsoft 365 voicemail card that uses an accountant as the caller so you will click Play before you think. The subject reads New voicemail from Accountant. The body says your accountant left you a voicemail. The duration is printed as 1 min, 12 sec. The caller line says Accountant. The date stamped on the lure is 17 August 2026. None of those details is a file you can take to a real bookkeeper.<\/p>\n\n\n\n<div id=\"mwtad2246716491\" class=\"mwtadp1 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"> \r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"7312657698\"><\/ins>\r\n <\/div><p class=\"wp-block-paragraph\">Microsoft is real. People sign in to Outlook, Teams, OneDrive, and Word every morning on Microsoft 365. That is the point of the costume. A brand you already trust is doing the letterhead. A job title you already fear missing is doing the urgency. The Play button is doing the theft.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What they want is the Microsoft password, and often the extra code that lands on your phone a few seconds later. After that they want the inbox. An accountant lure is not random. The mailbox they are trying to wear is the one that sees invoices, tax packets, payroll files, and the &#8220;please pay this today&#8221; thread. Once they can send mail as you, the next victim is the person who already trusts your name.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The Microsoft 365 costume<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The email is built to look like a product notice, not a letter from a stranger. A heading that simply says Voicemail. A timestamp. A short line of text. A wide blue button. A small Microsoft 365 mark at the bottom. If you are already inside Outlook on the web, the bars around the message do half the selling. It feels like office mail because you are standing in office mail.<\/p>\n\n\n\n<div id=\"mwtad2434516198\" class=\"gas_fallback-ad_309686-ad_309691-placement_400597\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p class=\"wp-block-paragraph\">Display names are cheap. Anyone can set a From line to read Microsoft 365 Voicemail. Microsoft&#8217;s own <a href=\"https:\/\/support.microsoft.com\/en-us\/windows\/protect-yourself-from-phishing-0c7ea947-ba98-3bd9-7184-430e1f860a44\" target=\"_blank\" rel=\"noopener\">guide to spotting phishing<\/a> tells you to treat mismatched email domains as a warning. A message that wears Microsoft&#8217;s name and arrives from a lookalike alerts address is not Microsoft talking to you. It is someone using the name because the name works.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Real Cloud Voicemail exists. Microsoft documents how to <a href=\"https:\/\/support.microsoft.com\/en-us\/teams\/calls-devices\/check-your-voicemail-in-microsoft-teams\" target=\"_blank\" rel=\"noopener\">check voicemail in Microsoft Teams<\/a>: you open Calls, then History, then Voicemail, and you listen there. You do not need a surprise card in the inbox to &#8220;unlock&#8221; audio with a fresh sign-in. If you want to know whether a real message is waiting, you open Teams or Outlook yourself. You do not let a blue button choose the website.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The accountant on the caller line<\/h3>\n\n\n\n<div id=\"mwtad1178346815\" class=\"mwtadp3 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"5910219726\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p class=\"wp-block-paragraph\">Caller: Accountant. That one word is doing more work than the Microsoft logo. An accountant is the person who can make a quiet Monday expensive. A missed call from that desk can mean a filing, a payroll run, a vendor who will not ship, a number the IRS already has and you do not. You do not need a long story when the job title already carries the bill.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The lure does not even bother with a first name. It does not say Maria from the firm. It does not name the practice. It says Accountant the way a system log would, as if a phone system tagged the call and moved on. That vagueness is useful. If your books are handled by a CPA, you fill in the face. If you are the person at work who pays invoices, you fill in the vendor. If you do not have an accountant at all, the word still sounds like money, and money still makes you click.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">1 min, 12 sec is part of the same trick. A duration that specific feels like a real recording. It is long enough to be a problem and short enough to be &#8220;just a listen.&#8221; You tell yourself you will play it, get the number, and call back. The page never intended to give you audio. It intended to give you a login box while that story is still in your head.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The Play button<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">PLAY VOICEMAIL sits in the middle of the card like a player control. That is why people press it. It does not look like &#8220;Sign in to your account.&#8221; It does not look like &#8220;Reset your password.&#8221; It looks like the one thing you came to do. Hear the message. Then get back to work.<\/p><div id=\"mwtad2377222226\" class=\"mwtadp4 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"5910219726\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">A voicemail notification should play audio, or it should take you into the app you already use. Microsoft&#8217;s phishing page is blunt about urgent buttons. Slow down when a message says you must click now. The accountant card is built so you will not. Tax, payroll, a missed call, and a timer under the button are there so you feel late before you have even hovered.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is no honest reason for a Microsoft-looking voicemail player to live on a surprise page you reached from an unexpected email. If the recording were real, it would already be sitting in Teams or in Outlook. The Play button is not a player. It is a door.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The login that is not Microsoft<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After Play, the next screen is often a sign-in page that borrows Microsoft&#8217;s layout. Your work email may already be sitting in the box. The logo looks familiar. The language is the language you see every morning. The address bar is the part they hope you do not read. Do not copy that address to look it up later. Those pages move, and a copied link is how the next person gets hurt. The habit is the tell. A voicemail that demands a Microsoft password is not a voicemail.<\/p>\n\n\n\n<div id=\"mwtad3787519604\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p class=\"wp-block-paragraph\">Microsoft&#8217;s support page says it plainly. If you worry a message might be real, open a new tab and go to the organization yourself. Type the official site. Use a saved favorite. Do not let the email choose the page. For Microsoft 365, that means opening <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\" target=\"_blank\" rel=\"noopener\">Microsoft 365<\/a>, Outlook, or Teams the way you always do, not through a Play button in a stranger&#8217;s card.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/consumer.ftc.gov\/articles\/how-recognize-and-avoid-phishing-scams\" target=\"_blank\" rel=\"noopener\">FTC&#8217;s phishing guide<\/a> describes the same story from the other side. A message that looks like a company you know. A problem you need to fix. A link that wants a password or a payment. The accountant voicemail is that story with a headset on. The Federal Trade Commission also says that if you already typed something, you treat it as lost information and you move, you do not wait to see if audio ever loads.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What they take after you type<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The first prize is the password. The second prize is the extra code, the app prompt, or the &#8220;Are you trying to sign in?&#8221; tap that lands while you are still staring at a page that looks like work. If you approve that prompt because you think you are unlocking a 72-second recording, you have handed them the second key. Microsoft and the FTC both treat that code as a key, not as a courtesy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After a sign-in, the mailbox is the office. They can read the threads you have with the real accountant. They can see who pays you, who you pay, and which invoice is already late. They can set a forwarding rule so a copy of every new message leaves with them. They can hide that rule in a folder you never open. They can send a new bill from your address that looks like last month&#8217;s bill, except the account number changed.<\/p>\n\n\n\n<div id=\"mwtad3275365701\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p class=\"wp-block-paragraph\">That is why the caller is Accountant and not a random first name. The lure is picking a desk that sits next to money. A compromised work inbox is not a nuisance. It is a way to move a payment without ever calling you again. If the account is a personal Microsoft account, they still get the mail that resets your bank, your tax software, and the other logins you tied to that address.<\/p>\n\n\n\n<div id=\"mwtad748563779\" class=\"gas_fallback-ad_309748-ad_309691-placement_400590\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">How The Scam Works<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">1. The email lands like office mail<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It arrives in the same Outlook you already trust. The display name says Microsoft 365 Voicemail. The subject is New voicemail from Accountant. There is no long pitch and no attachment you have to open. The whole card fits on a phone screen. That is on purpose. A short notice is easier to believe than a letter that asks for a Social Security number in the first line.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you are already signed in to Outlook on the web, the folders on the left and the search bar on the top make the fake card feel native. You are not visiting a strange site yet. You are reading mail. The costume only has to survive the three seconds between the subject and the button.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. The accountant name makes you hurry<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You do not get a novel. You get a job title and a clock. Your accountant left you a voicemail. 17 August 2026. 1 min, 12 sec. Caller: Accountant. Those lines are enough to invent the rest. A missed extension. A payroll question. A return that needs a signature before the window closes. People who would ignore a &#8220;Your account will be closed&#8221; threat will still press Play for a bookkeeper.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The date on this lure is part of that hurry. 17 August 2026 sits close enough to the present that it does not look like leftover spam from last year. It looks like this morning. A timestamp with seconds is there so the notice feels logged, not written.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Play does not play a recording<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You click PLAY VOICEMAIL because that is what a player is for. The click is the moment the costume can drop. The next page is not an audio bar. It is a sign-in, a &#8220;verify it is you&#8221; wall, or a short hop that still ends at a password box. There is no transcript. There is no callback number from a firm you recognize. There is a request for the same credentials you use to open the inbox you are already sitting in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That request is the tell. You are already in Outlook. A real voicemail would play, or it would open Teams. It would not ask you to prove you are you so you can hear 72 seconds of audio from &#8220;Accountant.&#8221; Microsoft&#8217;s own Teams page puts playback inside the app. The email button is a detour.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. A Microsoft-looking sign-in asks for you<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The page that follows is often dressed as Microsoft. It may use the same blue, the same word Sign in, the same field for the work address. It may say the voicemail is protected and that you need to authenticate to play it. That sentence is the whole product. There is no protected recording. There is a form.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do not finish that form to &#8220;see if it is real.&#8221; A fake login does not become safer because you only wanted audio. Type the official Microsoft site in a new tab if you need to check the account. Open the <a href=\"https:\/\/account.microsoft.com\/security\" target=\"_blank\" rel=\"noopener\">Microsoft account security page<\/a> yourself. Leave the Play tab alone. Close it. The address in that tab is not a clue you need to collect. It is a door you should stop using.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. The password and the code leave with them<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you type the password, they have the first key. If a text, an authenticator prompt, or an email code arrives while that tab is still open, they want the second key too. The story will be helpful. Confirm so the file can play. Approve so the secure voicemail can load. Enter the code to verify your work account. Each line is the same request. Access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft&#8217;s phishing page tells you to change the password on every affected account if you think you typed it on the wrong site, and to turn on multifactor authentication if it is not already on. The FTC says the same thing in consumer language. Treat the password as burned. Treat the code as burned. Do not reuse either one on the next page that promises to &#8220;unlock&#8221; the recording.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6. Your inbox becomes their desk<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Once they can open the account, they are not hunting for a 72-second clip. They are hunting for money that already has your name on it. They read the last invoice you sent. They read the last invoice you received. They look for a thread with the real accountant, a payroll vendor, a bank, a client who pays by wire. Then they write the next message in your voice.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A bill that looks like last month&#8217;s bill is enough. A &#8220;new account, same firm&#8221; line is enough. A request to re-send a W-9, a voided check, or a routing number is enough. If they add a forwarding rule, they can keep a copy after you change the password, until someone deletes the rule. If they add a hidden folder, the replies that would have warned you never reach the inbox you still think you own.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">7. The next message goes out as you<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The last move is social. They have your From line. They have your threads. They can write to the real accountant as you, or to your clients as the accountant&#8217;s office, or to payroll as the person who always approves the file. The first email was a costume of Microsoft. The second email is a costume of you.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is why a quiet &#8220;I already clicked, but I did not pay anyone&#8221; is not the end of the story. You may not have paid. The person who trusts you might. Tell the people who send you money and the people you pay. Tell the real accountant on a number you already have, not on a number that arrived after Play. A 30-second call from you is cheaper than a week of wires that look like your week.<\/p>\n\n\n\n<div id=\"mwtad3342867679\" class=\"gas_fallback-ad_309749-ad_309691-placement_400591\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5354318971\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">What To Do If You Already Clicked Play<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you only opened the email and closed it, you are not finished, but you are not doomed. If you pressed Play and then typed, treat the account as touched and move in this order.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Write down what you typed, then stop using that tab.<\/strong> Note the time, the subject New voicemail from Accountant, whether you entered a password, and whether you approved a code or an app prompt. Close the Play page. Do not keep &#8220;checking&#8221; it to see if audio appears.<\/li>\n<li><strong>Open Microsoft yourself and change the password.<\/strong> Use a new browser tab. Type the official site, or use the app you already trust. Follow Microsoft&#8217;s steps to <a href=\"https:\/\/support.microsoft.com\/en-us\/office\/my-outlook-com-account-has-been-hacked-35993ac5-ac2f-494e-aacb-5232dda453d8\" target=\"_blank\" rel=\"noopener\">recover a hacked or compromised Microsoft account<\/a>. Pick a password you have not used on anything else. If you cannot sign in, use the official reset path, not a link from the voicemail card.<\/li>\n<li><strong>Sign out everywhere and turn the extra lock back on.<\/strong> On the <a href=\"https:\/\/account.microsoft.com\/security\" target=\"_blank\" rel=\"noopener\">Microsoft account security page<\/a>, review recent activity and sign out of other sessions if that control is there. Confirm multifactor authentication is on. If you approved a prompt you did not start, assume that session is not yours until you kill it.<\/li>\n<li><strong>Look for rules, forwarding, and mail that left without you.<\/strong> Check inbox rules, automatic forwarding, and the Sent folder. Look for a new mailbox delegate, a new app that can read mail, or a filter that hides replies. Delete what you did not create. If this is a work account, call IT before you spend an hour hunting. They can dump sessions and pull the audit faster than you can.<\/li>\n<li><strong>Call the real accountant and the people who pay you.<\/strong> Use a number from a last year&#8217;s invoice, a card in the drawer, or a listing you already trust. Tell them a fake Microsoft 365 voicemail tried to take the mailbox, and that they should not honor a new account number or a rushed &#8220;updated wiring&#8221; note that arrives this week. If you handle payroll, say that out loud. The lure picked that word for a reason.<\/li>\n<li><strong>Tell the bank if the mailbox sits next to money.<\/strong> If invoices, payroll, or tax software live in that inbox, call the bank and any payroll vendor the same day. Ask them to watch for a change-of-account request. A charge you did not make and a transfer you approved because &#8220;you&#8221; asked for it are different problems. Time still matters on both.<\/li>\n<li><strong>Report the email, then scan the device if you downloaded anything.<\/strong> In Outlook, use Report and then Report phishing, the path Microsoft publishes on its <a href=\"https:\/\/support.microsoft.com\/en-us\/windows\/protect-yourself-from-phishing-0c7ea947-ba98-3bd9-7184-430e1f860a44\" target=\"_blank\" rel=\"noopener\">phishing help page<\/a>. Forward a copy to the Anti-Phishing Working Group at reportphishing@apwg.org. File at <a href=\"https:\/\/reportfraud.ftc.gov\/\" target=\"_blank\" rel=\"noopener\">the FTC fraud report form<\/a>. If a password, a bank account, or a Social Security number went into that page, use <a href=\"https:\/\/www.identitytheft.gov\/\" target=\"_blank\" rel=\"noopener\">the government&#8217;s identity theft site<\/a> for the next steps. If Play saved a file or pushed a player, run a full scan with <strong>Malwarebytes<\/strong> or the antivirus you already keep updated. The scan does not get a password back. The password change does that.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">If someone forwarded you the card, send them this page instead of the Play button. These notices travel in office threads because they look like work. That is part of how they move.<\/p>\n\n\n\n<div id=\"mwtad694119017\" class=\"gas_fallback-ad_309750-ad_309691-placement_400592\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4041237300\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">The Bottom Line<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A card that says New voicemail from Accountant, stamps 17 August 2026, prints 1 min, 12 sec, and offers PLAY VOICEMAIL is not a recording from the person who does your books. It is a Microsoft 365 costume with a login behind the button. Microsoft is real. The Play button is not how you reach Microsoft.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open Teams or Outlook yourself if you need to know whether a real message is waiting. Call the accountant on a number you already have. If you already typed the password, change it on Microsoft&#8217;s own page, kill the other sessions, and tell the people who send you money before the next email goes out as you. The audio was never the point. The inbox was.<\/p>\n\n\n<div id=\"mwtad2202855919\" class=\"gas_fallback-ad_176819-ad_309691-placement_400595\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A fake Microsoft 365 voicemail card uses an Accountant caller and a PLAY VOICEMAIL button to push a lookalike login. Microsoft is real. The Play button is the trap.<\/p>\n","protected":false},"author":51,"featured_media":403724,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2840,49],"tags":[],"class_list":["post-403723","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-product-scams","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/403723","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=403723"}],"version-history":[{"count":2,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/403723\/revisions"}],"predecessor-version":[{"id":403814,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/403723\/revisions\/403814"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/403724"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=403723"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=403723"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=403723"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}