Phishing via a legitimate Microsoft address: Power BI abuse and GDPR obligations for companies

Since January 2026, a sophisticated phishing campaign has been active in which attackers send deceptive emails using the legitimate Microsoft sender address no-reply-powerbi@microsoft.com . This is technically possible due to a legitimate feature of Microsoft Power BI: when creating a dashboard, any external email address can be added as a subscriber, and the content of the automatically sent notification can be freely configured. Since the emails are actually sent through Microsoft’s infrastructure, these messages pass email authentication and security mechanisms without obstruction and are generally not detected by spam filters. For companies, this results in a multi-layered need for action: technical, organizational, and data protection-related.
Background
Microsoft Power BI is a business intelligence and analytics platform that enables dashboard subscriptions for external recipients. When a user creates a Power BI dashboard and adds external email addresses as subscribers, Microsoft automatically sends a notification email from the address no-reply-powerbi@microsoft.com . The key point is that the creator of the dashboard can freely define the content of this notification. Attackers have been systematically exploiting this mechanism since at least early 2026. They create Power BI accounts, add target email addresses as subscribers, and design the notification text to include fake payment demands (typically between 400 and 700 US dollars) as well as fraudulent support phone numbers. Victims are instructed to call these numbers to stop an allegedly unauthorized transaction (voice phishing), while the actual fraud occurs during the phone call itself. From a security perspective, this is particularly relevant: the emails show no signs of a spoofed sender address. Authentication and security mechanisms such as SPF, DKIM, and DMARC checks pass successfully, as the messages are genuinely sent from Microsoft servers. Microsoft itself recommends in its official documentation that the address no-reply-powerbi@microsoft.com be whitelisted in spam filters so that legitimate Power BI notifications are not blocked. This institutional trust is deliberately exploited in the attack. Only at the end of the email is there a small notice indicating that the message originates from a Power BI subscription notification, which is easy to overlook. This attack pattern is not entirely new: security researchers have previously documented the misuse of Power BI for phishing links, as well as similar attacks involving Google Cloud services. However, the current wave represents an escalation in sophistication, as no separate phishing links are required anymore—links that could otherwise be detected by filtering systems.
Legal and Data Protection Assessment
Technical and organizational measures
Article 32 GDPR requires controllers to ensure a level of security appropriate to the risk. In the context of this wave of attacks, companies using Microsoft 365 and Power BI are faced with two concrete questions: first, whether the configuration of Power BI—particularly regarding permissions for creating external subscriptions—is appropriately documented and restricted as a technical and organizational measure (TOM). Second, whether the use of a service provider (Microsoft), whose platform is structurally susceptible to social engineering attacks or is being actively exploited in this way, is compatible with the company’s own risk assessments.
Notification Obligations in Case of Data Breaches
If employees or customers of an organization fall victim to this phishing campaign and disclose personal data (such as login credentials or payment information), it must be assessed whether this constitutes a notifiable personal data breach under Article 33 GDPR. The 72-hour notification period to the competent supervisory authority begins as soon as the controller becomes aware of the breach.
Integrity and Confidentiality
The principle of integrity and confidentiality under Article 5(1)(f) GDPR requires that personal data be protected against unauthorized processing. If employees are tricked by this attack vector into disclosing credentials or payment information, the confidentiality of affected data sets is compromised. Organizations that have not implemented sufficient protective and awareness-raising measures risk being unable to demonstrate adequate compliance with this principle in the event of damage.
Processor Relationships and Third-Party Risk
Organizations using Microsoft 365 under a data processing agreement (DPA) must be aware that the described abuse does not constitute a data breach on Microsoft’s side, but rather an exploitation of a legitimate platform feature. Nevertheless, it should be carefully assessed whether the use of Power BI in its current default configuration is compatible with internal IT security policies. Since the emails originate from Microsoft’s legitimate infrastructure and pass all cryptographic verification checks, gateway solutions, spam filters, and reputation-based systems are structurally ineffective. Even advanced threat protection solutions such as Microsoft Defender did not initially flag these messages. The attack is technically easy to execute but difficult for recipients to recognize without prior awareness. Employees without strong IT expertise and individuals unfamiliar with Power BI notifications are particularly at risk.
Risks
Risk of data protection breaches:
Successful attacks may lead to the disclosure of access credentials, payment information, or the compromise of end devices through remote access tools – resulting in immediate GDPR notification obligations.
Reputational risk for companies:
If customers, suppliers, or business partners are entered as subscribers in an attacker-controlled dashboard using a company’s email address, they may mistakenly attribute the attack to the affected company.
Power BI configuration risk:
Companies using Power BI that grant employees permission to create external subscriptions potentially expose their own platform usage to misuse by third parties.
Recommendations for Action
Short-term: Information and employee awareness
  • Immediate communication to all employees regarding the attack vector – including specific indicators: unexpected Power BI subscription notifications, payment requests via email, and prompts to call a phone number.
  • Internal reporting procedures must be clearly communicated: employees must know where and how to report suspicious emails.
  • Internal reporting procedures must be clearly communicated: employees must know where and how to report suspicious emails.
Medium-term: Implement technical and organizational measures
  • Review Power BI tenant configuration: In the Microsoft 365 Admin Center, it is possible to control who is allowed to subscribe external recipients to Power BI reports. Restrictive configurations reduce the potential for misuse by third parties.
  • Set up email rules for no-reply-powerbi@microsoft.com: Organizations that do not actively use Power BI can route incoming emails from this address directly to quarantine or automatically warn recipients.
  • Incident response process for social engineering attacks: Ensure that your incident management also covers vishing attacks, including the assessment of whether a personal data breach under Article 33 GDPR has occurred.
  • Include in Data Protection Impact Assessment (DPIA): If Power BI is used to process personal data, the current abuse vector must be documented and evaluated within the risk analysis.
Need for consulting?
GfDDE – Gesellschaft für Datenschutz und Datensicherheit – in Europa GmbH supports you in assessing phishing incidents in the GDPR context, configuring cloud services in accordance with Article 32 GDPR, and developing GDPR-compliant incident response processes.
Sources

Ars Technica (January 2026): There’s a rash of scam spam coming from a real Microsoft address

t3n (January 2026): Echte Microsoft-Mailadresse verschickt Spam

PCWorld (January 2026): Beware! That Microsoft email is genuine, but it’s also a scam

ProArch (February 2026): Power BI Notifications Used for Phishing: Risks and User Awareness

Jennifer Stirrup / BI Expert Blog (February 2026): When Trusted Domains Betray Trust: Power BI Scam-Spam and Proactive BI Governance

Cofense Phishing Defense Center: When Data Tools Become Dangerous: MS Power BI Links Used in Phishing Campaigns

Microsoft Q&A (Community-Dokumentation des Vorfalls): Payment Successfuly processed Mail from no-reply-powerbi@microsoft.com

GDPR (Regulation (EU) 2016/679), Articles 5(1)(f), 32, 33, 34

More news

How secure is encrypted data if the key is stored in the cloud?

A report published by Forbes in January 2026 provides the first public evidence that Microsoft has handed over BitLocker recovery keys to the FBI. This was made technically possible by the default configuration of modern Windows versions, which automatically upload recovery keys to the Microsoft cloud. For companies in the DACH region, this results in an immediate need for review:

Read more…