heroui logo

Service abuse: Microsoft Power BI callback scam

Sublime Rules

View Source
Summary
This detection rule identifies potential callback scams that leverage the Microsoft Power BI email service to distribute fraudulent solicitations. The rule specifically looks for inbound email communications where the sender's email is identified as 'no-reply-powerbi@microsoft.com'. It utilizes a combination of natural language understanding (NLU) techniques to analyze the body of the email for certain intents indicative of a callback scam, tagging them with a medium severity level. The rule employs sender analysis and content evaluation to flag potentially malicious interactions, leveraging machine learning classifiers to filter out legitimate communications from those that may attempt to manipulate users into sharing sensitive information or making fraudulently induced phone calls.
Categories
  • Cloud
  • Web
  • Identity Management
Data Sources
  • User Account
  • Application Log
  • Service
Created: 2026-01-23