Decade-old fake Microsoft domain resurfaces in ‘typosquatting’ scam


This recording was made using enhanced software.

Summary

Phishing comeback

A fake Microsoft domain using “rn” instead of “m” is back online, fooling users with password reset scams that look authentic.

Repeat offender

The domain’s registered owner, Park HyungJin, has been tied to multiple cybersquatting disputes, including a 2019 WIPO case over a stolen cybersecurity site.

CISA warning

CISA says most victims click or reply within minutes of receiving fake emails.


Full story

A fake Microsoft email domain is making the rounds again, tricking users into clicking password reset links that look legitimate. The phishing campaign uses the domain “rnicrosoft.com,” swapping the letters “r” and “n” to resemble the real “m” in Microsoft’s name.

The scheme relies on ‘typosquatting,’ a tactic where scammers register domain names that look almost identical to real ones. According to the Cybersecurity and Infrastructure Security Agency, 70% of all attached files or links in phishing emails containing malware were not blocked by network protection systems. 

A familiar domain returns

Public domain records show rnicrosoft.com has existed for more than a decade. It was first registered in 2012 under Park HyungJin based in South Korea and is currently set to expire in March 2026.

Users on Reddit and LinkedIn say the domain reappears every few years, often with the same email design that mimics real Microsoft password reset messages. The layout, tone and timing are all engineered to look authentic.

QR code for SAN app download

Download the SAN app today to stay up-to-date with Unbiased. Straight Facts™.

Point phone camera here

Tied to past cybersquatting disputes

Park HyungJin’s name also appears in multiple domain disputes filed with the World Intellectual Property Organization.

Unbiased. Straight Facts.TM

Phishing was the cybercrime most frequently reported to the FBI in 2024, with 193,407 complaints.

In one 2019 case, a Swiss cybersecurity company called WISeKey SA accused Park of taking over its domain name wisekey.net. The company said the registration was done in bad faith to exploit WISeKey’s existing trademark.

The WIPO panel agreed, finding that Park had “no legitimate interest” in the name and had registered it with intent to mislead users. The panel ordered the domain to be transferred back to WISeKey.

WIPO records show Park has been listed in at least a dozen similar cases over the years, often involving domains that mimic well-known brands. 

Phishing vs spam

Technology company Cisco defines phishing as “fraudulent communications that appear to come from a reputable source.” These messages often trick people into sharing passwords, payment information or other sensitive data.

By contrast, spam usually refers to unsolicited or irrelevant junk email. While spam clutters inboxes, phishing attempts are far more dangerous because they aim to steal personal information or install malware. Both types of email should be reported.

How phishing scams succeed

Perhaps the most alarming statistic from CISA was that 84% of employees took the bait within the first ten minutes of receiving a phishing email often by clicking a spoofed link or replying with sensitive information. Only 13% reported the phishing attempt, limiting their organization’s ability to respond quickly.

The Federal Trade Commission (FTC) and CISA recommend simple but effective steps to protect yourself:

  • Expand the full sender address before clicking any links.
  • Hover over links to see where they actually lead.
  • Don’t share personal information from an email you didn’t expect.
  • Be skeptical of urgency, such as “password reset” or “account suspended” alerts.

If you didn’t request the action mentioned in the email, ignore it and report it — especially if it’s sent to a work address. However, if you suspect a scammer has any sensitive information from a response to an email, visit IdentityTheft.gov.

For more resources, visit the FTC’s guide on how to recognize and avoid phishing scams.

Alex Delia (Deputy Managing Editor) and Ally Heath (Senior Digital Producer) contributed to this report.
Tags: ,

SAN provides
Unbiased. Straight Facts.

Don’t just take our word for it.


Certified balanced reporting

According to media bias experts at AllSides

AllSides Certified Balanced May 2025

Transparent and credible

Awarded a perfect reliability rating from NewsGuard

100/100

Welcome back to trustworthy journalism.

Find out more

Why this story matters

This story highlights an ongoing cybersecurity threat where scammers use deceptive domains to imitate trusted brands like Microsoft, exposing individuals and organizations to significant risks from phishing attacks.

Phishing tactics

The story demonstrates how attackers use techniques like typosquatting and carefully crafted emails to trick users into revealing sensitive information or clicking malicious links.

Vulnerability to scams

According to the Cybersecurity and Infrastructure Security Agency, many users and systems fail to detect or report phishing attempts, leading to successful attacks and data breaches.

Prevention and awareness

Guidance from agencies like the Federal Trade Commission and CISA emphasizes vigilance, reporting, and education as critical steps for individuals and organizations to protect themselves from phishing and similar scams.

SAN provides
Unbiased. Straight Facts.

Don’t just take our word for it.


Certified balanced reporting

According to media bias experts at AllSides

AllSides Certified Balanced May 2025

Transparent and credible

Awarded a perfect reliability rating from NewsGuard

100/100

Welcome back to trustworthy journalism.

Find out more

Daily Newsletter

Start your day with fact-based news

Start your day with fact-based news

Learn more about our emails. Unsubscribe anytime.

By entering your email, you agree to the Terms and Conditions and acknowledge the Privacy Policy.