A large-scale tech support scam campaign targeting Japan sent over 13 million emails across 165 days (mid-December 2025 to May 2026), using more than 240,000 IP addresses and 33,000 disposable fake alert sites hosted on Microsoft Azure Blob Storage. The campaign evolved from generic fake security warnings to workplace-themed lures (performance reviews, salary revisions, security audits), suggesting a shift toward enterprise targets for larger financial payouts. Delivery infrastructure likely relied on hijacked IoT devices, particularly MikroTik routers. Only 11 distinct phone numbers were reused across thousands of sites. Recommended defenses include enforcing SPF/DKIM/DMARC, strengthening email gateways, restricting remote access software, monitoring outbound international calls, and employee training.