I've seen those emails, but how does the scam work, anyways? They don't actually have access to your bank account so do they somehow talk the target of the scam into actually giving them that information?
Both people who replied had an email domain at a specific business. Apart from that, I have no idea. What you said is probably right.
"Please to be doing the needful and refunding your money now, valued customer. For security purposes please confirm your bank account and routing number. Sincerely, Microsoft" 😂