logo

Crims compromised energy firms' Microsoft accounts, sent 600 phishing emails

ID: 71b6e24e-b6c3-5615-bfd6-5d7f0b952bb2

STIX ID: report--71b6e24e-b6c3-5615-bfd6-5d7f0b952bb2

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-01-22

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft observed a multi-stage phishing campaign targeting energy-sector organizations where attackers used previously compromised addresses to send SharePoint links that prompt users to enter credentials, enabling account takeover. Compromised accounts were used to create inbox rules (deleting/marking messages), monitor and respond to replies, and send hundreds of follow-on phishing emails to internal and external contacts; attackers also employed MFA tampering and persistence techniques, making simple password resets insufficient.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.