logo

Holiday Phishing: Office 365

ID: a2a5719c-e0ab-553f-895f-a7f84ead4fcf

STIX ID: report--a2a5719c-e0ab-553f-895f-a7f84ead4fcf

Feed Name: TrustedSec blog

Threat Score
55/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This advisory describes seasonal phishing campaigns targeting Office 365 users—especially finance personnel—where attackers gain access (via brute force, credential phishing, password reuse, or MITM), create mailbox rules to forward or delete mail, and impersonate valid accounts to defraud customers. It recommends detection and response actions such as enabling and exporting O365 audit and mailbox logs (retain locally beyond 90 days), automating detection for failed logins and mailbox rule changes, implementing MFA and least-privilege policies, enforcing stronger password practices, and using VPNs or SOC monitoring to reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.