Holiday Phishing: Office 365
ID: a2a5719c-e0ab-553f-895f-a7f84ead4fcf
STIX ID: report--a2a5719c-e0ab-553f-895f-a7f84ead4fcf
Feed Name: TrustedSec blog
This advisory describes seasonal phishing campaigns targeting Office 365 users—especially finance personnel—where attackers gain access (via brute force, credential phishing, password reuse, or MITM), create mailbox rules to forward or delete mail, and impersonate valid accounts to defraud customers. It recommends detection and response actions such as enabling and exporting O365 audit and mailbox logs (retain locally beyond 90 days), automating detection for failed logins and mailbox rule changes, implementing MFA and least-privilege policies, enforcing stronger password practices, and using VPNs or SOC monitoring to reduce risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
