logo

Hackers Exploit Routing Misconfigurations to Successfully Spoof Organizations

ID: 97eff284-2d14-51f2-b639-fcde68a0777f

STIX ID: report--97eff284-2d14-51f2-b639-fcde68a0777f

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Microsoft Threat Intelligence reports a widespread phishing and domain-spoofing campaign (active since May 2025) that abuses complex mail routing and misconfigured DMARC/SPF to make emails appear internal; threat actors are using the Tycoon2FA PhaaS and AiTM techniques to steal credentials and execute financial invoice fraud, with Microsoft Defender blocking millions of related messages and recommending strict DMARC/SPF policies, connector hardening, ZAP, Safe Links, and phishing-resistant MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.