logo

Phishing Emails Use New Technique to Bypass Microsoft 365 Security Filters

ID: a8b26a0f-7ee7-5da6-ae56-9b393c6863ed

STIX ID: report--a8b26a0f-7ee7-5da6-ae56-9b393c6863ed

Feed Name: KnowBe4 Blog

Threat Score
65/100

Date Published: 2026-09-15

Date Updated: 2026-09-16

Author: KnowBe4 Team

...
...

ReliaQuest researchers observed threat actors sending phishing emails with an empty SMTP sender field to bypass Microsoft 365's RejectDirectSend protection so spoofed internal addresses can reach inboxes; attackers targeted executives and finance-facing staff with familiar business-themed lures and SVG attachments to facilitate fraudulent payments and sensitive-data theft, and defenders are advised to treat allow-listing exceptions as high-risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.