logo

Surge in Phishing Attacks Hijacking Legitimate Microsoft Communications

ID: ad0de5ed-4042-5265-aedc-fa2e818bd88d

STIX ID: report--ad0de5ed-4042-5265-aedc-fa2e818bd88d

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2025-03-27

Date Updated: 2026-04-28

Author: KnowBe4 Threat Lab

...
...

KnowBe4 Threat Labs observed a large phishing campaign (peaking at ~7,000 messages in a 30-minute window) that abused legitimate Microsoft tenancies and mailflow rules to forward real Microsoft invoice emails containing a maliciously crafted "account name" message asking recipients to call a fraudulently provided phone number. By embedding the social-engineered payload in an organization name and using onmicrosoft.com domains, attackers preserved SPF/DKIM/DMARC authentication to increase deliverability and evade standard defenses; KnowBe4 Defend detected the attack via recipient/address mismatches and linguistic anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.