Threat Actors Exploit Misconfigurations to Spoof Internal Emails
ID: c596bacc-96ad-5b6b-b563-a6ae8a802da1
STIX ID: report--c596bacc-96ad-5b6b-b563-a6ae8a802da1
Feed Name: KnowBe4 Blog
Threat Score
Microsoft researchers observed a surge (since May 2025) of phishing attacks that abuse complex routing misconfigurations and spoof-protection errors to send emails that appear internal; actors are largely using the Tycoon2FA PhaaS and AiTM techniques to bypass MFA and harvest credentials, resulting in elevated risk of data theft, BEC, and financial loss.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
