logo

Malicious Connectors Potentially Impact Hundreds of Millions of Microsoft 365 Users

ID: f526f21c-9001-5a79-84a4-d289e7ba8bc2

STIX ID: report--f526f21c-9001-5a79-84a4-d289e7ba8bc2

Feed Name: KnowBe4 Blog

Date Published: 2025-07-31

Date Updated: 2026-04-28

Author: Roger Grimes

...
...

The report warns that attackers are increasingly abusing Microsoft 365 Outlook rules, forms, and Exchange connectors to maintain persistence, conceal activity, and facilitate payment fraud after account compromise—often via adversary-in-the-middle phishing that steals session cookies despite MFA. It highlights that these server-side connectors are easy to miss, persist across password changes, and are now common enough that Microsoft provides specific guidance; it includes steps to locate and review connectors, recommends enabling phishing-resistant MFA (e.g., FIDO), monitoring for creation/modification of rules/forms/connectors, and watching for anomalies like mismatched 5321.MailFrom and 5322.From in headers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.