Phishing Attacks Abuse Microsoft 365 to Bypass Security Filters
ID: f7397531-625e-57d9-a3db-231d939d87bf
STIX ID: report--f7397531-625e-57d9-a3db-231d939d87bf
Feed Name: KnowBe4 Blog
Threat Score
Researchers at Guardz report a phishing campaign that compromises multiple Microsoft 365 tenants and weaponizes the tenant display name/organization name field to insert phishing lures into legitimate-looking transaction notifications; recipients are instructed to call a fraudulent support number, enabling social engineering that leads to business email compromise, credential theft, or installation of stealer malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
