logo

Phishing Attacks Abuse Microsoft 365 to Bypass Security Filters

ID: f7397531-625e-57d9-a3db-231d939d87bf

STIX ID: report--f7397531-625e-57d9-a3db-231d939d87bf

Feed Name: KnowBe4 Blog

Threat Score
65/100

Date Published: 2025-03-20

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Researchers at Guardz report a phishing campaign that compromises multiple Microsoft 365 tenants and weaponizes the tenant display name/organization name field to insert phishing lures into legitimate-looking transaction notifications; recipients are instructed to call a fraudulent support number, enabling social engineering that leads to business email compromise, credential theft, or installation of stealer malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.