logo

Phishers Abuse Microsoft 365 to Spoof Internal Users

ID: 5ec4adb3-aca7-51e5-acf4-a0c1bc99d869

STIX ID: report--5ec4adb3-aca7-51e5-acf4-a0c1bc99d869

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-08-06

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Cybercriminals are exploiting Microsoft 365's Direct Send feature to send unauthenticated emails that look like internal messages, allowing them to bypass SPF/DKIM/DMARC and evade Microsoft Defender and third-party secure email gateways; multiple vendors (Varonis, Barracuda, Arctic Wolf, StrongestLayer) have observed widespread campaigns delivering phishing via malicious QR-code PDFs and obfuscated HTML/SVG, primarily targeting U.S. organizations in finance, manufacturing, and healthcare. Recommended mitigations include enabling Microsoft's Reject Direct Send setting, enforcing strict DMARC, deploying header stamping for internal messages, and quarantining unmarked mail.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.