logo

Phishers Exploit Office 365 Users Who Let Their Guard Down

ID: e3393b48-7a91-5038-b0f8-40529e666e09

STIX ID: report--e3393b48-7a91-5038-b0f8-40529e666e09

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-01-07

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Microsoft Threat Intelligence reports an increase in phishing campaigns that spoof organization domains in Office 365 by abusing complex routing and misconfigured spoof protections; attackers, including those using PhaaS platforms like Tycoon2FA, deliver credential-stealing and BEC-style lures. Microsoft recommends enforcing strict DMARC/SPF, properly configuring third-party connectors, and adopting phishing-resistant MFA to mitigate these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.