logo

The SharePoint Share That Passed Every Check: A Compromised M365 Tenant With DMARC Reject and Tokenized Links

ID: 930daa45-4110-5d42-89b6-0559ae2872be

STIX ID: report--930daa45-4110-5d42-89b6-0559ae2872be

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: [email protected] (Audian Paxson)

...
...

A compromised Microsoft 365 tenant (packnfresh.com) was used to send authentic-looking SharePoint sharing notifications that passed SPF/DKIM/DMARC and resolved to legitimate Microsoft-hosted SharePoint links containing tokenized parameters; formatting anomalies and behavioral signals revealed the credential-harvesting phishing attempt, leading to quarantine of the mailbox and publication of IoCs and ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.