Microsoft 365 Admin portal abused to send sextortion emails
ID: 14ac5a47-0f97-5623-ac51-b1563c859d4f
STIX ID: report--14ac5a47-0f97-5623-ac51-b1563c859d4f
Feed Name: Bleeping Computer
Threat Score
The report details a sextortion scam campaign where attackers abused the Microsoft 365 Message Center 'Share' functionality by altering the client-side character limit to include full extortion messages, causing legitimate-looking emails (from [email protected]) to bypass spam filters; Microsoft investigated and later changed the behavior to mitigate the abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
