Microsoft 365 'Direct Send' abused to send phishing as internal users
ID: af543b53-8acc-5110-99d2-8c36ccc0251d
STIX ID: report--af543b53-8acc-5110-99d2-8c36ccc0251d
Feed Name: Bleeping Computer
A phishing campaign discovered in May 2025 is abusing Microsoft 365's Direct Send feature to relay unauthenticated, internal‑looking emails through organizations' smart hosts, bypassing SPF/DKIM/DMARC and delivering branded PDF attachments with QR codes that lead to credential‑harvesting pages; over 70 organizations (mostly in the US) across financial services, manufacturing, construction/engineering, healthcare, and insurance have been targeted, and Varonis recommends enabling Exchange's "Reject Direct Send" setting plus stricter SPF/DMARC/anti‑spoofing controls and user training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
