Microsoft Flags Mass Phishing Campaign Using Fake Compliance Emails
ID: 70659b7f-8bb8-5acc-ba23-425608d146ce
STIX ID: report--70659b7f-8bb8-5acc-ba23-425608d146ce
Feed Name: Infosecurity Magazine (News)
Microsoft Defender Research identified a large-scale credential-theft phishing campaign (April 15–16, 2026) that targeted more than 35,000 users at 13,000 organizations across 26 countries using polished enterprise-style compliance lures and PDF links that redirected victims through Cloudflare CAPTCHA and staged AiTM landing pages to steal Microsoft authentication tokens; Microsoft published recommended mitigations including EOP/Defender settings, realistic phishing training, passwordless MFA, Safe Links/Safe Attachments, and Defender XDR configuration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
