Skip to main content

Phishing Attacks Leveraging Microsoft 365 Infrastructure

A new phishing campaign, including Business Email Compromise (BEC), has been discovered using Microsoft 365’s legitimate infrastructure. It poses a significant threat to user credentials and account security, leading to credential theft, data breaches, financial fraud, and malware spread.

Targeted Users:

  • High-level targets
  • Organizations handling sensitive data
  • Users with privileged access (administrative)
  • Organizations using Microsoft ADFS (Active Directory Federation Services)
  • General Microsoft 365 users


Recommendations:

  • Implement Multi-Factor Authentication (MFA)
  • Regularly review and audit Microsoft 365 tenant configuration
  • Educate users about phishing tactics and security best practice
  • Implement robust email and application security solutions
  • Enforce sign-in risk policies
     

References:

https://www.securityweek.com/microsoft-365-targeted-in-new-phishing-account-takeover-attacks/

https://www.securitymagazine.com/articles/101483-phishing-campaign-leverages-microsoft-365-infrastructure-for-attacks/

 

About

Brunei Computer Emergency Response Team (BruCERT) was established in 2004 as the national and government CERT to deal with computer-related and internet-related security incidents in Negara Brunei Darussalam.