Target Industry

Indiscriminate, opportunistic targeting.

Overview

A sophisticated phishing campaign has targeted over 70 organisations by exploiting Microsoft 365’s Direct Send feature. This is a feature that lets devices like printers or apps send emails within an organisation without needing a username or password.

Impact

The threat actor doesn’t need to compromise any accounts, they only need the organisation’s domain and valid email addresses. By using Microsoft 365’s Direct Send feature, they can send emails that appear to come from internal users. This increases the likelihood of successful phishing, potentially leading to data breaches, financial loss, and reputational damage.

Exploitation

The threat actor identifies the target organisation’s domain and gathers valid internal email addresses, often through open-source intelligence (OSINT) or previous breaches. Using Microsoft 365’s Direct Send smart host (e.g. organisation.mail.protection.outlook.com), the threat actor sends emails without needing to authenticate or compromise any accounts. The emails are crafted to appear as if they originate from legitimate internal users, exploiting trust in internal communications. These spoofed emails may contain phishing links, malicious attachments, or social engineering lures (e.g. fake voicemail or fax notifications). Because Direct Send bypasses standard email checks, traditional email security tools may not flag the messages as suspicious.

Containment, Mitigations & Remediations

To reduce the risk of abuse, organisations should restrict the use of Direct Send to trusted internal systems and avoid exposing it to the internet. Switching to authenticated methods like SMTP Auth or Microsoft Graph API adds security and traceability. Email filtering and monitoring should be enhanced to detect spoofed internal messages, and detection rules should flag emails that bypass SPF, DKIM, or DMARC. Staff should be trained to recognise suspicious internal-looking emails, and mail flow rules should be reviewed to ensure only authorised systems can send messages this way.

Threat Landscape

More than 3.7 million companies worldwide rely on Microsoft 365 products. Microsoft has detected an increase in cyber-attack campaigns that exploit legitimate file hosting services. This campaign exposes a critical blind spot in Microsoft 365’s email security. Organisations are urged to implement additional monitoring and detection for Direct Send abuse, while still supporting legitimate use cases.

Threat Group

The specific threat group behind this has not been publicly identified at the time of writing.

Further Information

Cyber Security News article

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content