Target Industry
Indiscriminate, opportunistic targeting.
Overview
A sophisticated phishing campaign has targeted over 70 organisations by exploiting Microsoft 365’s Direct Send feature. This is a feature that lets devices like printers or apps send emails within an organisation without needing a username or password.
Impact
The threat actor doesn’t need to compromise any accounts, they only need the organisation’s domain and valid email addresses. By using Microsoft 365’s Direct Send feature, they can send emails that appear to come from internal users. This increases the likelihood of successful phishing, potentially leading to data breaches, financial loss, and reputational damage.
Exploitation
The threat actor identifies the target organisation’s domain and gathers valid internal email addresses, often through open-source intelligence (OSINT) or previous breaches. Using Microsoft 365’s Direct Send smart host (e.g. organisation.mail.protection.outlook.com), the threat actor sends emails without needing to authenticate or compromise any accounts. The emails are crafted to appear as if they originate from legitimate internal users, exploiting trust in internal communications. These spoofed emails may contain phishing links, malicious attachments, or social engineering lures (e.g. fake voicemail or fax notifications). Because Direct Send bypasses standard email checks, traditional email security tools may not flag the messages as suspicious.
Containment, Mitigations & Remediations
To reduce the risk of abuse, organisations should restrict the use of Direct Send to trusted internal systems and avoid exposing it to the internet. Switching to authenticated methods like SMTP Auth or Microsoft Graph API adds security and traceability. Email filtering and monitoring should be enhanced to detect spoofed internal messages, and detection rules should flag emails that bypass SPF, DKIM, or DMARC. Staff should be trained to recognise suspicious internal-looking emails, and mail flow rules should be reviewed to ensure only authorised systems can send messages this way.
Threat Landscape
More than 3.7 million companies worldwide rely on Microsoft 365 products. Microsoft has detected an increase in cyber-attack campaigns that exploit legitimate file hosting services. This campaign exposes a critical blind spot in Microsoft 365’s email security. Organisations are urged to implement additional monitoring and detection for Direct Send abuse, while still supporting legitimate use cases.
Threat Group
The specific threat group behind this has not been publicly identified at the time of writing.
Further Information
Intelligence Terminology Yardstick













