Think you can spot a phishing email? This new trick is harder to catch

Think you can spot a phishing email? This new trick is harder to catch
new phishing email trick bypassing Microsoft 365

You may think you can spot a phishing email, but a new trick is making that much harder. A recently discovered vulnerability in Microsoft 365 lets hackers bypass traditional security and send convincing fake emails that slip past your defenses. Many people are getting better at spotting phishing attacks from outside sources. However, what if the phishing email attack appears to come from within your own company?

The New Phishing Email Trick, Explained

At the heart of this threat is a Microsoft 365 feature called Direct Send. It was created for a simple reason: to allow internal office devices, such as printers and scanners, to send you emails without needing to log in with a password. This feature is designed for convenience and is intended only for internal use.

However, this convenience has created a security loophole. Because Direct Send does not require authentication, hackers have found a way to exploit it to send phishing email messages without needing to steal a single password or compromise any accounts. All they need is a few publicly available details and some guesswork to figure out your company email address format.

Once an attacker has a valid internal email address, they can use the Direct Send system to send emails that look like they are from someone inside your organization. Because these emails are routed through Microsoft infrastructure and appear to be internal, they often bypass the security filters designed to catch suspicious messages.

In a recent campaign that affected over 70 organizations, attackers used this method to send fake voicemail notifications containing malicious QR codes, which tricked users into visiting websites that stole their Microsoft 365 credentials.

What You Can Do: Stay Alert Against Phishing Emails

While the technical fix is up to your IT team, everyone can help prevent these attacks by being cautious.

  • Be suspicious of the sender: Even if a phishing email looks like it is from a coworker, be wary if the request is unusual.
  • Question internal notifications: Employees are used to seeing notifications from scanners and printers, so they rarely question their authenticity. Think twice before opening attachments or clicking links in automated messages.
  • Beware of QR codes: Be very careful about scanning QR codes received in emails, as they may lead you to malicious websites.
  • Report, do not reply: If you see a suspicious email, report it to your IT department immediately.

For Your IT Department: The Technical Fix

This attack exploits a misconfiguration, not an impossible-to-stop zero-day threat. Your technical team can take several steps to shut this vulnerability down.

  • Implement strict policies: Enforce strict DMARC and anti-spoofing policies to make it harder for fakes to get through. You should also enable SPF hardfail in Exchange Online Protection.
  • Disable or reject Direct Send: Microsoft is working to disable Direct Send by default. In the meantime, enable the Reject Direct Send setting in the Exchange Admin Center to block this type of phishing email attack.
  • Flag unauthenticated mail: Set up rules to flag any unauthenticated internal emails for review.
  • Secure your devices: Treat all network-connected devices such as printers and scanners as fully fledged endpoints. Put them on segmented networks, monitor their activity, and restrict what they are allowed to do.

Do not wait for an attack to test your defenses. Our cybersecurity services team can help you secure your email systems and protect your organization against phishing email threats today. Contact us now.

Share:

Cover all your bases with 360° support

From private cloud hosting to cybersecurity to IT consulting, New Jersey businesses rely on 360 Networks for complete IT solutions and 24/7 support. Focus on your goals — we'll keep your business running smoothly and securely.