A new phishing campaign is exploiting Microsoft 365 infrastructure for user account takeovers. Attackers insert phishing lures directly into legitimate Microsoft emails to bypass its conventional security measures, making it harder for email security systems to detect the attack.
Ron Lev, a security researcher at Guardz Research, explained how attackers are refining their method, stating, “Unlike traditional phishing, which relies on lookalike domains or email spoofing, this method operates entirely within Microsoft’s ecosystem, bypassing security measures user skepticism by leveraging native Microsoft 365 infrastructure to deliver phishing lures that appear authentic and blend in seamlessly.”
Dor Eisner, CEO of Guardz, warned that this attack is especially dangerous as it relies on Microsoft’s native infrastructure. “By exploiting the inherent trust in Microsoft’s cloud services, this phishing campaign is significantly more challenging for security teams to detect and mitigate,” Eisner says.
According to security researchers at Guardz Research, hackers use the following attack strategy:
According to Paubox’s 2025 Healthcare Email Security Report, 43.3% of email-related breaches involved Microsoft 365. This high percentage shows how popular the platform is becoming among cybercriminals, who exploit its infrastructure to carry out attacks.
These phishing emails originate from legitimate Microsoft services, bypassing security filters, and placing Microsoft 365 users, especially businesses and enterprises, at higher risk of credential theft, financial fraud, and business email compromise (BEC) attacks.
Learn more: HIPAA Compliant Email: The Definitive Guide (2025 Update)
HIPAA compliance is required for covered entities, such as healthcare providers, health plans, and healthcare clearinghouses, as well as their business associates who handle protected health information (PHI).
Yes, phishing attacks in healthcare fall under Health Insurance Portability and Accountability Act (HIPAA) regulations. Phishing attacks compromise the privacy and security of PHI and can lead to severe penalties, including fines and reputational damage.
Yes, DMARC can help healthcare organizations prevent email-based breaches of patient information by verifying the authenticity of email messages, detecting and blocking unauthorized emails, and reducing the risk of email spoofing and phishing attacks.