Scworld
Energy Sector Targeted by Phishing Campaign via Microsoft SharePoint
First seen 23 Jan 2026, 22:10 UTC
•
•32.0
Export
Article Content
Browse articles
Unknown attackers are exploiting Microsoft SharePoint file-sharing services to target multiple energy-sector organizations. The campaign involves harvesting user credentials, taking over corporate inboxes, and sending hundreds of phishing emails from compromised accounts to contacts both inside and outside these organizations. The attackers likely gained initial access using previously compromised email addresses.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Microsoft SharePoint Attacks: Over 400 Victims Including US Agencies
Active Exploitation of Microsoft SharePoint JWT Token Bypass Vulnerability
CISA Warns of Exploitation of 17-Year-Old Excel Vulnerability
Critical SharePoint RCE Vulnerability Exploited for Key Theft
FBI Warns of Kali365 Phishing Kit Targeting Microsoft 365 Users
Warlock Ransomware Group Enhances Attack Techniques with BYOVD and Remote Access Tools