Energy Sector Targeted by Phishing Campaign via Microsoft SharePoint

Energy Sector Targeted by Phishing Campaign via Microsoft SharePoint

First seen 23 Jan 2026, 22:10 UTC TheregisterScworld 32.0

Article Content

Browse articles
ThreatCluster

Unknown attackers are exploiting Microsoft SharePoint file-sharing services to target multiple energy-sector organizations. The campaign involves harvesting user credentials, taking over corporate inboxes, and sending hundreds of phishing emails from compromised accounts to contacts both inside and outside these organizations. The attackers likely gained initial access using previously compromised email addresses.