Phishing Attacks Exploit Microsoft 365 Direct Send Bypass

Phishing Attacks Exploit Microsoft 365 Direct Send Bypass

First seen 4 Sep 2026, 14:18 UTC GbhackersCybersecuritynewsScworldreliaquest.com 63.0

Article Content

Browse articles
ThreatCluster

Cyber attackers are using an 'empty envelope' technique to bypass Microsoft 365's RejectDirectSend control, allowing unauthenticated emails to reach organizational inboxes. This method targets senior leaders and utilizes a blank Simple Mail Transfer Protocol (SMTP) envelope sender, which tricks the system into accepting the emails. Between September 2025 and August 2026, 40% of these phishing emails were aimed at senior leaders, with common lures including document notifications and payment requests. While not a vulnerability in Microsoft software, this limitation exposes organizations to increased spearphishing risks. Testing showed that using IP-restricted inbound connectors can effectively block these attempts. Organizations are advised to monitor for empty envelope attacks and tighten email filtering protocols.

Key Points: • Attackers exploit a blank SMTP envelope sender to bypass Microsoft 365 protections. • 40% of phishing emails using this technique targeted senior leaders between September 2025 and August 2026. • IP-restricted inbound connectors can mitigate the risk of these phishing attacks.

Ask AI about this cluster

Timeline

2025-09-01
Phishing campaign targeting senior leaders identified
ReliaQuest reported that 40% of phishing emails used an empty envelope technique aimed at senior leaders.
Scworld
2026-09-04
Threat spotlight published by ReliaQuest
ReliaQuest detailed the empty envelope technique and its implications for Microsoft 365 users.
reliaquest.com
2026-09-04
Gbhackers report on Direct Send bypass
Gbhackers highlighted the security control bypass affecting Microsoft 365's email system.
Gbhackers
2026-09-04
Cybersecuritynews article on phishing technique
Cybersecuritynews reported on the phishing technique using an empty SMTP envelope sender to evade Direct Send blocking.
Cybersecuritynews