Scworld
Phishing Attacks Exploit Microsoft 365 Direct Send Bypass
Article Content
Cyber attackers are using an 'empty envelope' technique to bypass Microsoft 365's RejectDirectSend control, allowing unauthenticated emails to reach organizational inboxes. This method targets senior leaders and utilizes a blank Simple Mail Transfer Protocol (SMTP) envelope sender, which tricks the system into accepting the emails. Between September 2025 and August 2026, 40% of these phishing emails were aimed at senior leaders, with common lures including document notifications and payment requests. While not a vulnerability in Microsoft software, this limitation exposes organizations to increased spearphishing risks. Testing showed that using IP-restricted inbound connectors can effectively block these attempts. Organizations are advised to monitor for empty envelope attacks and tighten email filtering protocols.
Key Points: • Attackers exploit a blank SMTP envelope sender to bypass Microsoft 365 protections. • 40% of phishing emails using this technique targeted senior leaders between September 2025 and August 2026. • IP-restricted inbound connectors can mitigate the risk of these phishing attacks.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.