Phishing Campaign Exploits Mimecast Links to Target SharePoint Users

Phishing Campaign Exploits Mimecast Links to Target SharePoint Users

First seen 11 Dec 2025, 23:50 UTC Blog.CheckpointScworld 24.3

Article Content

Browse articles
ThreatCluster

Threat actors have exploited Mimecast's secure-link rewriting feature to send over 40,000 phishing emails that impersonate SharePoint and DocuSign. These emails, which included Microsoft branding and fake display names, aimed to deceive recipients into clicking malicious links disguised as legitimate notifications. The campaign highlights the vulnerabilities in digital communication platforms widely used in various industries.