Skip to content
Phishing Campaign Exploits Mimecast Links to Target SharePoint Users

Phishing Campaign Exploits Mimecast Links to Target SharePoint Users

First seen 11 Dec 2025, 23:50 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Threat actors have exploited Mimecast's secure-link rewriting feature to send over 40,000 phishing emails that impersonate SharePoint and DocuSign. These emails, which included Microsoft branding and fake display names, aimed to deceive recipients into clicking malicious links disguised as legitimate notifications. The campaign highlights the vulnerabilities in digital communication platforms widely used in various industries.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed