M365 — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
November 4, 2025
Last Seen
June 13, 2026

M365 is a technology platform tracked across 7 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity June 13, 2026.

Overview

Microsoft 365 (M365) is a cloud-based productivity platform offering email, collaboration, and content services. In cybersecurity, it is a high-value target for identity- and access-focused threats (phishing, MFA bypass attempts, credential theft) and can serve as a vector for ransomware and data exfiltration; recent reports highlight novel phishing techniques and MFA-targeted campaigns against M365.

Related Threat Clusters

Recent Intelligence Reports

  • Geist in der Cloud: Chinesische Hacker waren 18 Monate in M365 unterwegs — Borncity · June 13, 2026
  • Patchday Microsoft: Critical DNS Client Gap Threatened Windows — www.heise.de · May 13, 2026
  • Phishing Attacks Abuse OAuth Device Code to Gain Access to M365 Accounts — Gbhackers · December 22, 2025
  • Scottish council still reeling from 2023 ransomware attack — Theregister · November 27, 2025
  • Attackers Use Quantum Route Redirect to Launch Instant Phishing on M365 — Gbhackers · November 11, 2025
  • Anatomy of Tycoon 2FA Phishing: Tactics Targeting M365 and Gmail — Gbhackers · November 4, 2025

CVSS v3.1 Breakdown