Microsoft 365 is Microsoft's cloud-based productivity and collaboration platform (including apps like Exchange Online, Teams, SharePoint, and OneDrive) with identity features such as single sign-on.
Overview
Microsoft 365 is Microsoft's cloud-based productivity and collaboration platform (including apps like Exchange Online, Teams, SharePoint, and OneDrive) with identity features such as single sign-on. Its large global user base and cloud-native services make it a high-value target for credential abuse, phishing, and account compromise, and threat actors increasingly leverage QR-code phishing and infrastructure-enabled techniques against these environments. Recent activity shows enforcement actions against cybercrime infrastructure and ongoing exploitation vectors affecting cloud accounts and communications.
Related Threat Clusters
-
Microsoft SharePoint Attacks: Over 400 Victims Including US Agencies
A series of attacks exploiting zero-day vulnerabilities in Microsoft SharePoint has compromised over 400 organizations, including multiple US government agencies. The attacks, attributed to Chinese threat groups such as…
2 articles · Updated August 12, 2026 -
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
A DNS poisoning campaign has compromised hotel and conference center Wi-Fi gateways to steal Microsoft 365 login credentials from corporate travelers. The campaign has been active since at least June 2026, affecting…
73 articles · Updated July 24, 2026 -
CISA Urges Endpoint Security Enhancements After Stryker Cyberattack
On March 11, 2026, medical technology firm Stryker experienced a significant cyberattack attributed to the Iran-linked hacking group Handala. The attack exploited vulnerabilities in Stryker's Microsoft Intune endpoint…
45 articles · Updated March 19, 2026 -
Russian FSB Exploits Vulnerable Routers to Target Critical Infrastructure
A joint advisory from 21 global cybersecurity agencies warns that Russian state hackers from the FSB's Center 16 are exploiting poorly configured routers to infiltrate critical infrastructure networks worldwide. The…
76 articles · Updated July 13, 2026 -
Jewelbug APT Group Engages in Espionage and Cryptocurrency Fraud
The Jewelbug APT group, based in China, has been conducting simultaneous cyber espionage and cryptocurrency fraud operations. Utilizing a single command-and-control platform named XG-Web, the group has compromised over…
15 articles · Updated August 13, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Global Takedown of Kratos Phishing-as-a-Service Infrastructure
On July 20, 2026, German and U.S. authorities dismantled the Kratos phishing-as-a-service (PhaaS) platform, arresting its developer in Indonesia. The operation neutralized over 200 servers and disrupted approximately…
17 articles · Updated July 21, 2026 -
Russian Hackers Target Networks via RDP, VPNs, and Supply Chains
Russian state-aligned threat groups are increasingly exploiting Remote Desktop Protocol (RDP), Virtual Private Networks (VPNs), and supply chain vulnerabilities to gain initial access to networks across various sectors,…
3 articles · Updated May 22, 2026 -
Chinese APT VerdantBamboo Exploits Brickstorm Malware for Long-term Network Access
The Chinese espionage group UNC5221, also known as VerdantBamboo, has been using the Brickstorm backdoor and new malware variants Plenet and AgentPSD to maintain access to compromised Microsoft 365 environments.…
5 articles · Updated June 5, 2026 -
Iranian APT Group Conducts Password Spray Attacks on Microsoft 365 Accounts
In March 2026, a suspected Iranian APT group, identified as Gray Sandstorm, initiated a password spraying campaign targeting Microsoft 365 accounts of over 300 organizations in Israel and more than 25 in the UAE. The…
9 articles · Updated April 1, 2026
Recent Intelligence Reports
- How Aitm Phishing Bypassed Mfa To Hijack A Microsoft 365 Mailbox In Bec Scheme — www.trendaisecurity.com · August 20, 2026
- Business Email Compromise Attack Hijacks Session Token to Steal Vendor Payments — Pymnts · August 20, 2026
- Hackers Bypass Microsoft 365 MFA and Hijack Finance Mailbox to Steal Payments — Cybersecuritynews · August 20, 2026
- Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud — Gbhackers · August 20, 2026
- Dangerous Invitations Russian Threat Actor Spoofs European Security Events In Targeted Phishing Attacks — www.volexity.com · August 19, 2026
- Best email security solutions for MSPs in 2026: a buyer's guide — Acronis · August 18, 2026
- Unc6671 Targets Financial Services And Enterprise Cloud Environments — cloud.google.com · August 18, 2026
- TCS, HCL, Hexaware named in global Azure directory data leak linked to infostealers — Crnasia · August 17, 2026