Security News

Phishing Campaign Exploits Microsoft 365 Direct Send Feature, Mimics Business Hours

Infosecurity Magazine · 11 Sept 2026
Key Takeaway Australian SMBs using Microsoft 365 should review their DMARC settings and shift to a 'reject' policy to block spoofed internal emails exploiting the Direct Send feature.

Security researchers at KnowBe4 Threat Lab have uncovered a phishing campaign that abuses a legitimate Microsoft 365 feature called Direct Send, which is normally used by devices like printers and scanners to send email without needing a dedicated account. The campaign involved nearly 30,000 confirmed phishing emails sent across July and August 2026, with activity concentrated during US Eastern business hours, peaking on Mondays and Tuesdays around midday and again at 2pm.

By exploiting Direct Send, attackers can send emails that appear to come from trusted internal sources such as HR, accounting or admin teams, without needing to steal an employee's credentials. This also lets them bypass an organisation's usual email security gateway by connecting directly to its Exchange Online mail server. Around 35% of the phishing emails identified carried malicious attachments, including fake invoices, document requests, voicemail alerts and OneDrive file shares. Some messages also used a reply-to address pointing to a different domain, redirecting any employee replies straight to the attacker.

KnowBe4 recommends organisations check for a specific Exchange header that signals unauthenticated delivery, and strengthen their DMARC policy by moving from a monitoring-only setting to one that actively rejects spoofed messages.

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.