Listen to this Post

A New Wave of Phishing Hits Critical Infrastructure
Cybercriminals are increasingly targeting the global energy sector, and their latest weapon of choice is a familiar one: Microsoft SharePoint. According to new threat intelligence shared by Cybersecurity News Everyday, attackers have been abusing legitimate SharePoint links to carry out highly convincing phishing campaigns. These attacks have successfully stolen user credentials, hijacked corporate email accounts, and quietly maintained long-term access inside victim organizations.
What makes this campaign particularly dangerous is not just the technical sophistication, but how seamlessly it blends into normal enterprise workflows. By leveraging trusted Microsoft 365 infrastructure, attackers reduce suspicion, bypass basic security filters, and exploit gaps in multi-factor authentication (MFA) deployments. Microsoft has since urged organizations to strengthen MFA enforcement and deploy conditional access policies, especially within high-risk industries such as energy.
the Original Report
The reported phishing campaign focuses on abusing Microsoft SharePoint links, which are widely used for internal and external document sharing. Attackers distribute malicious SharePoint URLs that appear legitimate, often mimicking internal file-sharing notifications or collaboration requests. When users click these links, they are redirected to credential-harvesting pages designed to closely resemble Microsoft login portals.
Once credentials are captured, attackers move quickly to take over the victim’s email account. In several documented cases involving energy firms, threat actors went further by manipulating multi-factor authentication settings. This included registering their own MFA methods or exploiting weaker MFA configurations, allowing them to maintain access even if passwords were later changed.
To ensure persistence, attackers also created malicious inbox rules. These rules automatically hid security alerts, forwarded sensitive emails to attacker-controlled accounts, or deleted warning messages from IT teams. As a result, compromised users often remained unaware for extended periods, giving attackers time to conduct internal reconnaissance, spread laterally, or prepare for more damaging follow-up attacks such as ransomware or financial fraud.
Microsoft responded by reiterating best practices for Microsoft 365 security, emphasizing the importance of strong MFA enforcement, conditional access policies, and continuous monitoring of email rules and login activity. The campaign highlights how trusted cloud platforms, when misconfigured or insufficiently monitored, can become powerful tools in the hands of attackers.
What Undercode Say:
The most alarming aspect of this campaign is not the use of phishing itself, but how effectively attackers are weaponizing trust. SharePoint is deeply embedded in enterprise culture, especially in sectors like energy where collaboration with vendors, regulators, and partners is constant. When a SharePoint link arrives in an inbox, users are conditioned to click first and question later.
This attack also exposes a harsh reality about MFA: simply “having MFA enabled” is no longer enough. If MFA methods can be modified post-compromise, or if conditional access policies are too permissive, attackers can turn MFA from a defense into a false sense of security. Energy companies, in particular, often operate with legacy workflows and complex user roles, which can lead to inconsistent security enforcement across environments.
Inbox rule abuse is another recurring theme that continues to be underestimated. It is a low-tech tactic with devastating impact, allowing attackers to remain invisible while siphoning sensitive communications. The fact that this technique keeps succeeding suggests many organizations still lack proper auditing and alerting around mailbox configuration changes.
From a strategic standpoint, this campaign fits into a broader trend: attackers are shifting away from noisy exploits and toward identity-based attacks. Credentials, sessions, and cloud access tokens are now more valuable than unpatched servers. For critical infrastructure sectors, this means cybersecurity is no longer just an IT issue—it is an operational and national security concern.
Microsoft’s guidance on conditional access and stronger MFA is sound, but implementation is where most organizations struggle. Security teams must balance usability and protection, and attackers are betting that convenience will win. Unless energy firms invest in continuous monitoring, zero-trust principles, and user education tailored to modern cloud threats, similar attacks will continue to succeed with minimal effort.
🔍 Fact Checker Results
✅ The use of Microsoft SharePoint links in phishing campaigns is a well-documented tactic.
✅ Inbox rule manipulation is a known persistence technique in Microsoft 365 attacks.
❌ There is no evidence that SharePoint itself was technically breached; the abuse relies on social engineering and misconfiguration.
📊 Prediction
🔮 Identity-focused attacks using trusted cloud platforms will accelerate across critical infrastructure sectors.
🔮 Regulators may push for stricter cloud security baselines for energy companies.
🔮 Organizations that fail to monitor MFA changes and mailbox rules will face longer, stealthier breaches rather than quick, detectable incidents.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.medium.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




