Hackers Exploit Microsoft 365 Feature to Impersonate Internal Staff and Bypass Email Defenses

Listen to this Post

Featured Image

A Dangerous Loophole Inside

In a startling discovery that has sent ripples across cybersecurity circles, attackers have uncovered a clever way to abuse a legitimate Microsoft 365 feature — known as “Direct Send” — to send highly convincing phishing emails that appear to come from within an organization. This method not only tricks users into believing the messages are genuine but also bypasses Microsoft’s own Defender as well as third-party email security systems.

The key to this strategy lies in the exploitation of Direct Send, a feature intended to simplify email delivery from internal systems like scanners, apps, and printers. However, its design allows unauthenticated messages to pass through unchecked, so long as the sender mimics internal naming conventions.

the Original

Cybercriminals are now leveraging Microsoft

The phishing campaigns avoid common authentication checks like SPF, DKIM, and DMARC, which typically help determine whether a message originates from a trusted domain. These forged messages are difficult to trace due to malformed or missing email headers, which adds another layer of stealth.

Microsoft has acknowledged this vulnerability and introduced new options for admins to create custom header stamps and quarantine policies for suspicious internal-looking messages. However, multiple security vendors — including Varonis, Barracuda, and Arctic Wolf — have confirmed that threat actors are actively exploiting this loophole.

The attackers have been sending phishing emails using PowerShell scripts from IP addresses in Ukraine and France, masquerading as internal traffic. StrongestLayer reports the campaign has already targeted over 70 organizations across various sectors, especially financial services, healthcare, and manufacturing — with 95% of victims located in the United States.

What’s particularly concerning is that these attacks don’t require access to the victim’s Microsoft 365 environment. All the hackers need is a predictable address format and knowledge of the organization’s Direct Send endpoint. From there, they can send emails with no authentication, embedding QR codes, PDFs, or HTML attachments to steal user credentials.

Security experts at StrongestLayer recommend turning off Direct Send entirely or enabling Microsoft’s “Reject Direct Send” setting. In addition, companies should enforce strict DMARC policies, use header stamping, and quarantine any emails not marked as genuine internal communication.

🧠 What Undercode Say:

This story is yet another glaring reminder that “features for convenience” in enterprise tech are often a double-edged sword. Microsoft 365’s Direct Send, while designed to streamline internal workflows, has ironically become a weapon of exploitation due to its loose security controls.

The fundamental issue lies in trust. Security systems inherently trust messages that appear to come from within an organization. Attackers, always opportunistic, are exploiting this blind spot by disguising themselves as insiders. The success of this method — even against tools like Microsoft Defender and third-party SEGs — shows that the traditional “internal vs external” distinction is becoming obsolete in threat modeling.

What makes this method so dangerous is its simplicity.

Additionally, the absence of proper email header data makes forensic tracking extremely difficult. Security teams might not even realize they’ve been infiltrated — until it’s too late.

Another major takeaway: authentication protocols like SPF, DKIM, and DMARC are only as effective as their implementation. If your system lets emails bypass them due to internal assumptions, the attacker already has the upper hand.

This type of campaign is a nightmare scenario for SOC teams and CISOs, especially in sectors like banking or healthcare where internal messages may carry sensitive data or influence major decisions. Imagine an attacker posing as a CFO asking for urgent fund transfers — and the email passes every security gateway.

Organizations must now rethink their zero-trust strategies. Trust should not be assigned merely based on perceived origin; instead, emails must be validated via cryptographic proofs, behavioral baselines, and dynamic sender policies. Any deviation, even from supposed insiders, should trigger alerts or quarantines.

In summary, Direct Send is a convenience that now carries a cost. Unless patched with strict policies and authentication enforcement, it’s an open invitation to cybercriminals. IT teams must act now to reconfigure this feature or risk falling victim to silent, devastating phishing attacks that appear to come from within.

🔍 Fact Checker Results:

✅ Microsoft has acknowledged the vulnerability and rolled out header stamping/quarantine options.
✅ Major vendors (Varonis, Barracuda, Arctic Wolf) have confirmed active exploitation of Direct Send.
❌ There is no official Microsoft fix to completely disable Direct Send by default — it must be configured manually.

📊 Prediction:

As awareness grows, more organizations will disable or restrict Direct Send over the next 6–12 months. However, until enforcement becomes a default setting from Microsoft, phishing campaigns exploiting this feature will likely surge, especially targeting less mature security environments. Expect attackers to evolve this method by combining it with AI-generated spear phishing, leading to even more convincing internal impersonation attempts in Q4 2025 and beyond.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.darkreading.com
Extra Source Hub:
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon