KnowBe4 Security Awareness Training Blog

"Delete" Notification as Office 365 Phishbait

Written by Stu Sjouwerman | May 31, 2019 12:00:00 PM

Attackers are posing as Office 365 support in phishing emails that warn users about an “unusual volume of file deletion” on their accounts, BleepingComputer has found. The emails claim that a medium-severity alert was triggered by fifteen file deletions within five minutes. If victims click on the link to view the alert’s details, they’ll be taken to a spoofed Microsoft login page. The attackers will then collect their credentials before forwarding them to the legitimate Microsoft login portal.

A notable feature of this campaign is that the phishing pages are hosted on Microsoft’s Azure cloud services, so the URLs end with “windows.net.” As a result, even users who know that they should inspect the top-level and second-level domains of the URL could still fall for the scam. Azure-hosted sites are also secured with Microsoft SSL certificates, increasing the appearance of authenticity.

Researchers have discovered hundreds of phishing sites hosted on Azure and other cloud services in the past month. While Microsoft takes these sites down as quickly as it can, the sheer volume of malicious domains means that attackers usually have several days to carry out their attacks. Additionally, when their sites are shut down, they can easily set up more. New-school security awareness training can give your employees up-to-date knowledge of the evolving techniques and technologies being used in phishing campaigns.

BleepingComputer has the story: https://www.bleepingcomputer.com/news/security/phishing-emails-pretend-to-be-office-365-file-deletion-alerts/

Free Phishing Security Test

Find out what percentage of your employees are Phish-prone™

Would your users fall for urgent-looking phishing attacks? Take the first step now and find out before the bad guys do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

Here's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer