New Phishing Attack Uses Google Firebase to Trick Microsoft and Achieve a Spam Confidence Level of Just 1

Phishing Attack Spam This new phishing scam takes advantage of inherent trust in credible domains to get past the scrutiny of even Microsoft to trick Office 365 users into giving up their online credentials.

I’ve written about plenty of Office 365 credential phishing attacks that, in general, end up taking the victim to a lookalike Office 365 logon page in an attempt to be convincing enough to get the victim to enter in their credentials. Some take the path of checking credentials in real-time, while others detect inbound connections to see if it’s a virtual sandbox testing the link.

In this latest iteration, security researchers at armorblox identified an attack that simply chose to host their spoofed Office 365 logon page on Google’s Firebase. Designed for app developers and hosted on a subdomain of, this platform ended up being the perfect place to host the malicious web pages for this attack.

According to armorblox, this attack hit an organization with 20,000 users and was able to bypass the security checks in both Exchange Online Protection (EOP), Microsoft Defender for Office 365. Microsoft assigned the email a Spam Confidence Level (SCL) of ‘1’, meaning that Microsoft didn’t see the email as being suspicious, subsequently delivering it to the intended mailboxes.

The lesson learned here is that while Microsoft won’t necessarily make the same mistake twice, there will always be reputable domain names, hosting platforms, etc. that the bad guys can use that will assist in getting past some or all of your organization’s security checks.

That’s why it’s important to include Security Awareness Training in your cybersecurity strategy, where users themselves are educated to become part of the solution. In most every case of an attack like this, there are telltale signs of it being a scam: improper from email address, poor representation of Microsoft and/or Office 365 in both the email and the spoofed logon page, etc.

In reality, it’s quite easy to spot these scams… IF the user is taught to be watching. If they’re not, it’s also quite easy to fall for these attacks too.

Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before the bad guys do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

Subscribe To Our Blog

Ransomware Hostage Rescue Manual

Get the latest about social engineering

Subscribe to CyberheistNews