Microsoft 365 Direct Send phishing campaign tracked to US Eastern business hours
Campaign
Summary
Hide ▲
Show ▼
A phishing campaign abused Microsoft 365 Direct Send to deliver 29,785 confirmed phishing emails across July and August 2026, with activity clustering during US Eastern business hours. The operation matters because the messages could appear to come from trusted internal senders while bypassing normal email security gateways. One observed message reached 900 recipients in a single send.
Related Happenings
High-volume Unicode-smuggling phishing campaign
Campaign
H score29
First: 04.09.2026 18:57
Last: 04.09.2026 18:57
Sources 1
About this happening:
A high-volume phishing campaign is using invisible Unicode tag characters to split lure words and bypass email filters, pushing finance-themed emails at scale. The...
High-volume Unicode-smuggling phishing campaign
CampaignAbout this happening: A high-volume phishing campaign is using invisible Unicode tag characters to split lure words and bypass email filters, pushing finance-themed emails at scale. The...
Microsoft Exchange Online outage delaying external email with Server busy errors
Service Disruption
H score0
First: 04.09.2026 15:22
Last: 04.09.2026 15:22
Sources 1
About this happening:
Microsoft is dealing with an ongoing Exchange Online outage that is delaying email to and from external domains, creating visible disruption for mail flow across multipl...
Microsoft Exchange Online outage delaying external email with Server busy errors
Service DisruptionAbout this happening: Microsoft is dealing with an ongoing Exchange Online outage that is delaying email to and from external domains, creating visible disruption for mail flow across multipl...
Microsoft Exchange Online service disruption causing authentication and email failures
Service Disruption
H score0
First: 31.08.2026 19:56
Last: 31.08.2026 19:56
Sources 1
About this happening:
Microsoft is investigating a widespread Exchange Online outage that is disrupting authentication and email delivery for tens of thousands of users. The issue i...
Microsoft Exchange Online service disruption causing authentication and email failures
Service DisruptionAbout this happening: Microsoft is investigating a widespread Exchange Online outage that is disrupting authentication and email delivery for tens of thousands of users. The issue i...
Latest development: 31.08.2026 20:30
Microsoft began investigating a widespread Exchange Online service issue after a stream of user reports on social media and a Downdetector spike indicated tens of thousands of affected users. The disruption is causing authentication-related errors, delays or failures when sending and receiving email, mailbox-operation problems, and access issues in Exchange administration experiences.
Microsoft Teams OAuth phishing campaign targeting 120 organizations
Campaign
H score30
First: 30.07.2026 15:00
Last: 30.07.2026 15:00
Sources 1
About this happening:
A Microsoft Teams-themed phishing campaign is abusing Microsoft’s legitimate authentication infrastructure to steal OAuth access and compromise corporate accounts...
Microsoft Teams OAuth phishing campaign targeting 120 organizations
CampaignAbout this happening: A Microsoft Teams-themed phishing campaign is abusing Microsoft’s legitimate authentication infrastructure to steal OAuth access and compromise corporate accounts...
Kali365 Microsoft 365 device-code phishing campaign
Campaign
H score46
First: 25.05.2026 15:45
Last: 25.05.2026 15:45
Sources 1
About this happening:
A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...
Kali365 Microsoft 365 device-code phishing campaign
CampaignAbout this happening: A Kali365 phishing-as-a-service campaign is targeting Microsoft 365 and Microsoft Entra accounts with OAuth device-code phishing and an AiTM mode called Cook...
Latest development: 05.08.2026 14:43
Kali365 uses device-code phishing to target US organizations, presenting lures that impersonate SharePoint, OneDrive, or DocuSign before redirecting victims to Microsoft's legitimate device login portal for attacker-provided codes; successful approvals can yield access and refresh tokens with continued access to Microsoft 365 email, documents, and cloud resources, and ANY.RUN telemetry records more than 80 public sessions linked to the campaign each week.
Timeline
-
11.09.2026 16:30 2 articles · 1h ago
Microsoft 365 Direct Send phishing campaign tracked to US Eastern business hours
Initial DisclosureEarly activity centered on a Microsoft 365 Direct Send abuse pattern that routed phishing mail through an unauthenticated delivery path. The operation was already sending at scale and showed a repeatable timing pattern during US Eastern business hours.
Show sources
- Hackers Favor US Eastern Business Hours in M365 Phishing Campaign — www.infosecurity-magazine.com — 11.09.2026 16:30
- Hackers Favor US Eastern Business Hours in M365 Phishing Campaign — www.infosecurity-magazine.com — 11.09.2026 16:30