Email security

Phishing campaign leverages Microsoft 365 Direct Send feature

A phishing campaign observed to follow US Eastern business hours has been abusing Microsoft 365’s Direct Send feature. The KnowBe4 Threat Lab team uncovered this campaign, identifying 29,785 confirmed phishing emails utilizing the Direct Send functionality throughout July and August 2026. Researchers noted a distinct human pattern in the delivery, with attackers showing peak activity from Monday to Tuesday during US Eastern business hours, particularly around noon and 2 p.m. EST, based on information published by Infosecurity Magazine.

The attackers exploit Microsoft 365's Direct Send feature, a legitimate tool for devices and legacy applications to send emails without a dedicated account. This allows malicious emails to appear as if they originate from trusted internal sources like HR or accounting, bypassing standard email security gateways by connecting directly to the Exchange Online MX endpoint. Approximately 35% of these phishing emails contained malicious attachments, disguised as fake document requests, voicemail alerts, or invoices. Additionally, a significant number used a reply-to address pointing to a different domain, redirecting employee responses to the attackers.

To mitigate these threats, organizations are advised to look for the "X-MS-Exchange-Organization-AuthAs: Anonymous" header, enforce strict DMARC policies (p=reject), restrict legitimate senders via Exchange Online connectors, disable Direct Send if unnecessary, and enable DKIM signing to verify outbound emails.

Source: Infosecurity Magazine

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds