Cyber Attack | Data Breach

Published on July 23rd, 2019 📆 | 2872 Views ⚑

0

Fake Admin Alerts Phishing Scam Targets Microsoft Office 365 Admins


iSpeech.org

In another wave of phishing, this time attackers have begun targeting Microsoft Office 365 admins. This phishing attack involves sending fake admin alerts in an attempt to steal account credentials.

Office 365 Fake Admin Alerts

BleepingComputer discovered a phishing campaign going on in the wild targeting Office 365 admins. The campaign executes by sending fake admin alerts to the target users. These alerts usually attempt to panic users by stating time-sensitive issues.

As stated in their report,

These alerts will typically be about a time-sensitive issues that requires an admins immediate attention such as an issue with the mail service or unauthorized access being discovered.

They identified the campaign upon noticing a few fake alerts. One of these stated about license expiration of an organizationā€™s Office 365 account. The mail asked the recipient to ā€œSign in to the Office 365 Admin centerā€ to view the message. The hyperlinked text within the emails contains malicious URL.

Source: BleepingComputer

Whereas, the other message they analyzed, from a seemingly legit email account, supposedly informed the recipient of a ā€˜low-severity alertā€™.

Source: BleepingComputer

Like always, clicking on the links redirects the users to phishing web pages that mock the legit website. As demonstrated by BleepingComputer, clicking on the ā€˜Investigateā€™ button in the second example would take the user to a fake Microsoft page. The users, here, should supposedly enter their account credentials.





What Next?

Despite warnings, advice, recommendations, and real-time examples of losses, people still fall for phishing campaigns.

Considering the declining success rate of lottery wins and prize money scams, it seems the scammers have changed their strategy. In order to target the corporate sector and even some semi-savvy individuals, the scammers now strive to take advantage of the usersā€™ lack of knowledge about IT. Thus, they trick users with fake technical emails, such as the admin alerts reported here.

Although, an IT admin, ideally, should not fall for this scam. However, since most admins working at different organizations arenā€™t really true IT guys, they are likely to believe these emails. Therefore, the organizations must ensure appointing the right IT personnel at such crucial positions. Moreover, make sure to train every person in the firm about basic cybersecurity.

Let us know your thoughts in the comments.

The following two tabs change content below.

Avatar
Abeerah has been a passionate blogger for several years with a particular interest towards science and technology. She is crazy to know everything about the latest tech developments. Knowing and writing about cybersecurity, hacking, and spying has always enchanted her. When she is not writing, what else can be a better pastime than web surfing and staying updated about the tech world! Reach out to me at: [emailĀ protected]
Avatar

Source link

Tagged with: ā€¢ ā€¢ ā€¢ ā€¢ ā€¢ ā€¢



Comments are closed.