HomeSecurityAdministrators are being scammed with fake Office 365 notifications

Deceiving administrators with fake notifications in Office 365

New Office 365 account breach campaign targets administrators.

Office

Hacking email can be a lucrative business for hackers or help distribute malware .But a jackpothacking into the account of a domain administrator's email account is considered.

Hackers don't always target ordinary employees of an organization, but also administrators.

Phishers target administrators because compromising their accounts can provide them with many advantages. Administrator credentials allow hackers to create new accounts with the domain , send emails impersonating other users and read other users' emails.

Phishers are using a new method to trick administrators into gaining access to their accounts. They send notifications to Office 365 administrators, which usually indicate a critical issue that requires immediate attention. It might say, for example, that unauthorized access was discovered.

Office 365 Admin Phishing Emails

An example of a fake notification is one that states that Office 365 licenses have expired. The notification then recommends that the user log in to the Office 365 Admin Center to check information .

Office

Another message appeared to come from Office 365 and warned the administrator that someone had gained access to one of the accounts. It then asked the administrator to “investigate” the issue by logging in.

Deceiving administrators with fake notifications in Office 365

However, if someone opens the links contained within these emails, they will be taken to phishing pagesthat look like official Microsoft, but are actually aimed at stealing credentials.

In fact, to make it more convincing, the phishing pages have a certificate from Microsoft, as shown below:

Deceiving administrators with fake notifications in Office 365

If an administrator falls into the trap and enters his credentials, the hackers will manage to gain access to the Office 365 admin portal.

You might think that an administrator would never fall into such a trap. But it's not unlikely that it could happen, because most companies don't have a dedicated IT administrator, which is essential.

Those who fall victim to phishing emails are the administrators who lack sufficient IT support and experience.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS