Microsoft announced that its cloud-based email security solution Defender for Office 365 will automatically detect and block “ email bombing ” attacks.
See also: Siemens warns of a problem with Microsoft Defender Antivirus

Defender for Office 365 (formerly known as Office 365 Advanced Threat Protection or Office 365 ATP) protects organizations operating in high-risk industries and facing advanced threatsfrom malicious emails, links, and collaboration tools.
The new “Mail Bombing” feature began rolling out in late June 2025 and is expected to reach all organizations by the end of July. It will be enabled by default, requires no manual configuration, and will automatically move all messages detected as part of such an attack to the “Junk” folder.
As explained over the weekend, Mail Bombing is now available to security and administrators as a new detection type in Threat Explorer, the Email item page, the Email summary panel, and Advanced Hunting.
In e -mail bombing attacks , cybercriminals flood their victims' inboxes with thousands or even tens of thousands of messages within minutes, either by mass-subscribing them to newsletters or by using specialized cybercrime services that can send a huge volume of emails.
In most cases, the ultimate goal of attackers is to overload email security systems, as part of social engineering attacks, paving the way for malware or ransomware attacks, aimed at stealing sensitive data from victims' systems.
See also: Defendnot tool disables Microsoft Defender
The email bombing has been used for over a year by various cybercrime and ransomware groups. The practice began with the BlackBasta, which flooded its victims' inboxes with messages within minutes, just before launching the main attack.

The attackers then proceeded to launch voice phishing, impersonating companies' IT support departments, with the aim of tricking the victims into giving them remote access to their computers through tools like AnyDesk or the built-in Windows Quick Assist.
After gaining access to systems, they installed malicious tools and software, allowing them to move laterally within corporate networks before launching ransomware attacks.
More recently, email bombing has been adopted by members of the 3AM ransomware gang, as well as cybercriminals associated with the FIN7 group. The latter have also used the fake technical support as part of social engineering attacks, with the aim of convincing employees to reveal their credentials for remote access to corporate systems.
See also: Microsoft Defender vulnerability allows elevation of privilege
Based on the above, modern attacks do not only target technological weaknesses but, above all, the psychological pressure and the inability of employees to recognize when they are being scammed. The large volume of emails sent in a short period of time not only overloads systems, but also distracts employees, creating the perfect ground for a targeted social engineering attack.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
