A previously unknown vulnerability in Microsoft 365, known as Direct Send, has been uncovered by cybersecurity firm KnowBe4. This flaw allows hackers to impersonate internal email addresses on a large scale without needing to breach any user accounts. Between July and August 2026, KnowBe4 researchers observed nearly 30,000 fraudulent emails exploiting this technique, with the timing of the attacks closely matching typical office hours. These emails often used generic senders like "hr" or "no-reply" to bypass user suspicion, delivering fake invoices, missed call notifications, or file-sharing links without triggering visible security alerts.
Direct Send is a feature in Microsoft 365 intended for devices that do not have their own email inbox, such as printers or scanners. By default, Microsoft's Exchange Online leaves a public entry point open, unintentionally creating an opportunity for cybercriminals to exploit. During the two-month observation period, KnowBe4 confirmed 29,785 impersonation attempts. The majority of these emails—between 22,000 and 32,000 per week—were sent from Monday to Friday, with a peak on August 3 and 4, when over 20,000 fraudulent messages were sent in a single day. Some attacks targeted as many as 900 recipients at once.
In nearly 4,000 cases, the email address displayed to recipients was a decoy, redirecting replies to domains controlled by attackers. Around 35% of these emails included an attachment, often designed to trick users into clicking or downloading content. Attackers frequently changed hosting providers, with Oracle Cloud being the most commonly used. The attacks varied in form, including fake invoices, OneDrive links, and voicemail notifications. Some links led to counterfeit Microsoft login pages, while others used Windows shortcut files (.url) to redirect users to attacker-controlled websites.
KnowBe4 identified a range of psychological tactics used in the attacks, including fake wealth management advice. These tactics rely on the trust people place in messages that appear to come from within their organization. However, the displayed domain does not necessarily confirm the sender's true identity. While authentication systems can detect anomalies, many companies have DMARC (Domain-based Message Authentication, Reporting, and Conformance) set to a "monitoring" mode (p=none), which allows suspicious emails to reach inboxes. This is often the first step in implementing DMARC, with many organizations failing to adopt stricter settings. Additionally, Exchange Online does not, by default, restrict which IP addresses can send emails on behalf of a company's domain.
To address the issue, KnowBe4 recommends switching DMARC to a strict mode (p=reject), limiting Direct Send to only essential IP addresses, and enabling DKIM (DomainKeys Identified Mail) for outgoing emails. A technical indicator, the header "X-MS-Exchange-Organization-AuthAs: Anonymous," can help track these attacks after they occur. Once users enter their credentials on fake login pages, attackers gain access to their email accounts, sometimes immediately. From there, hackers can monitor calendars and work habits before launching new attacks using real company accounts, making these threats more difficult to detect.
Microsoft 365 Flaw Enables Large-Scale Email Impersonation Attacks
AI-rewritten from original reportingHow it works
microsoft365cybersecuritydirectsendemailsecuritydmarcknowbe4
Original sources:
- 🇫🇷Clubic



