Skip to content

A new phishing pattern in Microsoft 365

blank

 As work becomes more connected within Microsoft 365, attackers are adapting their methods to reflect that connectivity.

A pattern now emerging involves compromised Microsoft accounts and legitimate Microsoft SharePoint file sharing. Rather than relying on suspicious links or external impersonation, the technique operates within trusted channels that employees use every day.

Understanding how this works supports both technical response and user awareness.

How the method works

This technique follows a structured sequence:

  1. A legitimate Microsoft account is compromised. Access may have been obtained through credential reuse, earlier phishing, or password exposure.
  2. The attacker uses Microsoft SharePoint to share a genuine file from that real account. The recipient receives a standard SharePoint notification from a recognised contact.
  3. When the file is opened, a Microsoft sign-in prompt appears. The prompt mirrors the usual Microsoft authentication experience.
  4. If credentials are entered, access extends further.

At that point, the attacker is operating inside the organisation’s Microsoft 365 environment as a legitimate user. Collaboration patterns continue as normal, which allows exposure to expand through routine sharing.

This pattern is often described as a secondary attack. Even when most employees act carefully, a single compromised identity can create a downstream impact through everyday workflows.

Why this spreads quickly

Microsoft 365 is intentionally designed to support connected work. Within that environment, Microsoft SharePoint governs how information is shared, Microsoft Teams structures collaboration in shared digital spaces, and Microsoft Outlook sustains communication across the organisation.

These capabilities are central to productivity. When an attacker operates from a legitimate account, the same collaborative design that supports productivity also supports internal movement. Within that environment:

  • File shares appear consistent with normal collaboration
  • Authentication prompts align with expected workflows
  • Access extends through established trust relationships

The compromised identity carries organisational credibility, allowing activity to continue without immediate suspicion.

Where AI changes the equation

The introduction of AI capabilities such as Microsoft Copilot adds another dimension to this pattern.

Microsoft Copilot surfaces insight based on existing permissions across Microsoft 365, reflecting the structure and governance already in place. When identity controls align with role accountability and information architecture is clearly defined, AI supports productivity within those boundaries. Visibility within the environment is shaped directly by how access has been configured.

AI also influences how phishing techniques continue to develop. Generative tools allow attackers to produce communication that reflects organisational language and context. Messages can align closely with current projects or recent activity, which reduces obvious inconsistencies in tone or workflow.

Once access is established, AI-driven tools can assist with navigating large volumes of information or identifying high-value content more efficiently. This places greater emphasis on maintaining well-defined access boundaries and regularly reviewing how permissions are assigned within Microsoft Modern Workplace.

As organisations expand their use of AI, the relationship between Microsoft Modern Workplace design and responsible AI adoption becomes increasingly interconnected.

What to watch for

User awareness remains one of the most effective safeguards.

Pause when you notice:

  • A Microsoft SharePoint file share arriving without prior context
  • An authentication prompt appearing outside your usual workflow
  • A request from a known contact that feels inconsistent with recent activity

Verification through an alternate communication channel is a simple and effective control. Taking a moment before entering credentials can interrupt the progression of secondary compromise.

Strengthening the structural response

Key areas for review include:

  • Conditional access configuration within Microsoft Entra ID
  • Multi-factor authentication coverage
  • Microsoft SharePoint external sharing settings
  • Monitoring for unusual sign-in behaviour

These measures are not about limiting collaboration. They ensure that identity, access, and sharing controls remain aligned as Microsoft 365 usage expands and new technologies are introduced.

Cyber awareness training should also evolve to reflect that phishing techniques now operate within trusted platforms, instead of solely through external email campaigns.

A connected environment requires connected awareness

As work becomes more integrated within Microsoft 365, phishing techniques increasingly reflect that integration. Effective defence combines disciplined identity governance with users who recognise how trust can be leveraged within connected environments.

Designing and maintaining that structure requires a deep understanding of identity architecture, Microsoft SharePoint governance, access control design, and information protection within Microsoft 365.

Danet works with organisations to align Microsoft Modern Workplace environments to operational requirements and security standards, ensuring collaboration remains seamless while governance remains embedded.

Connected work brings opportunity. With considered design and ongoing oversight, organisations can support secure collaboration, responsible AI adoption, and sustained growth.