Copyright © Sullivan Wright All Rights Reserved
More Microsoft 365 Phishing
Microsoft accounts are one of the largest phishing targets these days. Attackers are trying to get access into your account, get access to install remote access tools on your computer, or just get access to other secrets in your account or on your computer.
In an effort to better secure accounts, Microsoft recently announced that they will disable the ability to receive MFA codes via text message or voice call. These methods will go away in early 2027.
In good cyber crime form, attackers never let a disruption go unexploited. We are already seeing phishing emails themed for setting up passkeys on M365 accounts. Attackers have already developed the backend phishing kits to look very authentic, as well.
Phishing attackers are getting very good at real-time replication of the MFA setup and execution mechanics, so you can't rely on that tell bad from good. Take cues from other places, though. Look at the from email address, look at how the email addresses you (email address versus actual name - your account usually has your name associated), and any other glitches in the content or images. Finally, know that this change does not become mandatory until early next year. Anything you are getting now trying to scare you into setting up a passkey is a bit premature.
If you are one of our clients, you can always report the emails as phishing for us to take a deeper look. If they are legitimate, we can return them right back to your inbox. We'd rather be cautious early than have to spend time investigating and cleaning up after a breach.
If you aren't a client of ours but want to improve your security posture and have better peace of mind, simply contact us and ask!
References:
https://www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accounts-evade-mfa/
https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/
