CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT Services
    • Cybersecurity
    • Business Continuity & Disaster Recovery (BCDR)
    • Virtual CTO & CIO Services
    • Cloud Services
    • Software Defined Wide Area Networks (SD-WAN)
    • Voice Over IP (VoIP)
    • Business Process Automation
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise IT Services & Support in Houston, TX
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Law Firms
    • Manufacturing
    • Oil & Gas Services
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Reviews
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Contact
I Need IT Support Now
Managed IT Houston Cybersecurity
Shane Stevens
Shane Stevens March 18th, 2025

Microsoft 365 Under Attack: New Sophisticated Phishing Campaigns Targeting Users

Legitimate Domain, Malicious Intent: The New Face of Microsoft 365 Attacks

Cybersecurity Alert
A Microsoft Billing Email Lands, Signed and Legitimate. This Microsoft 365 Phishing Campaign Defense Is How You Beat It.

Two active campaigns abuse real Microsoft infrastructure to reach Houston inboxes. Five steps to recognize the lure, verify the source, and shut the door before an account falls.

TL;DR
Microsoft 365 phishing campaign defense is the set of steps that stops attacks abusing Microsoft's own systems. Two active campaigns use real Microsoft infrastructure: one fakes a billing email to make you call a scam phone number, the other uses malicious OAuth apps posing as Adobe or DocuSign to steal your login. The five steps that matter: recognize the lure, verify the sender and URL, enforce phishing-resistant MFA, report it fast, and harden your M365 tenant. Push MFA alone will not save you here.
🎣 Recognize the Lure 🔎 Verify Sender and URL 🔐 Enforce Phishing-Resistant MFA 🚨 Report and Contain 🚀 How CinchOps Helps

Microsoft 365 phishing campaign defense starts with one uncomfortable fact: the emails hitting your inbox can be signed, authenticated, and sent through Microsoft's real mail servers, and still be a scam.

Two campaigns disclosed since early 2025 have moved past the sloppy fakes most people are trained to spot. Guardz documented attackers who spin up their own Microsoft 365 tenants, rename the organization field to read like a fraudulent subscription charge, and let Microsoft itself send the phishing email. Proofpoint documented a second set of attackers building fake OAuth apps that pose as Adobe, DocuSign, RingCentral, and SharePoint to harvest logins. Both pass SPF, DKIM, and DMARC because the mail really did come from Microsoft. That is what makes them dangerous for a Houston business running lean on IT.

This guide walks the five steps that actually work against these two campaigns, in the order that closes the most exposure fastest. The step most businesses get wrong is the MFA one, because the multifactor most companies deployed does not stop the attack Proofpoint found.

Start here: if you do one thing this week, move admin and finance accounts to phishing-resistant MFA (FIDO2 keys or passkeys) and review which third-party OAuth apps already have access to your Microsoft 365 tenant. Those two moves close the widest gaps these campaigns exploit.
MICROSOFT 365 PHISHING: THE 5-STEP DEFENSE THREAT 1 · FAKE BILLING (Guardz) Attacker-owned tenant renames org field, Microsoft sends the email, you call a scam number. THREAT 2 · OAUTH APPS (Proofpoint) Fake Adobe / DocuSign apps redirect to an AiTM kit that steals your session and beats push MFA. 1 RECOGNIZE Fake charge, refund number, urgent tone, surprise app consent 2 VERIFY Return-path headers, onmicrosoft sender, real support number 3 MFA Phishing-resistant: FIDO2 keys, passkeys. Push alone fails here. 4 REPORT One-click report, revoke sessions, reset fast 5 HARDEN Admin consent for apps, audit OAuth, monitor tenants CinchOps · cinchops.com
Two active Microsoft 365 phishing campaigns and the five-step defense - step three is the one most businesses get wrong.

How Do You Recognize a Microsoft 365 Phishing Lure That Looks Real?

Step 1 is knowing what these two campaigns actually look like, because both are built to survive the "does this look fake?" test.

Recognizing the lure means judging the message by what it asks you to do, not by how legitimate it looks, because both of these campaigns are designed to look completely legitimate.

The Guardz campaign lands as a Microsoft subscription or billing notice. The organization name field is rewritten to read like a charge you never made, something close to "(Microsoft Corporation) Your subscription has been successfully purchased for $689.89. If you did not authorize this transaction, please call" followed by a phone number the attacker controls. The email is real, sent by Microsoft, and passes every authentication check. The trap is the phone number. Call it and a fake support agent walks you into handing over access or installing remote software. The whole point is to move you off email, where security tools watch, and onto a voice call, where nothing does.

The Proofpoint campaign lands as a document or file-sharing request. You click, and a consent screen asks you to approve an app named to look like Adobe Drive, Adobe Acrobat, or DocuSign. Approving it either grants the attacker permissions to your account data or bounces you to a login page that steals your credentials in real time. Proofpoint counted more than 50 impersonated apps, including four posing as Adobe and five posing as DocuSign.

  • Step 1 - Recognize the two lures. A surprise Microsoft charge with a refund or dispute phone number is the billing scam - the number is the payload. An unexpected consent screen for an Adobe or DocuSign app, especially after clicking a shared file, is the OAuth scam. Treat urgency about money and any request to approve app permissions as the two loudest warning signs.

Here is the pattern we see with Houston businesses: the fake billing email works best on owners and finance staff, because a surprise charge feels like something to fix right now. The OAuth consent screen works best on everyone else, because clicking "Accept" on a Microsoft-looking prompt is muscle memory. Both campaigns bet on a busy person acting fast. Slowing down for ten seconds is most of the defense.

How Do You Verify the Sender, the URL, and the Phone Number?

Step 2 turns "this feels off" into a decision you can defend, using the details attackers cannot fully fake.

Verification means checking the parts of a message the attacker does not control, because they can borrow Microsoft's authentication but they cannot make a scam phone number into a real Microsoft one.

Authentication passing is not proof the message is safe here - it is proof the mail came from Microsoft's servers, which is exactly what these campaigns arrange. So verify the details underneath. On the billing scam, the sending tenant often traces back to an unfamiliar .onmicrosoft.com address, and the return-path header can carry a giveaway like bounces+SRS= pointing at an onmicrosoft.com domain you have never dealt with. Never call the number in the email. Look up Microsoft's real support number independently, or check your billing directly in the Microsoft 365 admin center where an actual charge would appear.

  • Step 2 - Verify before you act. For a billing email: do not call the listed number, confirm charges only inside the Microsoft 365 admin center, and check the sender tenant and return-path for an unknown onmicrosoft.com origin. For a consent screen: stop and read the app name and publisher, and cancel any app you did not deliberately go looking for. Hover every link and confirm the real domain before you click.

For the OAuth campaign, the URL is the tell. The consent prompt or the page behind the shared file often sits on a domain that has nothing to do with Microsoft, Adobe, or DocuSign. A real DocuSign request comes from DocuSign, not from a random tenant asking you to grant an app broad access to your mailbox. When in doubt, close the tab and open the service yourself from a known-good bookmark.

PASSES CHECKS ≠ SAFE WHAT PASSES (IGNORE AS PROOF) ✓ SPF - Microsoft sent it ✓ DKIM - signature is valid ✓ DMARC - alignment holds ✓ Real Microsoft branding ✓ Legitimate-looking UI WHAT TO CHECK (THE REAL TELLS) → Unknown onmicrosoft.com sender → bounces+SRS= return-path → Phone number you did not look up → App name / publisher on consent → URL that is not the real service CinchOps · cinchops.com
Both campaigns pass SPF, DKIM, and DMARC by design, so verify the details on the right instead.

Not Sure Which OAuth Apps Already Have Access to Your M365?

CinchOps audits the third-party apps connected to your Microsoft 365 tenant, flags risky consent grants, and locks down the settings both of these campaigns exploit - for Houston and Katy area businesses.

Talk to CinchOps

Why Does Ordinary MFA Fail, and What Actually Stops It?

Step 3 is the one most businesses get wrong, because the multifactor they already turned on does not stop the Proofpoint attack.

Phishing-resistant MFA is multifactor that binds your login to the real Microsoft domain, and it is the only kind that stops the adversary-in-the-middle attack the OAuth campaign uses to walk straight past a push notification.

Here is the mechanism that trips people up. The Proofpoint OAuth campaign feeds victims into an adversary-in-the-middle phishing kit, mostly a kit called Tycoon. The kit sits between you and the real Microsoft login as a proxy. You type your password, you approve the push notification or type the six-digit code, and the kit relays all of it to Microsoft in real time, then steals the resulting session token. Your MFA worked perfectly and the attacker is now logged in as you. Proofpoint tracked attempted compromises across nearly 3,000 accounts in more than 900 Microsoft 365 environments, with a success rate above 50 percent since early 2025. Push and one-time codes are why the success rate is that high.

Phishing-resistant MFA breaks this by design. FIDO2 security keys and passkeys, along with Windows Hello for Business, cryptographically tie your authentication to the genuine login domain. When the Tycoon proxy sits in the middle on its own lookalike domain, the key simply refuses to respond, because the domain is wrong. CISA and NIST classify FIDO2 keys, passkeys, and certificate-based authentication as phishing-resistant, and they explicitly exclude SMS codes, one-time passcodes, and push notifications, because a proxy can intercept all three.

  • Step 3 - Enforce phishing-resistant MFA. Move admin, finance, and executive accounts to FIDO2 hardware keys or passkeys first, then roll out to the rest of the company. Keep push and app-code MFA only as a fallback, not the front line. This is the single control that neutralizes the AiTM session-theft step, which is where the OAuth campaign does its real damage.
Every business I talk to says the same thing - "we have MFA, we are fine." Then I show them how a proxy kit relays their push approval and lifts the session token anyway. The multifactor most companies bought stops password guessing. It does not stop this. A fifteen-dollar security key does, because it will not answer to a fake domain. That is not an upgrade you schedule for next year.
Shane Stevens, CEO, CinchOps - LinkedIn

Roll Out Phishing-Resistant MFA Without the Guesswork

CinchOps deploys FIDO2 keys and passkeys across Microsoft 365, sets conditional-access policies that block the AiTM login path, and trains your team on what a real Microsoft prompt looks like. It is part of our cybersecurity and managed IT services for Houston-area businesses.

Explore CinchOps cybersecurity services →

How Do You Report It and Contain the Damage Fast?

Step 4 is what happens after someone clicks or calls, because assuming nobody ever will is how a small mistake becomes a breach.

Reporting and containment mean giving staff a one-click way to flag a suspect message and giving IT a fast path to revoke access, because the window between a click and a takeover is short.

Somebody in your business will eventually approve the app or call the number. The measure of a defense is how fast you catch it and how much you can undo. Make reporting effortless with the Microsoft Report Phishing button so a suspect email reaches IT in one click instead of sitting ignored. Tell people plainly that reporting a mistake immediately is rewarded, never punished - the fastest way to guarantee a breach is to make staff afraid to raise their hand.

  • Step 4 - Report fast and contain faster. If someone approved a suspicious OAuth app, revoke that app's consent and its refresh tokens, force a sign-out of all sessions, and reset the password on a clean device. If someone called the billing number, treat any remote-access software they were told to install as a compromise and disconnect that machine. Then check sign-in logs for the account across the last few days.

The billing scam has a different containment shape than the OAuth one. If nobody called the number, the fake email is loud but harmless - report and delete it. If someone did call, the risk moved to whatever the fake agent talked them into, usually remote-access software or a payment. For the OAuth scam, the damage is a live session in the attacker's hands, so revoking tokens and forcing re-authentication is the move that actually locks them out.

How CinchOps Hardens Houston Businesses Against These Campaigns

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, turning a scattered set of Microsoft 365 defenses into a tenant that holds up against both of these campaigns.

CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. Step 5 - hardening the tenant - is ongoing work, exactly what a managed partner handles day to day:

  • Phishing-resistant MFA rollout. FIDO2 keys and passkeys deployed across Microsoft 365, starting with admin, finance, and executive accounts.
  • OAuth app governance. Require admin consent for third-party apps, audit existing consent grants, and remove risky ones, aligned with the default hardening Microsoft rolled out in 2025.
  • Email and identity monitoring. Watching for unfamiliar tenant senders, suspicious consent events, and impossible-travel sign-ins so a takeover attempt is caught early.
  • Security awareness training. Teaching your team to recognize the fake-billing phone lure and the fake-app consent screen, since staff are the ones these campaigns target.

You do not need an in-house security team to shut down attacks that abuse Microsoft's own infrastructure - you need a partner who has closed these exact gaps before and keeps them closed. If your business in Houston or Katy is running Microsoft 365 with push MFA and no idea which apps have access, talk to CinchOps and we will harden the tenant before someone tests it for you.

100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Frequently Asked Questions

What is the new Microsoft 365 phishing campaign?

There are two active campaigns. Guardz documented attackers who create their own Microsoft 365 tenants, rename the organization field to look like a fraudulent charge, and let Microsoft send the email so it passes authentication. Proofpoint documented fake OAuth apps posing as Adobe and DocuSign that redirect users to credential-stealing pages.

Why do these phishing emails pass spam filters?

Because the mail genuinely comes from Microsoft's servers. Both campaigns abuse real Microsoft infrastructure, so the messages pass SPF, DKIM, and DMARC and carry authentic branding. Passing those checks proves the email came from Microsoft, not that it is safe, which is exactly why these attacks slip past traditional filters that trust authentication alone.

Does MFA stop the Microsoft 365 OAuth phishing attack?

Not the common kind. The OAuth campaign uses an adversary-in-the-middle kit called Tycoon that relays your password and push approval to Microsoft and steals the session token. Push notifications and one-time codes do not stop it. Only phishing-resistant MFA - FIDO2 keys or passkeys that bind login to the real domain - blocks the attack.

How many businesses has the OAuth campaign hit?

Proofpoint tracked attempted account compromises across nearly 3,000 user accounts in more than 900 Microsoft 365 environments, with a success rate above 50 percent since early 2025. It used over 50 impersonated apps, including several posing as Adobe and DocuSign. Microsoft began tightening default third-party app consent settings in mid-2025 in response.

What should a Houston business do first to defend Microsoft 365?

Move admin, finance, and executive accounts to phishing-resistant MFA such as FIDO2 keys or passkeys, then audit which third-party OAuth apps already have access to your tenant and require admin consent for new ones. Those two steps close the widest gaps both campaigns exploit, before touching anything else.

Discover More

How to Prevent Phishing Attacks for Texas SMBs
Why Houston Businesses Need Phishing-Resistant Authentication
Security Awareness Training for SMBs
Malicious Microsoft OneNote Login Pages
ClickFix: The Fake-Fix Social Engineering Trick
CinchOps Cybersecurity Services

Sources

  • Guardz, Sophisticated Phishing Campaign Exploiting Microsoft 365 Infrastructure (tenant / billing-email attack)
  • Proofpoint, Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing (~3,000 accounts, 900+ tenants, Tycoon AiTM)
  • BleepingComputer, Malicious Adobe, DocuSign OAuth Apps Target Microsoft 365 Accounts
  • CISA, Implementing Phishing-Resistant MFA (FIDO2 / WebAuthn guidance)
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

March 9th, 2026
Construction IT
How Much Does Managed IT Cost a 50-Person Construction Company in Houston?

Managed IT Services for Houston Area Construction Companies – Protecting Houston Construction, One Job Site at a Time

February 3rd, 2026
Managed IT Houston
Why CinchOps Is the Best MSP Choice in West Houston

Enterprise Expertise, Local Commitment IT Solutions For West Houston Businesses – Real Industry Experience, Real Business Results

April 21st, 2026
Cybersecurity Houston
Phishing Attacks Targeting Houston Businesses Are Getting Harder to Spot

A Houston Business Owner’s Guide to Email Security and Phishing Prevention – The Case for Layered Phishing Defenses in Houston Area Businesses

August 17th, 2026
Cybersecurity Houston
Texas Hearing Institute Data Breach: What Houston Should Know

How Ransomware Groups Select Specialty Healthcare Targets – A Practical Security Checklist Drawn From A Houston Breach

March 16th, 2026
Law Firm Cybersecurity
Law Firm Cybersecurity: 76% of Greater Houston Firms Do Not Pass Basic Security Standards

Six Security Categories, Over 1,300 Firms: A Data-Driven Assessment – Understanding the Blind Spot Between Passive and Active Security Scores

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT Services
  • Cybersecurity
  • Virtual CTO & CIO
  • Business Continuity & Disaster Recovery for Houston Businesses
  • Cloud Services
  • Business Process Automation for Houston Businesses
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy