Microsoft 365 Under Attack: New Sophisticated Phishing Campaigns Targeting Users
Legitimate Domain, Malicious Intent: The New Face of Microsoft 365 Attacks
Two active campaigns abuse real Microsoft infrastructure to reach Houston inboxes. Five steps to recognize the lure, verify the source, and shut the door before an account falls.
Microsoft 365 phishing campaign defense starts with one uncomfortable fact: the emails hitting your inbox can be signed, authenticated, and sent through Microsoft's real mail servers, and still be a scam.
Two campaigns disclosed since early 2025 have moved past the sloppy fakes most people are trained to spot. Guardz documented attackers who spin up their own Microsoft 365 tenants, rename the organization field to read like a fraudulent subscription charge, and let Microsoft itself send the phishing email. Proofpoint documented a second set of attackers building fake OAuth apps that pose as Adobe, DocuSign, RingCentral, and SharePoint to harvest logins. Both pass SPF, DKIM, and DMARC because the mail really did come from Microsoft. That is what makes them dangerous for a Houston business running lean on IT.
This guide walks the five steps that actually work against these two campaigns, in the order that closes the most exposure fastest. The step most businesses get wrong is the MFA one, because the multifactor most companies deployed does not stop the attack Proofpoint found.
How Do You Recognize a Microsoft 365 Phishing Lure That Looks Real?
Step 1 is knowing what these two campaigns actually look like, because both are built to survive the "does this look fake?" test.
Recognizing the lure means judging the message by what it asks you to do, not by how legitimate it looks, because both of these campaigns are designed to look completely legitimate.
The Guardz campaign lands as a Microsoft subscription or billing notice. The organization name field is rewritten to read like a charge you never made, something close to "(Microsoft Corporation) Your subscription has been successfully purchased for $689.89. If you did not authorize this transaction, please call" followed by a phone number the attacker controls. The email is real, sent by Microsoft, and passes every authentication check. The trap is the phone number. Call it and a fake support agent walks you into handing over access or installing remote software. The whole point is to move you off email, where security tools watch, and onto a voice call, where nothing does.
The Proofpoint campaign lands as a document or file-sharing request. You click, and a consent screen asks you to approve an app named to look like Adobe Drive, Adobe Acrobat, or DocuSign. Approving it either grants the attacker permissions to your account data or bounces you to a login page that steals your credentials in real time. Proofpoint counted more than 50 impersonated apps, including four posing as Adobe and five posing as DocuSign.
- Step 1 - Recognize the two lures. A surprise Microsoft charge with a refund or dispute phone number is the billing scam - the number is the payload. An unexpected consent screen for an Adobe or DocuSign app, especially after clicking a shared file, is the OAuth scam. Treat urgency about money and any request to approve app permissions as the two loudest warning signs.
Here is the pattern we see with Houston businesses: the fake billing email works best on owners and finance staff, because a surprise charge feels like something to fix right now. The OAuth consent screen works best on everyone else, because clicking "Accept" on a Microsoft-looking prompt is muscle memory. Both campaigns bet on a busy person acting fast. Slowing down for ten seconds is most of the defense.
How Do You Verify the Sender, the URL, and the Phone Number?
Step 2 turns "this feels off" into a decision you can defend, using the details attackers cannot fully fake.
Verification means checking the parts of a message the attacker does not control, because they can borrow Microsoft's authentication but they cannot make a scam phone number into a real Microsoft one.
Authentication passing is not proof the message is safe here - it is proof the mail came from Microsoft's servers, which is exactly what these campaigns arrange. So verify the details underneath. On the billing scam, the sending tenant often traces back to an unfamiliar .onmicrosoft.com address, and the return-path header can carry a giveaway like bounces+SRS= pointing at an onmicrosoft.com domain you have never dealt with. Never call the number in the email. Look up Microsoft's real support number independently, or check your billing directly in the Microsoft 365 admin center where an actual charge would appear.
- Step 2 - Verify before you act. For a billing email: do not call the listed number, confirm charges only inside the Microsoft 365 admin center, and check the sender tenant and return-path for an unknown
onmicrosoft.comorigin. For a consent screen: stop and read the app name and publisher, and cancel any app you did not deliberately go looking for. Hover every link and confirm the real domain before you click.
For the OAuth campaign, the URL is the tell. The consent prompt or the page behind the shared file often sits on a domain that has nothing to do with Microsoft, Adobe, or DocuSign. A real DocuSign request comes from DocuSign, not from a random tenant asking you to grant an app broad access to your mailbox. When in doubt, close the tab and open the service yourself from a known-good bookmark.
Not Sure Which OAuth Apps Already Have Access to Your M365?
CinchOps audits the third-party apps connected to your Microsoft 365 tenant, flags risky consent grants, and locks down the settings both of these campaigns exploit - for Houston and Katy area businesses.
Talk to CinchOpsWhy Does Ordinary MFA Fail, and What Actually Stops It?
Step 3 is the one most businesses get wrong, because the multifactor they already turned on does not stop the Proofpoint attack.
Phishing-resistant MFA is multifactor that binds your login to the real Microsoft domain, and it is the only kind that stops the adversary-in-the-middle attack the OAuth campaign uses to walk straight past a push notification.
Here is the mechanism that trips people up. The Proofpoint OAuth campaign feeds victims into an adversary-in-the-middle phishing kit, mostly a kit called Tycoon. The kit sits between you and the real Microsoft login as a proxy. You type your password, you approve the push notification or type the six-digit code, and the kit relays all of it to Microsoft in real time, then steals the resulting session token. Your MFA worked perfectly and the attacker is now logged in as you. Proofpoint tracked attempted compromises across nearly 3,000 accounts in more than 900 Microsoft 365 environments, with a success rate above 50 percent since early 2025. Push and one-time codes are why the success rate is that high.
Phishing-resistant MFA breaks this by design. FIDO2 security keys and passkeys, along with Windows Hello for Business, cryptographically tie your authentication to the genuine login domain. When the Tycoon proxy sits in the middle on its own lookalike domain, the key simply refuses to respond, because the domain is wrong. CISA and NIST classify FIDO2 keys, passkeys, and certificate-based authentication as phishing-resistant, and they explicitly exclude SMS codes, one-time passcodes, and push notifications, because a proxy can intercept all three.
- Step 3 - Enforce phishing-resistant MFA. Move admin, finance, and executive accounts to FIDO2 hardware keys or passkeys first, then roll out to the rest of the company. Keep push and app-code MFA only as a fallback, not the front line. This is the single control that neutralizes the AiTM session-theft step, which is where the OAuth campaign does its real damage.
Every business I talk to says the same thing - "we have MFA, we are fine." Then I show them how a proxy kit relays their push approval and lifts the session token anyway. The multifactor most companies bought stops password guessing. It does not stop this. A fifteen-dollar security key does, because it will not answer to a fake domain. That is not an upgrade you schedule for next year.
Roll Out Phishing-Resistant MFA Without the Guesswork
CinchOps deploys FIDO2 keys and passkeys across Microsoft 365, sets conditional-access policies that block the AiTM login path, and trains your team on what a real Microsoft prompt looks like. It is part of our cybersecurity and managed IT services for Houston-area businesses.
Explore CinchOps cybersecurity services →How Do You Report It and Contain the Damage Fast?
Step 4 is what happens after someone clicks or calls, because assuming nobody ever will is how a small mistake becomes a breach.
Reporting and containment mean giving staff a one-click way to flag a suspect message and giving IT a fast path to revoke access, because the window between a click and a takeover is short.
Somebody in your business will eventually approve the app or call the number. The measure of a defense is how fast you catch it and how much you can undo. Make reporting effortless with the Microsoft Report Phishing button so a suspect email reaches IT in one click instead of sitting ignored. Tell people plainly that reporting a mistake immediately is rewarded, never punished - the fastest way to guarantee a breach is to make staff afraid to raise their hand.
- Step 4 - Report fast and contain faster. If someone approved a suspicious OAuth app, revoke that app's consent and its refresh tokens, force a sign-out of all sessions, and reset the password on a clean device. If someone called the billing number, treat any remote-access software they were told to install as a compromise and disconnect that machine. Then check sign-in logs for the account across the last few days.
The billing scam has a different containment shape than the OAuth one. If nobody called the number, the fake email is loud but harmless - report and delete it. If someone did call, the risk moved to whatever the fake agent talked them into, usually remote-access software or a payment. For the OAuth scam, the damage is a live session in the attacker's hands, so revoking tokens and forcing re-authentication is the move that actually locks them out.
How CinchOps Hardens Houston Businesses Against These Campaigns
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, turning a scattered set of Microsoft 365 defenses into a tenant that holds up against both of these campaigns.
CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. Step 5 - hardening the tenant - is ongoing work, exactly what a managed partner handles day to day:
- Phishing-resistant MFA rollout. FIDO2 keys and passkeys deployed across Microsoft 365, starting with admin, finance, and executive accounts.
- OAuth app governance. Require admin consent for third-party apps, audit existing consent grants, and remove risky ones, aligned with the default hardening Microsoft rolled out in 2025.
- Email and identity monitoring. Watching for unfamiliar tenant senders, suspicious consent events, and impossible-travel sign-ins so a takeover attempt is caught early.
- Security awareness training. Teaching your team to recognize the fake-billing phone lure and the fake-app consent screen, since staff are the ones these campaigns target.
You do not need an in-house security team to shut down attacks that abuse Microsoft's own infrastructure - you need a partner who has closed these exact gaps before and keeps them closed. If your business in Houston or Katy is running Microsoft 365 with push MFA and no idea which apps have access, talk to CinchOps and we will harden the tenant before someone tests it for you.
Frequently Asked Questions
What is the new Microsoft 365 phishing campaign?
There are two active campaigns. Guardz documented attackers who create their own Microsoft 365 tenants, rename the organization field to look like a fraudulent charge, and let Microsoft send the email so it passes authentication. Proofpoint documented fake OAuth apps posing as Adobe and DocuSign that redirect users to credential-stealing pages.
Why do these phishing emails pass spam filters?
Because the mail genuinely comes from Microsoft's servers. Both campaigns abuse real Microsoft infrastructure, so the messages pass SPF, DKIM, and DMARC and carry authentic branding. Passing those checks proves the email came from Microsoft, not that it is safe, which is exactly why these attacks slip past traditional filters that trust authentication alone.
Does MFA stop the Microsoft 365 OAuth phishing attack?
Not the common kind. The OAuth campaign uses an adversary-in-the-middle kit called Tycoon that relays your password and push approval to Microsoft and steals the session token. Push notifications and one-time codes do not stop it. Only phishing-resistant MFA - FIDO2 keys or passkeys that bind login to the real domain - blocks the attack.
How many businesses has the OAuth campaign hit?
Proofpoint tracked attempted account compromises across nearly 3,000 user accounts in more than 900 Microsoft 365 environments, with a success rate above 50 percent since early 2025. It used over 50 impersonated apps, including several posing as Adobe and DocuSign. Microsoft began tightening default third-party app consent settings in mid-2025 in response.
What should a Houston business do first to defend Microsoft 365?
Move admin, finance, and executive accounts to phishing-resistant MFA such as FIDO2 keys or passkeys, then audit which third-party OAuth apps already have access to your tenant and require admin consent for new ones. Those two steps close the widest gaps both campaigns exploit, before touching anything else.
Discover More
Sources
- Guardz, Sophisticated Phishing Campaign Exploiting Microsoft 365 Infrastructure (tenant / billing-email attack)
- Proofpoint, Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing (~3,000 accounts, 900+ tenants, Tycoon AiTM)
- BleepingComputer, Malicious Adobe, DocuSign OAuth Apps Target Microsoft 365 Accounts
- CISA, Implementing Phishing-Resistant MFA (FIDO2 / WebAuthn guidance)