Phishing hides in routine Microsoft 365 workflows
Summary
Attackers are abusing Microsoft 365 Groups, Outlook, shared files, and calendar invitations to make phishing activity look like normal work. The lure often starts with an attacker-controlled group that uses urgent themes such as payroll, renewals, or training to push users into action. Fortra describes several CalPhishing techniques that use calendar items and .ics files to repeatedly expose victims to malicious prompts. The campaign can lead to credential theft, malware delivery, and data exposure, and it also makes investigations harder because the activity is spread across multiple Microsoft collaboration surfaces.
Classifications
industries
No industries detected
applications
Accounting and Taxes
AskAI Classifications
Labels
SaaS
Cloud Computing
Enterprise Software
Linked Companies
HelpSystems, LLC
$100M to $250M
Microsoft
$1B+