By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Daily HacklyDaily HacklyDaily Hackly
  • Tech & Digital Trends
  • Entertainment & Lifestyle
  • Money & Smart Living
  • Productivity & Life Hacks
Search
  • Contact
  • Blog
  • Complaint
  • Advertise
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Reading: Cyber Assault Aims at Microsoft 365 User Accounts
Share
Sign In
Notification Show More
Font ResizerAa
Daily HacklyDaily Hackly
Font ResizerAa
Search
  • Home
    • Home 4
  • Categories
  • Bookmarks
  • More Foxiz
    • Sitemap
Have an existing account? Sign In
Follow US
  • Contact
  • Blog
  • Complaint
  • Advertise
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Daily Hackly > Blog > Tech & Digital Trends > Cyber Assault Aims at Microsoft 365 User Accounts
Tech & Digital Trends

Cyber Assault Aims at Microsoft 365 User Accounts

DailyHackly
Last updated: May 13, 2025 5:55 am
DailyHackly
Share
Cyber Assault Aims at Microsoft 365 User Accounts
SHARE

New Cyber Threat Targets Microsoft 365 Users via Messaging Apps

A recent cyber assault is aimed at Microsoft 365 users through messages sent via Signal and WhatsApp. Hackers are masquerading as government officials to infiltrate accounts.

As reported by Bleeping Computer, these malicious actors, believed to be Russian operatives posing as European diplomats, are reaching out to individuals in organizations involved in Ukraine and human rights matters. Their ultimate aim is to deceive targets into clicking on an OAuth phishing link that leads them to verify their Microsoft 365 credentials.

This scheme was initially identified by the cybersecurity firm Volexity, which has noted a focused attack on entities related to Ukraine, though similar tactics could be employed broadly for data theft or device takeovers.

Understanding the Microsoft 365 OAuth Attack

Typically, the assault kicks off when targets receive a message through Signal or WhatsApp, originating from someone posing as a political figure. The communication usually includes an invitation for a video conference to discuss topics surrounding Ukraine.

As per Volexity’s findings, attackers might impersonate representatives from the Mission of Ukraine to the European Union or the Permanent Delegation of Bulgaria to NATO. In some instances, the attack may begin with an email from a compromised Ukrainian government account, followed by subsequent messages via Signal and WhatsApp.

After establishing contact, the perpetrators provide victims with PDF instructions alongside an OAuth phishing link. Clicking this link leads users to a login prompt for Microsoft and various third-party applications utilizing Microsoft 365 OAuth. The victims are redirected to a page requesting an authentication code, which they are advised to share to “join” the meeting. This code remains valid for 60 days and allows the attackers extensive access to email and other Microsoft 365 resources, even if victims alter their passwords.

Identifying the Microsoft 365 OAuth Attack

This cyber threat is one of several recent incidents exploiting OAuth authentication, making it less obvious from a technical standpoint. Volexity recommends implementing conditional access policies for Microsoft 365 accounts that restrict access to approved devices and activating login alerts.

Individuals should also remain vigilant against social engineering techniques that exploit human psychology to effectively execute phishing and related cyber attacks. Warning signs may include messages that seem atypical for a trusted contact, communications designed to elicit emotional responses such as fear or curiosity, and urgent requests or offers that seem too favorable.

A social engineering guide by CSO advises maintaining a “zero-trust mindset” and being aware of typical red flags, including spelling and grammar errors, as well as unexpected instructions to click links or open attachments. Screenshots of the Signal and WhatsApp communications shared by Volexity highlight minor mistakes, which can signal potential fraud.

Stay informed and proactive in safeguarding your digital assets from emerging cyber threats.

You Might Also Like

A Complete Guide to Personalizing Notifications on Your iPhone

Unbeatable Daily Bargain: Discover the Samsung Galaxy Buds 3 Pro on Amazon

Discover Google’s Secret ‘Squid Game’ That You Can Enjoy Immediately

Get This $80 Video Doorbell Now – No Ongoing Subscription Fees Required!

Samsung Introduces the ‘Now Bar’ as Its Response to iOS’s Live Activities Feature

TAGGED:comma-separated tags in French for the title “Cyber Assault Aims at Microsoft 365 User Accounts”: cyberattaquecomptes d’utilisateurscybersécuritégestion des identitéshackersHere’s a list of SEO-optimizedmenaces en ligneMicrosoft 365phishingprévention des cyberattaquesprotection des donnéessécurité cloudsécurité des comptessécurité informatiquevulnérabilités

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
[mc4wp_form]
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Copy Link Print
Share
Previous Article Unbeatable Deal: Get the Original Google Pixel Watch Now for Just $80! Unbeatable Deal: Get the Original Google Pixel Watch Now for Just $80!
Next Article Reviving Minesweeper and Seven Other Timeless Classics in Windows 11 Reviving Minesweeper and Seven Other Timeless Classics in Windows 11
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1kLike
69.1kFollow
134kPin
54.3kFollow
banner banner
Create an Amazing Newspaper
Discover thousands of options, easy to customize layouts, one-click to import demo and much more.
Learn More

Latest News

Google Unveils Innovative AI Models for Visual Content and Video Analysis
Google Unveils Innovative AI Models for Visual Content and Video Analysis
Tech & Digital Trends
Anker Soundcore Open Earbuds Reach Unprecedented Low Pricing
Anker Soundcore Open Earbuds Reach Unprecedented Low Pricing
Tech & Digital Trends
Save $200 on This Dyson Air Purifier Today!
Save $200 on This Dyson Air Purifier Today!
Tech & Digital Trends
A Guide to Implementing Two-Factor Authentication with macOS Password Manager
A Guide to Implementing Two-Factor Authentication with macOS Password Manager
Productivity & Life Hacks
//

We influence 20 million users and is the number one business and technology news network on the planet

Quick Link

  • Contact
  • Blog
  • Complaint
  • Advertise

Support

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

[mc4wp_form id=”1616″]

Daily HacklyDaily Hackly
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Join Us!
Subscribe to our newsletter and never miss our latest news, podcasts etc..
[mc4wp_form]
Zero spam, Unsubscribe at any time.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?