The Atlanta Journal-Constitution

Phishing campaign hits Microsoft in 62 countries

Targeting businesses, recent emails capitalize on pandemic.

- By Alyza Sebenius

Microsoft Corp. customers were targeted in a massive phishing campaign that has sought to defraud users in 62 countries since December. Recently, the malicious emails have evolved to capitalize on the pandemic, according to Microsoft.

The attack “targeted business leaders across a variety of industries, attempting to compromise accounts, steal informatio­n and redirect wire transfers,” Microsoft said Tuesday in a blog post. The campaign was vast, hitting millions of Microsoft Office 365 users with attempted hacks in a single week, the company said.

Microsoft was able to disrupt the scheme through a recent court ruling, which allowed the company to take over domains used by the cyber criminals and prevent them from being used for cyberattac­ks, according to the post.

The phishing attacks were executed by hackers who posed as employers and other trusted senders in emails that were sent to users of Office 365. The messages contained attachment­s that, when clicked, prompted users to grant access to a web applicatio­n that resembled those “widely used in organizati­ons.” However, in this case, the “familiar-looking” applicatio­ns were malicious and granting access let cyber-attackers into users’ Office 365 accounts, according to the company.

“The criminals attempted to gain access to customer email, contact lists, sensitive documents and other valuable informatio­n,” the blog said.

In the early part of the hacking campaign, the attachment­s had titles related to standard business terms, such as “Q4 Report — Dec19.” However, the hackers recently renewed their phishing efforts using attachment names related to the pandemic, such as “COVID-19 Bonus,” according to Microsoft.

Coronaviru­s-themed phishing attacks have become so pervasive in recent months that the U.S. and U.K. government­s warned about their growing use. For example, in March, the number of attempted phishing emails sent by criminals and state-linked actors more than quadrupled amid the spreading virus, the cybersecur­ity firm FireEye Inc. reported. And, this spring, a barrage of cyberscams and hacking attempts related to the virus hit remote workers as criminals sought to profit from the pandemic.

 ?? STEVEN SENNE / ASSOCIATED PRESS ?? The company says the phishing campaign was vast, hitting millions of Microsoft Office 365 users with attempted hacks in a single week. The attack “targeted business leaders.”
STEVEN SENNE / ASSOCIATED PRESS The company says the phishing campaign was vast, hitting millions of Microsoft Office 365 users with attempted hacks in a single week. The attack “targeted business leaders.”

Newspapers in English

Newspapers from United States