Microsoft 365 phishing hides behind Cloudflare bot protection
Researchers at DomainTools have identified a phishing campaign against Microsoft 365 accounts that abuses Cloudflare's security features to evade detection. The attackers use bot protection and human verification to stop automated scanners and security tools from analysing the pages, keeping the infrastructure alive longer. The campaign also uses IP blocklists, user-agent filtering and obfuscated scripts to serve phishing content only to genuine victims.
What this means for your business
The effect is that automated checks report nothing to see on a page that is very much alive for the employee who clicks. Detection resting on your security vendor having analysed the link becomes unreliable, and the defence shifts to what happens after the login attempt. Compromised Microsoft 365 accounts are typically used onward for invoice fraud and to attack customers and partners from an address they trust.
Berigo recommends
- Deploy phishing-resistant multi-factor authentication, such as passkeys or FIDO2 keys, on Microsoft 365.
- Configure conditional access to limit sign-in to known devices and locations.
- Alert on unusual logins, new mail forwarding rules and registration of new authentication methods.
- Rehearse how you shut down a compromised account quickly: sessions must be revoked, not just the password changed.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch