Friday, February 3, 2023
  • Login
No Result
View All Result
Atreju
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
    • Home – Layout 4
    • Home – Layout 5
  • World
  • News
  • SPORTS
  • Entertainment
  • Politics
  • Italy
  • Technology
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
    • Home – Layout 4
    • Home – Layout 5
  • World
  • News
  • SPORTS
  • Entertainment
  • Politics
  • Italy
  • Technology
No Result
View All Result
Atreju
No Result
View All Result
ADVERTISEMENT
Home Technology

Fake DHL emails allow hackers to breach Microsoft 365 accounts

by Atreju
January 18, 2023
in Technology
0
A laptop showing lots of email notifications
0
SHARES
6
VIEWS
Share on FacebookShare on Twitter

A new phishing campaign has been uncovered impersonating logistics giant DHL to try and steal Microsoft 365 credentials from victims in the education industry, experts has claimed.

Cybersecurity researchers from Armorblox recently discovered a major phishing campaign, with more than 10,000 emails sent to inboxes belonging to a “private education institution”. 

The email is made to look as if it’s coming from DHL: it carries the company branding as well as tone of voice one might associate with the shipping giant. In the email, titled “DHL Shipping Document/Invoice Receipt” the recipient is informed that a customer sent a parcel to the wrong address and that the correct delivery address needs to be provided.

The email obviously comes with an attachment, conveniently titled “Shipping Document Invoice Receipt” which, if opened, looks like a blurred-out preview of a Microsoft Excel file. 

Over the blurred-out document pops up a Microsoft login page, trying to trick the victims into thinking they need to log into their Microsoft 365 accounts in order to view the contents of the file. Should the victims provide the login credentials, they’d go straight to the attackers.

“The email attack used language as the main attack vector in order to bypass both Microsoft Office 365 and EOP email security controls,” Armorblox explained. “These native email security layers are able to block mass spam and phishing campaigns and known malware and bad URLs. However, this targeted email attack bypassed Microsoft email security because it did not include any bad URLs or links and included an HTML file that included a malicious phishing form.”

As the researchers said, the attackers used a valid domain which allowed them to bypass Microsoft’s email (opens in new tab) authentication checks. 

The best way for businesses to protect against phishing attacks is to train their employees to spot red flags in their inboxes, such as the sender’s email address, typos and spelling errors in the email, the sense of urgency (legitimate emails will almost never require the user to react urgently), and unexpected links/attachments. 

Via: SiliconAngle (opens in new tab)

Atreju

Atreju

Next Post
Prima l’industria, poi i consumatori

Prima l’industria, poi i consumatori

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Aborto, FdI propone una legge per i diritti del concepito

Aborto, FdI propone una legge per i diritti del concepito

2 weeks ago
Riva Arora Wiki Biography, Height, Age, Family, Affairs, Facts & More

Riva Arora Wiki Biography, Height, Age, Family, Affairs, Facts & More

3 weeks ago

Popular News

    Connect with us

    Newsletter

    Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor.
    SUBSCRIBE

    Category

    • Business
    • Entertainment
    • Fashion
    • food
    • Games
    • Gaming
    • Health
    • Italy
    • Lifestyle
    • Movie
    • Music
    • National
    • News
    • Politics
    • Science
    • SPORTS
    • Tech
    • Technology
    • Travel
    • Uncategorized
    • WORLD

    Site Links

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    About Us

    We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

    • About
    • Advertise
    • Careers
    • Contact

    © 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

    No Result
    View All Result
    • Home
    • Politics
    • World
    • Business
    • Science
    • National
    • Entertainment
    • Gaming
    • Movie
    • Music
    • Sports
    • Fashion
    • Lifestyle
    • Travel
    • Tech
    • Health
    • Food

    © 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Create New Account!

    Fill the forms below to register

    All fields are required. Log In

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In