M365 “Direct Send” Abused for Internal-Looking Phish

About DFIR · Medium sophistication
Last updated September 14, 2026

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business hours and often used malicious attachments and mismatched reply-to addresses to capture responses.

Key findings

  • KnowBe4 observed nearly 29,800 confirmed phishing emails in July and August abusing Microsoft 365 Direct Send.
  • Emails were timed to look human-sent, peaking around 2pm U.S. Eastern time on Mondays and Tuesdays.
  • Because Direct Send can make mail appear to originate from an organization’s own domain without an account compromise, “internal-looking” email cannot be assumed safe.
  • Roughly 35% of observed messages had malicious attachments, and thousands used mismatched reply-to addresses.
  • Defenders were advised to look for the header “X-MS-Exchange-Organization-AuthAs: Anonymous,” enforce DMARC reject, and disable Direct Send if not needed.

Who’s being targeted

  • Commonly targeted roles: All employees, Executive assistants, Finance, HR, IT helpdesk, Security team.
  • Affected industries: Any organization using Microsoft 365 (cross-industry).
  • Attack channels: email.
  • Impersonated: Victim organization’s own domain (spoofed internal sender appearance via M365 Direct Send).

Awareness takeaways

  • Treat ‘internal-looking’ email as untrusted, verify unexpected requests even if the sender appears to be your own company domain.
  • Be suspicious of unexpected attachments and don’t open them unless you can confirm the request through a trusted channel.
  • Check for Reply-To mismatches before responding, attackers may redirect your reply to an external address.
  • Have IT/security validate whether Microsoft 365 Direct Send is needed; if not, disable it and harden email authentication.

Red flags to watch for

  • Message looks internal but was sent without an employee account compromise
  • Attachment present in a message that is unexpected for the recipient
  • Reply-To address does not match the apparent internal sender/domain
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email at 2pm on Monday: subject line, “Document attached (please review)”, and it’s from your own company domain. But this could be a Microsoft 365 “Direct Send” phish. KnowBe4 saw nearly 29,800 of these in two months, many timed to feel human-sent, with about a third carrying malicious attachments. Here’s the trick: the email looks internal, but the Reply-To quietly points to an external address, and the attachment is unexpected. Internal-looking does not mean safe. If an “internal” email has an unexpected attachment or odd Reply-To, stop. Don’t open it, forward it to the security team and ask if it’s legit.

Similar attacks

Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
Hotel WiFi Scam Pushes Fake Updates and Malware

Hotel WiFi Scam Pushes Fake Updates and Malware

A Russia-linked threat group compromised hotel WiFi captive portals to redirect guests to fake “verification” pages. Victims were pushed toward either copying commands into a terminal to install malware or entering Microsoft credentials on spoofed login pages that added an attacker-controlled…

August 7, 2026
Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
FBI Warns of OAuth Consent Phishing Tricks

FBI Warns of OAuth Consent Phishing Tricks

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters…

September 11, 2026