216.73.217.22

Phishing actors exploiting complex routing scenarios and misconfigured spoof protections

· Published 07/01/2026 11:34 · Modified 07/01/2026 11:42

Export JSON

Essential information

Published
07/01/2026 11:34
Modified
07/01/2026 11:42
Tags
2026-01-07 credential-theft dkim dmarc email financial scams phishing spf spoofing tycoon2fa
Related entities
4 observables, 9 techniques (mitre), 1 malware, 6 others

Description

Threat actors are leveraging complex routing scenarios and misconfigured spoof protections to send emails that appear to be internal communications. These attacks, which have increased since May 2025, use various lures like voicemails, shared documents, and password resets to conduct credential and . The campaigns, often using PhaaS platforms like , are opportunistic and target multiple industries. While Microsoft detects most attempts, organizations can further mitigate risks by properly configuring spoof protections and third-party connectors. The attacks do not affect customers whose Microsoft Exchange MX records point to Office 365, as they are protected by built-in detections.

External references