• Home
  • News
  • Contact us
  • Support
Tecnica LtdTecnica LtdTecnica LtdTecnica Ltd
  • Managed IT Services
  • Solutions
    • Virtualization
    • Storage Solutions
    • Remote Access
    • VoIP Phone Systems
    • Upgrades and Migration
    • Networking
  • Cloud Services
  • Cyber Security
  • Professional Services
    • IT Consultancy
    • Design and Implementation
    • Web and App Development
    • Service Management (ITSM)
    • SharePoint Development
    • Microsoft Solutions
  • About Us
    • Contact Us
    • Case Studies
    • Our Partners
    • Careers
    • Privacy Policy

Microsoft 365 Business users targeted by Cyber Criminals

    Home Blog Cyber Security News Microsoft 365 Business users targeted by Cyber Criminals
    NextPrevious

    Microsoft 365 Business users targeted by Cyber Criminals

    By Tecnica | Cyber Security News, Microsoft Services | Comments are Closed | 7 September, 2022 | 0

    Microsoft 365 Business users have been targeted by Cyber Criminals in attempt to maliciously divert business payments. Research has found there is a recent email campaign sent out by fraudsters in attempts to leverage weakness’s in the Multi-factor Authentication system, Microsoft Authenticator and Microsoft 365 Identity Protection.

    The email campaign in question is said to hijack the users email address’s through phishing emails said to mascaraed from a reputable source – DocuSign. Users are prompted to to ‘Review Document’ and from there prompted to add their Microsoft Azure password, cookies within the webpage are used to take the login and MFA details. From there the attacker is able to set up a second Authenticator app. To gain access without the user even realising.

    The email and webpage look authentic to the user and difficult to spot even evading email filtering systems.

    Once the criminals have access to emails, they have taken over business payments by sending emails to change bank details to their clients through an imitator email address. The recipient of this email is led to believe that the usual bank details have been frozen and update the details to the new bank details belonging to the Cyber Criminals. Which in turn causes the recipient to pay the attacker.

    The attacker can remain ‘dormant’ for some time before attacking, waiting for a potential business deal to arise and watching emails.

    Microsoft in response to this malicious email campaign has advised users to set up another ‘layer of defense’:

    “We strongly recommend setting up another layer of defense, in the form of a third factor, tied to a physical device or to the employee’s authorized laptop and phone.”

    “Microsoft 365 offers this as part of Conditional Access by adding a requirement to authenticate via an enrolled and compliant device only, which would completely prevent [these] attacks.” – Microsoft

    Cyber threats continue to grow, with the complexity and severity becoming increasingly severe. Attacks on small and large organisations is increasingly more common. At Tecnica we deliver a range of secure IT Services and Solutions. As a Microsoft Gold Partner we are the trusted provider to ensure your Microsoft Services are secure. To discover more how Tecnica could secure your organisation and prevent being targeted by Cyber Criminals visit: IT Security – Scotland, Fife, Edinburgh, Glasgow, Aberdeen, Perth (tecnica-ltd.co.uk)

    No tags.

    NextPrevious

    Useful Links

    • Contact Us
    • News


    Services

    • Managed Services
    • Solutions
    • Cloud Services
    • Cyber Security
    • Professional Services

    Contact Us

    Head Office
    5 Castle Court, Carnegie Campus,
    Dunfermline, Fife,
    KY11 8PB,
    Registered in Scotland SC250307
    Phone Number 01383 722757
    Email Address enquiries@tecnica-ltd.co.uk

    Cookie Policy
    Living Wage Employer
    Copyright 2026 Tecnica Ltd | All Rights Reserved
    • Home
    • Managed IT Services
    • Solutions
      • Virtualization
      • Storage Solutions
      • Remote Access
      • VoIP Phone Systems
      • Upgrades and Migration
      • Networking
    • Cloud Services
    • Cyber Security
    • Professional Services
      • IT Consultancy
      • Design and Implementation
      • Service Management (ITSM)
      • Web and App Development
      • SharePoint Development
    • About Us
      • Contact Us
      • Case Studies
      • Our Partners
      • Privacy Policy
      • Careers
    • News
    Tecnica Ltd
    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}