DEFENDERBOX - LOGO PNG
Meet us at the May 20 & 21 on the Cybersecurity Europe in Brussels! Learn more here!

When protection becomes a weak point

DEFENDERBOX informs: When protection becomes a vulnerability - link-wrapping attacks on Microsoft 365 accounts

Link wrapping attacks on Microsoft 365 accounts

Phishing is becoming increasingly sophisticated - as shown by a recent case made public by Cloudflare. Microsoft 365 accounts in particular were attacked. With protection systems that became a weak point.

Cyber criminals combine several techniques to undermine even well-protected systems.

This is how the new attack technique works:

  1. Compromised accounts send emails with malicious links.

  2. These are shortened in advance using URL shorteners.

  3. Security solutions such as Proofpoint or Intermedia then intervene - and wrap the URLs in a supposedly secure link wrapping, i.e. in a trustworthy domain.

  4. The recipients do not see any danger at first glance - the attack appears to be "released".

  5. The click leads to deceptively genuine Microsoft 365 login pages that capture login data.

What makes this method so dangerous?

  • Protection systems are tricked because the links appear to be harmless.

  • Recipients do not see a warning because the senders often appear legitimate.

  • Trust in security technologies is being exploited.

What companies should do now:

  • Do not rely on automatic detection.

  • Regularly check the attack surface, even across established services.

  • Use proactive managed security checks such as DEFENDERBOX to simulate attacks and uncover security vulnerabilities before they are exploited.

Because the attackers know your protection mechanisms - and they know how to use them against you.

👉 Do you want to know how your IT security is doing? Find out now here Start cyber check. 

Stay vigilant - your IT will stay that way with us. 

 

How vulnerable is your company really?

Find out - with the DEFENDERBOX.

More DEFENDERBOX articles:

IHK-Siegen focuses on cybersecurity with the DEFENDERBOX

Hacker attacks are no longer only directed against large companies. In addition to public authorities, small companies are also targets....

89% critical security vulnerabilities

Cyberattacks and data leaks have serious consequences for companies, authorities and private individuals....

Keep your eyes open when it comes to cyber security

In the annual „ISC2 Cybersecurity Workforce Study 2023“, 14,865 cybersecurity professionals were surveyed online....