Office 365 Phishing Attack Investigation

Microsoft Office 365 Phishing Attack Investigation

Office 365 Phishing attacks are on the rise, spear phishing and social engineering methods are used to steal O365 user data, including login credentials. It occurs when an attacker, masquerading as a trusted entity, dupes a victim into opening an email that contains a URL to share a file via sharepoint. Office 365 attacks are classified as Spear phishing  that consist of email spoofing attacks, targeting a specific organization or individual, seeking unauthorized access to sensitive information such as email accounts or file share.

The common Microsoft Office 365 attacks occur when a target, an O365 user gets an email with a link to access a SharePoint document, the type of message Office 365 users receive everyday within their organisation, the sharepoint platform is a standard at millions of companies. The attack happens when an email is sent to a 0365 user, the email is spoofed and the sharepoint hyperlink is a fake. The office 365 user easily gets duped into clicking the URL to access the file, often described as a PDF, but what opens is a spoofed landing page opens where the target is asked to provide their Office 365 login credentials. This is how the hackers / attackers gain access to critical internal email accounts and sharing Office 365 systems, by stealing users login credentials.

Hackers are targeting large organisations that run on office365 and specific targets are group mailboxes. Digitpol investigates hacked office 365 accounts and O365 fraud on a daily basis and can identify if hackers are still active within an organisation and identify how the attack took place. 

Office 365 Phishing Attack Investigation

Digitpol's Cyber and Fraud Team are certified examiners and can assist to all cases related to Office 365 and Email phishing attacks, email scams and fraud. Digitpol can deploy computer forensic examiners to investigate the hack, determine how it took place and report the findings, Digitpol ensures that hackers are not active in your network and ensure your user accounts policies and rules are configured correctly to prevent further attacks. The following points are the first in each O356 attack investigation.

  • Forensic analysis of logs using certified analysis tools, all O365 IP and registry logs with operations such as, User Logged-In logs / User Login Failed / Inbox Rules / change of Inbox rules or policies / change passwords of Microsoft Office365 accounts involved in the attack and suspected accounts or all accounts.
  • If an account holder was hacked by content, attachment or phishing email, we can conduct forensic analysis on suspected emails, headers related to the attack, outgoing and incoming. Email Files are required in raw format (.msg or .eml files).
  • Forensic examination of targeted computers, phones, tablets, forensic analysis of devices to discover malware or active intruders.
  • Server / On-site exchange forensic analysis.

If your company has been targeted by an MS Office 365 phishing attack, we can help you, but only if you act fast!