August 15, 2026 03:22 am (IST)
Follow us:
facebook-white sharing button
twitter-white sharing button
instagram-white sharing button
youtube-white sharing button
Ajit Doval breaks silence on Operation Sindoor in Discovery’s explosive new docuseries | Rahul Gandhi's 'mock hug' taunt sparks row; Centre stresses 'mutual respect' with Italy | Delhi on high alert: Bomb threat to High Court, airport and multiple locations ahead of I-Day | ‘Who are they to interfere?’: CJI Surya Kant slams Bar Council of India over NALSAR students’ enrolment row | 'Shows how low Congress has sunk': BJP slams Rahul Gandhi over Modi foreign policy jibe | From guns to glamour: Former women Maoists walk the ramp in Chhattisgarh | Netaji row: Suvendu Adhikari govt strips BJP MP Anant Maharaj of state honour | Sukhbir Badal attacked by Nihang Sikh with kirpan at Maharashtra gurdwara; assailant detained | ‘If you cannot do it, we will pass an order’: Supreme Court’s final warning to Centre on food labels | ‘Time to move on’: Bombay HC sends strong message in Vijay Mallya-bank dispute
Microsoft
Microsoft reveals massive global phishing attack . Photo: Unsplash

35,000 users hacked? Microsoft reveals massive global phishing attack

| @indiablooms | May 06, 2026, at 03:20 pm

Microsoft has confirmed a series of sophisticated phishing campaigns targeting more than 35,000 users across over 13,000 organisations in 26 countries, with the majority of victims based in the United States.

According to the company, the attacks were observed between April 14 and April 16 and affected a wide range of industries, including healthcare and life sciences (19%), financial services (18%), professional services (11%), and technology and software (11%). The phishing emails were distributed in multiple waves during this period.

The attackers crafted emails to appear as internal compliance or regulatory communications, using display names such as “Internal Regulatory COC,” “Workforce Communications,” and “Team Conduct Report.” Subject lines included phrases like “Internal case log issued under conduct policy” and “Reminder: employer opened a non-compliance case log.”

The messages falsely claimed that a “code of conduct review” had been initiated and often included organisation-specific details to enhance credibility. Recipients were instructed to open a “personalised attachment” to review case materials. To reinforce legitimacy, the emails stated they were issued through an “authorised internal channel” and that links and attachments had been reviewed for secure access. Some messages also featured a banner indicating encryption via Paubox, a legitimate service associated with HIPAA-compliant communications.

Analysis revealed that the emails were sent using a legitimate email delivery service, likely from a cloud-hosted Windows virtual machine, and originated from multiple attacker-controlled domains. Each email included a PDF attachment with filenames such as “Awareness Case Log File – Tuesday 14th, April 2026.pdf” and “Disciplinary Action – Employee Device Handling Case.pdf.”

These attachments provided additional details about the supposed conduct review and directed users to click a “Review Case Materials” link. This link initiated a credential-harvesting process.

Users were first redirected to attacker-controlled domains, such as “acceptable-use-policy-calendly[.]de” or “compliance-protectionoutlook[.]de,” where they encountered a CAPTCHA challenge presented as a security check. This step likely served to evade automated detection systems.

After completing the CAPTCHA, users were taken to an intermediate page stating that the documents were encrypted and required authentication. They were then prompted to click a “Review & Sign” button, leading to a fake sign-in page requesting their email credentials, followed by another CAPTCHA verification.

Once completed, users were shown a message indicating successful verification and were redirected to a final site. The destination varied depending on whether the user accessed the link via mobile or desktop.

On the final page, victims were told that their case materials had been securely logged and maintained within a centralised compliance system. They were then prompted to schedule a discussion, which again required signing in—effectively capturing their login credentials.

Microsoft noted that while some elements resembled device code phishing, the confirmed attack chain primarily involved adversary-in-the-middle (AITM) techniques to harvest user credentials.

Support Our Journalism

We cannot do without you.. your contribution supports unbiased journalism

IBNS is not driven by any ism- not wokeism, not racism, not skewed secularism, not hyper right-wing or left liberal ideals, nor by any hardline religious beliefs or hyper nationalism. We want to serve you good old objective news, as they are. We do not judge or preach. We let people decide for themselves. We only try to present factual and well-sourced news.

Support objective journalism for a small contribution.