Grand Duchy of Luxembourg
Back to the news

Ongoing phishing campaigns - Microsoft 365

Wed, May 21, 2025
Ongoing phishing campaigns - Microsoft 365

Be careful of ongoing phishing campaigns targeting organisations using Microsoft 365, specifically Office 365 tenants where Multi-Factor Authentication (MFA) is not enforced!

If MFA is not enabled on a user’s Microsoft 365 account, a successful phishing attack allows the attacker to immediately access the account using the stolen credentials.

CIRCL observed more than 48 organisations with Microsoft 365 accounts compromised in the past 7 days in Luxembourg.

CIRCL has published a series of recommendations in the following report: https://www.circl.lu/pub/tr-94/