image credit: Jernej Furman / Flickr

A clever phishing campaign is targeting Office 365 users

August 4, 2021

Microsoft is warning about an ongoing, “sneakier than usual” phishing campaign aimed at Office 365 users.

The phishing emails

The phishers are using various themes as lures, and the emails are sent from email addresses from various top-level domains.

The sender addresses contain variations of the word “referral” – e.g.,,,, and similar. The emails are made to look like they point to a shared document stored on Microsoft SharePoint, a web-based collaborative platform that integrates with Microsoft Office, and they include Microsoft branding.

Read More on Help Net Security