Phishing Campaign Exploiting Microsoft 365 Direct Send Feature Surfaces
A recent investigation has unveiled a sophisticated phishing campaign that exploits Microsoft 365’s Direct Send feature, occurring primarily during standard U.S. Eastern business hours. This alarming development was reported by the KnowBe4 Threat Lab, which documented an extensive 29,785 confirmed phishing emails utilizing this functionality throughout July and August 2026.
The researchers observed a distinct pattern in the timing of the attacks. Notably, attackers demonstrated increased activity particularly from Monday to Tuesday, aligning closely with typical work hours in the Eastern Time Zone. The volume of phishing emails peaked just before noon, with another surge reaching its highest level around 2 PM EST. This behavior reflects a “distinctly human pattern” in the attackers’ approach, which suggests a level of strategic planning aimed at maximizing the likelihood of success.
Understanding the Direct Send Feature
For context, the Direct Send feature serves a legitimate purpose within the Microsoft 365 ecosystem. It allows various devices, such as printers and scanners, along with legacy applications, to send emails without requiring a dedicated email account. Unfortunately, this very feature has become a double-edged sword, with attackers leveraging it to send emails that appear to originate from familiar and trusted internal addresses, such as Human Resources, accounting, or administrative departments.
This tactic strikes a significant blow to organizational defenses, facilitating the distribution of malicious payloads without needing to compromise individual employee accounts or obtain credentials. Furthermore, it enables these attackers to bypass standard email security gateways, connecting directly to the organization’s Exchange Online MX endpoint.
The KnowBe4 report indicates that even if authentication checks are in place, organizations utilizing a domain-based message authentication, reporting, and conformance (DMARC) monitoring policy might still permit these malicious messages to be delivered. This loophole highlights the necessity for companies to reassess their cybersecurity protocols.
The Nature and Impact of Phishing Emails
In the analysis conducted by KnowBe4, approximately 35% of classified phishing emails were found to include risky attachments, with "virtually all" defined as threats. The types of correspondence sent during this campaign included fake requests for documents, internal voicemail notifications, invoices, payment approvals, and fraudulent OneDrive file share notifications. Alarmingly, 4,023 of these malicious emails directed employee responses to a reply-to address that pointed to a different, malicious domain, effectively routing inquiries and potential actions straight to the attackers.
In one particularly notable instance, a single phishing email managed to reach an astounding 900 recipients in just one send, showcasing the efficiency and potentially broad scope of the attackers’ operations.
Defensive Strategies Against Phishing
To mitigate the risk posed by this kind of phishing campaign, the KnowBe4 researchers have outlined several recommendations for organizations. First and foremost, security teams are advised to monitor for the Exchange header “X-MS-Exchange-Organization-AuthAs: Anonymous.” This header serves as a red flag, indicating that the email may have arrived via an unauthenticated delivery path.
Moreover, implementing a rigorous DMARC policy is crucial. Organizations should consider altering their DMARC policy from "p = none" to "p = reject," effectively blocking spoofed messages that falsely claim to originate from their domains. Additionally, limiting legitimate senders through Exchange Online connectors can help further secure the communication pathway, restricting permissions only to approved IP addresses.
If the Direct Send feature is not essential for operational processes, it is advisable for organizations to close this pathway altogether. Another layer of security can be added by enabling DomainKeys Identified Mail (DKIM) signing, which not only authenticates outbound emails but also equips DMARC with the necessary information to detect and reject unauthorized messages.
Conclusion
As the cyber threat landscape continues to evolve, the findings from the KnowBe4 Threat Lab serve as a stark reminder of how legitimate features can be weaponized against organizations. Implementing multi-layered defense strategies will be key to safeguarding sensitive information and maintaining trust within internal communications. Now more than ever, vigilance and proactive measures are essential in combating the growing threat of phishing attacks.
