Phishing Campaign Abuses Microsoft 365 Direct Send Feature
A phishing campaign exploiting Microsoft 365's Direct Send feature sent nearly 30,000 emails, primarily during US Eastern business hours, to bypass email

A phishing campaign abusing Microsoft 365's Direct Send feature sent 29,785 confirmed malicious emails in July and August 2026. The KnowBe4 Threat Lab team discovered the campaign, noting its activity peaked on Mondays and Tuesdays during US Eastern business hours.
Attackers used the legitimate Direct Send feature, designed for devices like printers, to send emails that appeared to come from trusted internal addresses such as HR or accounting. This method allows threat actors to spread malicious payloads without needing to compromise an employee's credentials. It also lets them bypass an organization's standard email security gateway by connecting directly to its Exchange Online MX endpoint.
Campaign Timing and Tactics
The researchers highlighted a "distinctly human pattern" in the attack schedule. Email volumes spiked just before noon EST, dipped, and then reached their highest point around 2pm. Approximately 35% of the phishing emails carried attachments, which the report classified as threats.
These attachments were used in fake document requests, internal voicemail alerts, invoices, payment approvals, and fake OneDrive file shares. In one instance, a single phishing email reached 900 recipients. Also, 4,023 malicious emails used a reply-to address pointing to a different domain, routing any employee responses directly to the attackers.
Bypassing Security Defenses
The KnowBe4 report explained how these attacks circumvent common defenses. "While authentication checks may detect that something is wrong, organizations using a domain-based message authentication, reporting and conformance (DMARC) monitoring policy can still allow the message to be delivered," the researchers stated. This shows the limitation of certain monitoring configurations against this attack vector.
Recommended Security Controls
To defend against such campaigns, KnowBe4 researchers provided several mitigation steps. Organizations should look for the Exchange header "X-MS-Exchange-Organization-AuthAs: Anonymous," which indicates an email arrived via an unauthenticated delivery path.
Security teams can also implement stricter policies. The primary recommendations include changing a DMARC policy from p = none to p = reject to block spoofed messages, restricting legitimate senders through Exchange Online connectors to approved IP addresses, and disabling the Direct Send pathway if it is not required. Enabling DomainKeys Identified Mail (DKIM) signing for outbound emails provides DMARC with the data needed to detect and reject unauthorized messages.
Organizations are advised to review their email security configurations to close this direct avenue for phishing attacks.





