📰 Full Story
Microsoft’s Defender Research team disclosed a large-scale phishing campaign observed between April 14 and 16, 2026, that targeted more than 35,000 users at over 13,000 organisations across 26 countries.
Around 92% of recipients were in the United States, with healthcare and life sciences (19%), financial services (18%), professional services (11%) and technology (11%) most affected.
Attackers used polished, code-of-conduct themed emails that included personalized PDF attachments.
Recipients who opened the PDFs were routed through multi-stage flows — including Cloudflare CAPTCHA pages and intermediate staging pages — before reaching fake Microsoft sign-in pages.
The campaign employed adversary-in-the-middle (AiTM) techniques to intercept authentication tokens in real time, enabling account access despite some forms of multi-factor authentication.
Microsoft said messages were sent via legitimate delivery services and used authenticity cues (including a false Paubox banner) to increase credibility.
Recommended mitigations include enabling Safe Links/Safe Attachments, Zero-hour Auto Purge, phishing-resistant authentication (FIDO/passwordless), conditional access, Defender XDR attack disruption, and user awareness training.
🔗 Based On
Infosecurity MagazineMicrosoft Flags Mass Phishing Campaign Using Fake Compliance Emails







💬 Commentary