Hackers are stealing Microsoft 365 accounts by abusing link-wrapping services
- Crooks are using link wrapping services to entice victims into clicking
- The links redirect the victims to a fake Microsoft 365 landing page
- The campaign has been going on for at least two months
Cybercriminals are abusing Proofpoint’s and Intermedia’s “link wrapping” service to bypass email protections, create convincing phishing emails, and ultimately – steal people’s Microsoft 365 credentials. This is according to cybersecurity researchers from Cloudflare, who have been observing such campaigns in the wild for at least two months.
Proofpoint’s link‑wrapping service, known as URL Defense, protects users by rewriting every inbound email link to route through Proofpoint’s inspection gateway before it reaches the actual recipient. When a person clicks a link in an email, it is evaluated in real-time (including sandbox detonation and reputation checks) and is only granted access if the link is deemed safe.
But here’s the catch: all original URLs are embedded within the encoded rewritten link (usually prefixed with “urldefense.proofpoint.com) which, as a side-effect, creates a sense of security with the recipients, making it more likely they will actually click it.
Active campaign
Cybercriminals were seen creating brand new landing pages that mimic the Microsoft 365 login screen, and as such, are not yet flagged by security products. They would then shorten the URLs to those pages using popular URL shorteners such as Bitly. The next step is to break into email accounts already protected by Proofpoint, and use them to wrap the shortened URL.
The final step is to distribute the shortened and wrapped URL, often through the very same email accounts that were compromised earlier.
Cloudflare says it’s seen multiple attacks already, with crooks sending fake voice mail notification emails, and fake shared Microsoft Teams documents. Victims who don’t spot the attack go through a chain of redirects, landing at a page where they’re asked for their Microsoft 365 login credentials.
As a rule of thumb, links in emails should be carefully reviewed before being clicked, especially if the emails carry any sense of urgency with them.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
You might also like
Crooks are using link wrapping services to entice victims into clicking The links redirect the victims to a fake Microsoft 365 landing page The campaign has been going on for at least two months Cybercriminals are abusing Proofpoint’s and Intermedia’s “link wrapping” service to bypass email protections, create convincing phishing…
Recent Posts
- AI leaders call for tougher protections against AI-aided bioweapons
- 5 Best Smart Speakers (2026): Alexa, Google Assistant, Siri
- I’m an outdoors expert — here are 9 easy-pitch tents I’d recommend for a fuss-free camping trip
- Samsung’s updated Health app unsurprisingly comes with new AI-powered features
- Amazon develops a warehouse robot workers can speak to
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023