Attackers are abusing Microsoft Exchange Online's Direct Send feature to deliver phishing emails that appear to come from trusted internal users, without needing authentication. The campaign has targeted more than 70 organizations, primarily in the United States, since May 2025. By using an organization's predictable smart host address and a recipient address, attackers can send messages through Microsoft's infrastructure with tools such as PowerShell, causing spoofed emails to look like legitimate internal mail and helping them evade many sender-authenticity checks, including SPF and DMARC.
The activity affects Microsoft 365 recipients and can also mislead third-party security products into treating forged messages as trusted internal traffic. Defenders are being urged to enable Reject Direct Send in Exchange Online, enforce stricter DMARC and SPF policies, deploy anti-spoofing rules, quarantine unauthenticated messages that appear internal, and monitor Direct Send traffic for suspicious headers, routing patterns, and behavioral anomalies. Organizations are also advised to enable MFA to reduce the impact of successful phishing attempts.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-11, Traficom reported the Direct Send phishing campaign was still ongoing and noted that the weakness could also cause third-party security tools to treat spoofed messages as trusted internal mail. The advisory reiterated mitigations such as enabling Reject Direct Send, stricter DMARC/SPF policies, quarantining unauthenticated internal-looking mail, and enabling MFA.
By July 2025, the campaign had targeted more than 70 organizations, primarily in the United States. Reports said attackers could use tools such as PowerShell to deliver the phishing emails and recommended mitigations including enabling Reject Direct Send and stricter anti-spoofing controls.
In May 2025, attackers began using Microsoft Exchange Online's Direct Send feature to send spoofed phishing emails that appeared to come from trusted internal users without authentication. The technique relied on predictable smart host addresses and allowed messages to traverse Microsoft's infrastructure, helping them evade checks such as SPF and DMARC.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.