Office 365 phishing kit counts on high-level execs not being security savvy

Office 365 phishing kit counts on high-level execs not being security savvy

While no specific names were included, a new report pointed to CEOs of U.S. companies as a primary target of a new phishing scheme. Here, Amazon founder Jeff Bezos speaks about a recent development by Blue Origin, the space company he founded. (Mark Wilson/Getty Images)

Cybercriminals have been using a phishing kit featuring fake Office 365 password alerts as a lure to target the credentials of chief executives, business owners and other high-level corporate leaders – highlighting the importance of ensuring that upper management is not excluded from security awareness training.


In a blog post on Monday, researchers from Trend Micro reported that they uncovered 70 email addresses that have been targeted with the so-called “Office 365 V4 phishing kit” since May 2020, 40 of which belong to “CEOs, directors, owners and founders, among other enterprise employee[s].”


Ryan Flores, senior manager of forward-looking threat research in APAC region at Trend Micro, told SC Media that the finding was “pretty striking because typically you would see a spam campaign or a phishing campaign sent to a wide range of email addresses.” ..

Support the originator by clicking the read the rest link below.