Skip to main content

Email security features are being hijacked to steal Microsoft 365 logins — what you need to know

An email inbox displayed on the screen of a laptop, next to a cup of coffee.
(Image credit: Shutterstock)

Hackers are now leveraging this popular email security service in their attacks to send out malicious links with the aim of taking over user accounts.

As reported by Bleeping Computer, a threat actor has been abusing the link-wrapping feature included in email security services like Proofpoint and Intermedia in order to redirect users to phishing pages designed to steal user credentials, specifically Microsoft 365 logins.

However, Cloudflare’s Email Security team found that this hacker managed to compromise Proofpoint and Intermedia-protected email accounts. From there they then legitimized their malicious URLs which allowed them to use their unauthorized access to distribute ‘laundered’ links. Researchers have further stated that attackers have also abused the system by “including multi-tiered redirect abuse with URL shorteners via compromised accounts.”

In one of the Intermedia campaigns that used link-wrapping services to trick victims, a hacker delivered emails that claimed to be a “Zix” secure message notification. Some of these emails claimed they would allow users to view a secure document while others impersonated a Microsoft Teams communication alerting the user to a newly received message.

Instead of doing either of these things though, these fake emails contained a URL wrapped by Intermedia’s service which redirected users to a fake page that was actually a phishing site. Meanwhile, users who clicked on the reply button were led to a page that stole their login credentials.


Follow Tom's Guide on Google News to get our up-to-date news, how-tos, and reviews in your feeds. Make sure to click the Follow button.

More from Tom's Guide

Amber Bouman
Senior Editor Security

Amber Bouman is the senior security editor at Tom's Guide where she writes about antivirus software, home security, identity theft and more. She has long had an interest in personal security, both online and off, and also has an appreciation for martial arts and edged weapons. With over two decades of experience working in tech journalism, Amber has written for a number of publications including PC World, Maximum PC, Tech Hive, and Engadget covering everything from smartphones to smart breast pumps. 

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.