Quick Summary
The Securityish Brief
Microsoft has identified a growing trend where threat actors exploit misconfigured email routing and spoof protections to conduct phishing attacks. This issue has been particularly noted since May 2025, with a significant increase in attempts to impersonate organizations’ domains. The Microsoft Threat Intelligence team reported that over 13 million malicious emails linked to the Tycoon 2FA phishing-as-a-service kit were blocked in October 2025.
These phishing emails often mimic internal communications, including voicemails, shared documents, and HR-related messages, making them particularly deceptive. The attacks can lead to credential theft, business email compromise, and financial scams, with some emails designed to trick organizations into paying fake invoices.
One example involves emails that appear to be from a CEO or accounting department, containing fake invoices and other documents to lend credibility to the scam. The emails may also include clickable links or QR codes directing recipients to phishing sites.
Understanding the Risks
Organizations with complex email routing configurations and lax spoof protection are especially vulnerable. A common scenario involves pointing mail exchanger records (MX records) to third-party services or on-premises Exchange environments, creating security gaps that attackers exploit.
Microsoft emphasizes that organizations with MX records directly pointed to Office 365 are not at risk from this attack vector. To mitigate these threats, it is crucial for organizations to implement strict Domain-based Message Authentication, Reporting, and Conformance (DMARC) reject policies and Sender Policy Framework (SPF) hard fail policies.
Additionally, organizations should ensure that third-party connectors, such as spam filtering services, are properly configured to enhance email security. Turning off Direct Send when unnecessary can also help prevent domain spoofing.
- Tycoon 2FA: A phishing-as-a-service kit used by attackers to facilitate credential theft.
- DMARC: A policy framework that helps prevent email spoofing and phishing.
- SPF: A protocol that verifies the sender’s identity to prevent unauthorized email sending.
- Direct Send: A feature that allows emails to be sent directly to recipients without going through a mail server.
Key Takeaways
- Implement strict DMARC reject policies to prevent email spoofing.
- Configure SPF hard fail policies to enhance email authentication.
- Review and secure third-party email connectors to prevent misconfigurations.
- Disable Direct Send if it is not necessary for your organization.
- Regularly monitor email logs for suspicious activity and phishing attempts.
Key Terms & Concepts
- Tycoon 2FA: In this article, Tycoon 2FA refers to a phishing-as-a-service kit used by attackers to create and manage phishing campaigns.
- DMARC: In this article, DMARC stands for Domain-based Message Authentication, Reporting, and Conformance, a protocol to prevent email spoofing.
- SPF: In this article, SPF refers to Sender Policy Framework, a protocol that helps verify the sender’s identity in email communications.
- Direct Send: In this article, Direct Send is a feature that allows emails to be sent directly to recipients without passing through a mail server.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.