Microsoft 365 Collaboration Becomes the New Phishing Path
Phishing is moving out of the inbox and into Microsoft 365 collaboration features that people trust as routine work. When a target is added to a malicious Group, the lure can arrive through group mail, shared files, or calendar items, so the suspicious part is no longer a single external email but ordinary-looking collaboration traffic.
Fortra says the campaign uses Outlook Groups and Microsoft 365 calendar features to deliver repeated prompts that can look like internal updates, shared resources, or meeting requests. Victims may be pushed toward credential theft, token theft, malware, or data exposure, and the evidence is spread across groups, mailboxes, files, and calendar events instead of one obvious message.
That scattering makes user suspicion lower and incident reconstruction harder. Treat unexpected groups, meetings, and shared files as phishing surfaces, not just inbox content.