Hackers target Office 365 business accounts

Image Credit: Pixabay (Image credit: Image Credit: Startup Stock Photos / Pixabay)

New research from Barracuda has revealed that account takeover attacks are one of the fastest growing email security threats as hackers set their sights on Microsoft Office 365 accounts.

The IT security company recently analyzed account takeover attacks targeted at its customers to discover that 29 percent of organizations had their Office 365 accounts compromised by hackers in March of this year.

In March alone, over 1.5m malicious and spam emails were sent from hacked Office 365 accounts highlighting the potential impact this security threat poses.

Hackers executed the account takeover attacks using a variety of methods including reusing stolen credentials, brute-force attacks, social engineering, phishing and even SMS to trick their victims into providing their account details.

Account takeover attacks

Office 365 account takeover attacks begin with infiltration and many hackers impersonate Microsoft and other large firms as a means of tricking users into disclosing their login credentials. In fact, Microsoft is the most impersonated brand in the world with 1 in 3 attacks impersonating the company.

Once an account has been compromised, hackers rarely launch an attack straightaway. Instead, they monitor email and track activity in the company to help maximize their chances of executing a successful attack.

One trick that scammers use to avoid detection is setting up mailbox rules to hide or delete any emails they send from the compromised account. According to Barracuda's March 2019 analysis, hackers set up malicious rules to hider their activity in 34 percent of the nearly 4,000 compromised accounts.

After the reconnaissance has been completed, cybercriminals use the harvested credentials to target other high-value accounts in an organization with executives and finance department employees being prime targets. They also use compromised accounts to monetize attacks by stealing personal, financial and confidential data to use it to commit identity theft, fraud and other crimes.

To protect your business from account takeover attacks, Barracuda recommends using AI to scan your emails, deploying account takeover protection, using multi-factor authentication, monitoring inbox rules and suspicious logins and training employees to recognize and report attacks.

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
China
Chinese hackers targeting Juniper Networks routers, so patch now
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Trump
Hackers are abusing $TRUMP tokens to lure victims in to new phishing scam
Latest in News
A collage of Tom Holland's unmasked Spider-Man and Sadie Sink's Max in Stranger Things season 4
Marvel reportedly casts Stranger Things star Sadie Sink in Spider-Man 4, but I don't want her to tackle the roles she's rumored to play
Google Gemini Robotics
Gemini just got physical and you should prepare for a robot revolution
Lilo & Stitch Official Trailer
Stitch crashes into earth and steals our hearts with the first trailer for the live-action Lilo & Stitch
GTA 5
GTA Online publisher Take-Two is gunning for a black market that’s basically heaven for cheaters
Y2K cast looking shocked
Y2K has a streaming release date on Max, so you can witness the technology uprising at home
The Discovery+ homepage
Discovery+ just got a big update to its streaming app that makes it more like Max – here are 5 great new features to try