Updated 4 days ago
Posted on
February 26, 2019

Director added you to a Project Team! – A new phishing attempt targeted on Office 365 users.

Summary
A phishing campaign targeting Office 365 users sends emails disguised as project team invitations from a company director. The spoofed message redirects to a fake Microsoft 365 login page with SSL certificates and Microsoft branding. Entering credentials gives attackers full account access. Users should always verify sender addresses and inspect URLs carefully.

Hi folks! It’s good to see you again.

Today, I got this email from our company Director that they have added me to the Project team! Ah, I’m on heavens 🙂 🙂

Wait!

This is not from our Director; I don’t have a director with this email address: ms-oxprotp.mycompanydomain.apcprd421.prdexchangpeenz.net@sv120.wadax.ne.jp

It’s neither from Microsoft’s Office 365 team.

Now, I recognize it is a fishy phishing trick by some prick. What does the link in the email do then? Let’s see.

It’s like this: https://happy-care.net/?d=dG9ueUBvdXJjb21wYW55ZG9tYWluLmNvbQ==

(I played a little and modified the URL to hide my email from future phishing attacks)

The base64 value directly converts to my email address and when I open, I see this.

dG9ueUBvdXJjb21wYW55ZG9tYWluLmNvbQ== is tony@ourcompanydomain.com in plain text.

Did you notice?

It has the Microsoft favicon, https, and also a very good looking Microsoft Office 365 login page. But…

The URL is not from Microsoft. The moment you enter your password, you are sharing your account with some anonymous user who can be you from now.

Conclusion:

Be careful folks, you may see a different email like this as well. Check the URLs twice after checking twice.

See you with a different security risk soon. I hope there are plenty nowadays.

Safety and Peace!

About the author

O365Reports Content Team is a specialized group of domain experts across Microsoft Entra, Exchange, SharePoint, Teams, Intune, Active Directory and security. Their work focuses on administration, governance, and configuration guidance that reflects real environment conditions. This helps IT teams apply settings correctly and maintain consistent operational control.

Previous Article

Office 365 TLS Deprecation Report - Preparing for TLS 1.2 Migration

Next Article

Export Office 365 Users’ Last Logon Time to CSV