ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault1
Part of a story covered by 9 sources: “Passkey-themed IT helpdesk vishing hijacks Microsoft 365 accounts; device-code phishing kits and Direct Send abuse widen the campaign” — merged summary and timeline →

Hackers Favor US Eastern Business Hours in M365 Phishing Campaign

mediumPhishing & fraud exploited in the wildimportance 58
AI summary · glm-5.3-flash

KnowBe4 tracked 29,785 phishing emails abusing Microsoft 365 Direct Send to spoof internal senders while timing sends to US Eastern business hours.

KnowBe4 Threat Lab observed 29,785 confirmed phishing emails between July and August 2026 abusing Microsoft 365's Direct Send feature, which lets devices and legacy apps send mail without a dedicated account. The emails appeared to come from trusted internal addresses such as HR or accounting, bypassing email gateways by connecting directly to Exchange Online MX endpoints, with activity peaking on Monday-Tuesday during US Eastern business hours and near-zero weekend volume. About 35% of the messages carried malicious attachments like fake invoices, voicemail alerts, and OneDrive shares, and 4,023 used reply-to addresses on different domains to capture employee responses. Researchers recommended strict DMARC enforcement, connector restrictions, DKIM signing, and checking for the 'X-MS-Exchange-Organization-AuthAs: Anonymous' Exchange header.

  • 29,785 phishing emails abused M365 Direct Send over July-August 2026
  • Campaign timed to US Eastern business hours with near-zero weekend volume
  • ~35% of messages carried malicious attachments; 4,023 used cross-domain reply-to addresses
  • DMARC p=none policies may still allow spoofed internal-appearing messages to deliver
  • Mitigations: DMARC p=reject, connector allowlists, DKIM signing, Anonymous header checks
Full article447 words · extracted from infosecurity-magazine.com · click to collapse

A phishing campaign abusing Microsoft 365’s Direct Send feature was observed to follow US Eastern business hours.

The campaign was uncovered by the KnowBe4 Threat Lab team, who observed 29,785 confirmed phishing emails abusing the Direct Send functionality across July and August 2026.

The researchers highlighted the “distinctly human pattern” of its delivery: attackers were observed to be particularly active from Monday to Tuesday during US Eastern business hours, with volumes peaking just before noon, dipping and then reaching their highest point at around 2pm EST.

Daily Direct Send volume, July 1 – August 12, 2026. Sharp weekday peaks and near-zero weekends confirm campaigns are timed around business hours. Source: KnowBe4
Daily Direct Send volume, July 1 – August 12, 2026. Sharp weekday peaks and near-zero weekends confirm campaigns are timed around business hours. Source: KnowBe4

Attackers Abuse Microsoft Direct Send Function

Direct Send is a legitimate Microsoft 365 feature designed to allow devices such as printers and scanners, as well as legacy applications, to send emails without a dedicated account.

Attackers exploited this feature to send emails that appear to originate from trusted internal addresses, such as HR, accounting or admin.

Such Direct Send attacks allow the perpetrator to spread malicious payloads without the need to compromise an employee account or obtain their credentials. It also enables them to bypass the targeted organization's normal email security gateway by connecting directly to its Exchange Online MX endpoint.

“While authentication checks may detect that something is wrong, organizations using a domain-based message authentication, reporting and conformance (DMARC) monitoring policy can still allow the message to be delivered,” said the KnowBe4 report, published on September 10.

The KnowBe4 researchers found that approximately 35% of emails it classified as phishing emails carried attachments, “virtually all of which” classified as threats.

These included fake document requests, internal voicemail alerts, invoices and payment approvals and fake OneDrive file shares.

Additionally, 4023 of malicious emails used a reply-to address pointing to a different domain, routing employee responses directly to the attacker.

In one instance, a phishing email reached 900 recipients in a single send.

To avoid being targeted by this kind of phishing campaigns, the KnowBe4 researchers recommended that organizations look for the Exchange header “X-MS-Exchange-Organization-AuthAs: Anonymous,” a sign suggesting the email arrived through an unauthenticated delivery path.

Other measures security teams can take include enforcing a strict DMARC policy by changing it from p = none to p = reject, which blocks spoofed messages claiming to come from your domain.

Organizations should also restrict legitimate senders through Exchange Online connectors, allowing only approved IP addresses, and close the Direct Send pathway if it is not required. Enabling DomainKeys identified mail (DKIM) signing further verifies outbound emails and gives DMARC the information needed to detect and reject unauthorized messages.

Image credits: gguy / Vladimka production / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/hackers-us-business-hours-m365/