www.infosecurity-magazine.com 11 Sept 2026, 13:30 UTC

Hackers Favor US Eastern Business Hours in M365 Phishing Campaign

Hackers Favor US Eastern Business Hours in M365 Phishing Campaign

A recent phishing campaign targeting Microsoft 365 utilized the Direct Send feature, sending 29,785 confirmed phishing emails during July and August 2026. The attackers demonstrated a preference for sending these emails during US Eastern business hours, particularly peaking on Mondays and Tuesdays around 2 PM EST. Exploiting Direct Send allowed attackers to send emails appearing from trusted internal sources without needing to compromise accounts.

Approximately 35% of these phishing emails contained attachments, which were mostly malicious, including fake document requests and spoofed invoices. Recommendations for organizations to mitigate such attacks include monitoring Exchange headers, enforcing strict DMARC policies, and limiting senders through Exchange Online connectors.

View full article

Article by CyberSIXT