Microsoft SharePoint exploited to hack several energy companies



  • Hackers exploit SharePoint emails to steal credentials from big energy companies
  • Attackers establish persistence with inbox rules and MFA manipulation to maintain access
  • Microsoft recommends phishing-resistant MFA and conditional access policies for defense

Hackers are once again using SharePoint to attack large energy companies, stealing employee email credentials and further spreading the attack.

This is according to a new report from Microsoft, which claims that “multiple” large organizations in the energy sector have already been attacked.



Leave a Comment

Your email address will not be published. Required fields are marked *