The most common phishing attack of 2025

Sep 3, 2025

Documentation
Phishing attack

Weโ€™re seeing this attack everywhere in the wild right now.

A real contact of yours emails you a file to review. You click. A Microsoft sign in appears. You log in. The file never opens.

๐–๐ก๐š๐ญ ๐ข๐ฌ ๐š๐œ๐ญ๐ฎ๐š๐ฅ๐ฅ๐ฒ ๐ก๐š๐ฉ๐ฉ๐ž๐ง๐ข๐ง๐ :

Attackers hijack a mailbox, then send an email to everyone in the address book. The link leads to a lookalike Microsoft page that collects your password and often your MFA token, then uses your account to spread the same trick.

๐‡๐จ๐ฐ ๐ญ๐จ ๐ฌ๐ฉ๐จ๐ญ ๐ข๐ญ:

โ€ข A sign in page before you can view the file

โ€ข The address bar is not microsoft.com or office.com

โ€ข Tone or urgency that feels off for that sender

โ€ข Shortened links, odd redirects, or a page that reloads with no file

๐–๐ก๐š๐ญ ๐ญ๐จ ๐๐จ ๐ข๐ง ๐ฒ๐จ๐ฎ๐ซ ๐›๐ฎ๐ฌ๐ข๐ง๐ž๐ฌ๐ฌ:

โ€ข Do not sign in from email links. Open office.com from a bookmark

โ€ข Verify the email is legitimate with the sender via phone or other method

โ€ข Enforce MFA for everyone and disable legacy authentication

โ€ข Put protection inside Microsoft 365. We run Avanan for our clients to block compromised sender blasts, fake login pages, and token theft before staff ever see them

Trust the person, not the email. If youโ€™re asked to sign in before you can open a file, stop and check first.

Want Great IT Support?

Want to know how you can get efficient, reliable IT support that works with your business the way you want it?

You may also like…

Monitor Your Microsoft Sign-In Logs!

Monitor Your Microsoft Sign-In Logs!

Ever wondered how you'd know if someone has breached your Office365 account? Think about the implications: They could email your clients or staff, compromise sensitive information, or even hold your files for ransom. As a business owner, you're usually the juiciest...

Stefan’s thoughts on the power of responsiveness in business

Stefan’s thoughts on the power of responsiveness in business

Ever noticed how just a quick reply or an update can make a world of difference in how we feel about a service? That's the magic of being responsive in the business world. This is why I think this seemingly simple act is so impactful: It Builds Trust: When customers...