A Microsoft 365 phishing attack does not lock anything up or announce itself. One employee types a password into the wrong page, and a stranger quietly reads your company’s mail for as long as nobody notices. Your business has the same mailbox.
See Where Your Business Stands →
Fifteen minutes with Craig on what is actually running in your business, and what it would take to keep it running. You won’t pay a dime for the conversation.
The problem: Owners picture a break-in as something loud. Locked screens, a ransom note, the phone ringing. So they judge their security by whether anything has blown up lately. A Microsoft 365 phishing attack never blows up. It just sits there and reads.
What it actually feels like: Not fear. Most owners I talk to are not frightened, they are irritated. They know there are four or five mailboxes in the building that hold everything worth knowing about the company, and they could not tell you who watches them. Some quiet part of them has known that for a while.
The straight answer: You should not have to become a security expert to know whether somebody is reading your mail. You need to know which mailboxes matter, whether anything is quietly forwarding out of them, and who would notice if it were. Short list, short conversation.
In this article
Hey folks! I want to walk you through something that happened this month, because the shape of it is going to be familiar and the ending is not the one you expect.
IEH Corporation is in Brooklyn, New York. They make hyperboloid connectors, which is a fancy way of saying the electrical plugs that have to work the first time and every time. Their parts go into Patriot air-defense batteries, THAAD, fighter aircraft, radar, satellites, military radios and torpedoes. Serious work. And the company does about thirty million dollars a year, which puts it squarely in the same size bracket as a lot of the businesses reading this.
On August 4 they discovered somebody had been inside an employee’s email account. They told the Securities and Exchange Commission about it, which is how the rest of us know.
Here is how it went, in the company’s own words. A malicious actor “impersonated a prospective business contact and delivered a hyperlink disguised as a Microsoft document-sharing link.” The employee clicked it. It brought up something that looked like a Microsoft sign-in page. He typed his email address and password into it. He went back to work.
That is the entire break-in. No malware. No exploit. Nobody picked a lock. A Microsoft 365 phishing page and a person having a normal Tuesday.
Sources: IEH Corporation disclosure to the SEC, August 2026, reported by Security Affairs and SC Media.
Nothing happened. Nothing was encrypted, no screens locked up, nobody demanded a dime. If ransomware had hit that company on August 4, everybody would have known by lunchtime and the recovery would have started that afternoon. Awful, expensive, but it announces itself.
This did not announce itself. Somebody with an ordinary employee’s password simply had a seat inside the company’s correspondence.
Think about what is reachable from one working mailbox at a manufacturer. Purchase orders. Back and forth with customers. Engineering documents. In IEH’s case, technical material that falls under ITAR and EAR, which are the rules governing what defense-related information may leave the country and who may see it. The company said that material was potentially exposed.
Ransomware takes your business away from you for a week. A read mailbox hands somebody your pricing, your customer list, your delivery schedule, your engineering, and the exact phrasing your people use with each other. One of those you recover from. The other one you never even find out the full size of.
And this is not some exotic technique reserved for defense contractors. When the Justice Department unsealed an indictment on August 18 naming seventeen Iranians who had been at this since 2013, the method was the same fake sign-in page. They aimed it at more than a hundred thousand professors’ email accounts and got into roughly eight thousand of them, walking off with thirty-one terabytes of American research. Same trick as the Brooklyn connector company, just run at the scale of a government.
The hosers use this because it works on everybody.
Sources: U.S. Department of Justice superseding indictment unsealed in the Southern District of New York, August 18, 2026, reported by Cybersecurity Dive and Help Net Security.
The intruder created rules inside the mailbox.
That one step is the difference between a Microsoft 365 phishing attack you recover from in an hour and one that runs for months, and it is what I would go look at in your business this afternoon.
A mailbox rule is that ordinary feature where incoming mail gets automatically filed, forwarded, or marked read. Everybody has a few. Yours probably shuffles newsletters into a folder. They are boring, they are invisible, and nobody ever audits them.
That is exactly why the hosers love them. Set a rule that quietly moves anything mentioning “invoice” or “wire” or “bank” into an obscure folder and marks it read, and the real owner of that mailbox never sees those messages. Meanwhile the intruder does. Now they can watch a payment conversation happen, step in at the right moment with new bank details, and the person whose account it is never sees the thread that would have tipped them off.
IEH found the rules and shut them off. Good for them. But the rules were the reason this could have run quietly for a long time, and rules are the single most overlooked thing in a business email system. I have been doing this for more than thirty-five years, and I still find businesses where nobody has ever once looked at what rules exist across their mailboxes.
Where they live, if you want to look yourself. In Outlook on the web or Microsoft 365 it is Settings, then Mail, then Rules, and there is a separate Forwarding page underneath that worth checking too. In Gmail it is Settings, then Filters and Blocked Addresses, and again a separate Forwarding and POP/IMAP tab. A minute per mailbox. You are looking for anything you did not set on purpose, and particularly for anything that files or forwards mail mentioning invoices, payments or bank details, or that marks messages as read.
The catch is that you have to do it for every mailbox in the building and not just your own, and you need the access to see them. That is usually the moment an owner finds out whether whoever handles the computers can actually do it, and how long it takes them to answer.
To be fair to IEH, and I want to be fair here: the company says there is no evidence anything was actually copied out, and that it does not expect a material effect on its operations. I will take them at their word on both counts. They caught it, they disclosed it, they cleaned it up. That is more than a lot of companies manage.
But “no evidence it was copied” is not the same sentence as “nothing happened.” It was readable. Somebody was in there. For most businesses, the way you eventually find out is a customer calling to ask about an invoice you never sent.
My father fell for a phishing email.
Mine. The guy who has spent more than thirty-five years in cybersecurity and trains FBI InfraGard members. My own dad clicked the thing and gave scammers remote access to his computer, and they went straight to work hunting for his financial documents.
My step-mother noticed something was off and called. I got in remotely and stopped them before they found the spreadsheet with all the bank credentials on it. We were lucky. We caught it in time.
I tell you that because I need you to hear this from somebody who cannot possibly be looking down on you. This is not a story about careless people. My father is not careless. The employee at IEH is not careless. Clicking a link from what appears to be a prospective customer is the most ordinary act in a working day, which is precisely why criminals built their whole business on it.
I hear this one constantly, and I understand why. Somebody set up two-factor authentication, that six-digit code on your phone, and it felt like the door got locked. It is genuinely worth having. Turn it on if you have not.
But against a modern Microsoft 365 phishing page it is a speed bump, not a wall, and you should know why.
The fake sign-in pages the hosers run now sit in the middle. You type your password, the page passes it straight through to the real Microsoft. Microsoft sends you the code. You type the code into the fake page. It passes that through too. Microsoft sees a perfectly valid login and hands over a session, and the criminal takes it. Everything worked exactly as designed, and they are still inside.
That is what trips up good, conscientious owners. You did the responsible thing. You turned on the protection everybody told you to turn on. And then you reasonably assumed the question was settled and stopped looking. The gap is not that you were lazy. The gap is that nobody told you the answer had a shelf life.
RingCentral, which runs phone service for a lot of American businesses, learned a version of this in July. A social engineering campaign got somebody inside. When the company refused to pay, the data went public, and Have I Been Pwned counted about 1.6 million email addresses in it along with names, phone numbers and street addresses. No firewall failed. A person did.
I am not going to hand you a project plan. You have a business to run. But there are three questions that cost you nothing and will tell you almost everything about where you stand.
1. Name the mailbox. Which single account in your company would hurt the most if a stranger read it for a week? Not the CEO’s, necessarily. Usually it is whoever handles purchase orders, or whoever your biggest customer talks to, or whoever the bank sends confirmations to. If you cannot name it in ten seconds, that is the finding.
2. Ask what rules are running. Call whoever handles your computers and ask them to show you every forwarding and filing rule across your mailboxes, and who created each one. This is a five-minute job for anybody with the right access. If the answer is vague, or if nobody has ever looked, you have learned something important about who is watching.
3. Ask who would notice. If somebody signed into one of your accounts tonight from an unfamiliar place, who finds out, and how long does it take? “Nobody” and “eventually” are real answers, and they are the ones I hear most. Every successful Microsoft 365 phishing attack I have looked at survived on that gap, not on anything clever.
Notice that all three are questions for a person, not tasks for you. That is deliberate. Your job here is to ask; it is somebody else’s job to have a good answer.
Let me say back to you what I think you already believe. That one or two mailboxes in your building hold nearly everything worth knowing about your company. That you are not certain anybody has ever looked at what is quietly forwarding out of them. And that this has been sitting in the back of your mind for a while, filed under things to get to.
If that is roughly right, you are not behind. You are exactly like nearly every owner I talk to. The uncomfortable part is not that something is wrong. It is the gap between paying somebody to handle this and not being able to say what they actually check. Both of those things can be true at once, and neither one makes you a bad operator.
So close the gap and stop carrying the question around. Book fifteen minutes with me. It is my company, so you are talking to the owner and not a salesperson, and you will not pay a dime for the conversation.
I am not going to tell you it makes you money. It does not sell anything for you. What it protects is the two things you actually run out of: the hours your people spend on computer trouble instead of billing or selling, and your own evenings, because you are the one who ends up chasing this and it is never at a convenient hour.
If you want somebody watching it from there, that is what Support & Defend does.
You run your business. We patch what Windows Update never touches, watch your systems around the clock, and act when something trips.
A few minutes with a real person, straight talk on where your business stands. No pressure.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
Join thousands of security professionals who receive Craig Peterson's Insider Show Notes and cybersecurity updates.
Join 10,000+ cybersecurity professionals