Skip to content
Roman and Flo discuss how to recognize and stop SharePoint phishing. What used to be recognizable as a classic email phishing campaign has evolved into highly professional attacks that specifically exploit trust, routine, and Microsoft ecosystems.

SharePoint Phishing: When Trust Becomes the Biggest Vulnerability.

Roman Padrun Knowledge

A SharePoint release from Microsoft or an attack? Phishing campaigns rely on identity theft rather than malware and are affecting many organizations.

Recent warnings from BACS and the National Cyber Security Center clearly show that the threat landscape surrounding SharePoint-based phishing in Switzerland continues to escalate. What used to be recognizable as a classic email phishing campaign has evolved into highly professional attacks that specifically exploit trust, routine, and Microsoft ecosystems.

These attacks are technically well-executed, virtually indistinguishable from legitimate Microsoft notifications, and affect organizations of all sizes.

What is monitored.

Most currently reported campaigns follow a similar pattern:

  • Users receive seemingly legitimate SharePoint document sharing notifications or invitations.

  • Senders appear to be internal colleagues or trusted business contacts.

  • Linked pages lead to convincing fake Microsoft sign-in pages.

  • Credentials and, in some cases, MFA information are captured using AiTM (Adversary-in-the-Middle) attacks.

  • This often results in:

    • Identity compromise

    • Deployment of malicious OAuth applications

    • Mailbox compromise

    • Lateral movement within the organization

    • Data exfiltration

The key point: These attacks often do not rely on malware. Instead, they exploit compromised identities, making them difficult for traditional security controls to detect in time.

Why SharePoint is an attractive target.

SharePoint is a core part of the modern workplace. Document sharing, external collaboration, and ad hoc invitations are standard practice and rarely questioned. Attackers exploit this inherent trust:

  • SharePoint links are perceived as legitimate

  • Microsoft branding lowers users' guard

  • Technically sophisticated implementations bypass basic security filters

As a result, the attack vector shifts from the endpoint to the identity.

Practical perspective.

Many Microsoft tenants face recurring security challenges:

  • Endpoint protection detects attacks too late or not at all
  • Conditional Access policies are bypassed using valid tokens
  • Audit logs are available but not actively monitored
  • External sharing has evolved over time and is rarely governed
  • Non-phishing-resistant authentication methods are still in use

This combination makes SharePoint phishing particularly effective and dangerous.

Recommended measures.

Identity-first security strategy

  • Risk-based Conditional Access policies
  • Restricting and monitoring Auth consent
  • Using modern token and session protection mechanisms

Control of external collaboration

  • Regularly reviewing external SharePoint access

  • Clear policies for external sharing

  • Visibility into who shares content and with whom

Targeted security awareness

  • Real-world attack examples
  • Clear guidance for handling unexpected sharing
  • Focus on login pages and contextual verification

Active detection and monitoring

  • Monitoring suspicious SharePoint activity

  • Correlation of click, sign-in, and consent events

  • Early detection of identity anomalies

From awareness to action.

At Epic Fusion, we do not see SharePoint phishing as an isolated email problem, but as a symptom of insufficient governance and security awareness across the Microsoft 365 environment. These attacks do not succeed because of a single vulnerability. Instead, they exploit accumulated configurations, overly permissive sharing settings, limited visibility into identities and access, and a lack of security awareness.

Recommendation.

SharePoint phishing is here to stay. The question is not whether your organization could be targeted, but how well prepared it is. If you want to understand your tenant’s current security posture and identify concrete risks, it is worth taking a structured look behind the scenes.

A targeted Security Assessment is often the first step from reactive protection to sustainable governance.

Sanche Baskaran, CEO - Partner

Questions? I am happy to help.

Would you like to learn more? Find out where your organization stands? Discuss your Microsoft 365 security strategy?

No problem. Get in touch today.