Recent warnings from BACS and the National Cyber Security Center clearly show that the threat landscape surrounding SharePoint-based phishing in Switzerland continues to escalate. What used to be recognizable as a classic email phishing campaign has evolved into highly professional attacks that specifically exploit trust, routine, and Microsoft ecosystems.
These attacks are technically well-executed, virtually indistinguishable from legitimate Microsoft notifications, and affect organizations of all sizes.
What is monitored.
Most currently reported campaigns follow a similar pattern:
-
Users receive seemingly legitimate SharePoint document sharing notifications or invitations.
-
Senders appear to be internal colleagues or trusted business contacts.
-
Linked pages lead to convincing fake Microsoft sign-in pages.
-
Credentials and, in some cases, MFA information are captured using AiTM (Adversary-in-the-Middle) attacks.
-
This often results in:
-
Identity compromise
-
Deployment of malicious OAuth applications
-
Mailbox compromise
-
Lateral movement within the organization
-
Data exfiltration
-
The key point: These attacks often do not rely on malware. Instead, they exploit compromised identities, making them difficult for traditional security controls to detect in time.
Why SharePoint is an attractive target.
SharePoint is a core part of the modern workplace. Document sharing, external collaboration, and ad hoc invitations are standard practice and rarely questioned. Attackers exploit this inherent trust:
-
SharePoint links are perceived as legitimate
-
Microsoft branding lowers users' guard
-
Technically sophisticated implementations bypass basic security filters
As a result, the attack vector shifts from the endpoint to the identity.
Practical perspective.
Many Microsoft tenants face recurring security challenges:
- Endpoint protection detects attacks too late or not at all
- Conditional Access policies are bypassed using valid tokens
- Audit logs are available but not actively monitored
- External sharing has evolved over time and is rarely governed
- Non-phishing-resistant authentication methods are still in use
This combination makes SharePoint phishing particularly effective and dangerous.
Recommended measures.
Identity-first security strategy
- Risk-based Conditional Access policies
- Restricting and monitoring Auth consent
- Using modern token and session protection mechanisms
Control of external collaboration
Regularly reviewing external SharePoint access
Clear policies for external sharing
Visibility into who shares content and with whom
Targeted security awareness
- Real-world attack examples
- Clear guidance for handling unexpected sharing
- Focus on login pages and contextual verification
Active detection and monitoring
Monitoring suspicious SharePoint activity
Correlation of click, sign-in, and consent events
Early detection of identity anomalies
From awareness to action.
At Epic Fusion, we do not see SharePoint phishing as an isolated email problem, but as a symptom of insufficient governance and security awareness across the Microsoft 365 environment. These attacks do not succeed because of a single vulnerability. Instead, they exploit accumulated configurations, overly permissive sharing settings, limited visibility into identities and access, and a lack of security awareness.
Recommendation.
SharePoint phishing is here to stay. The question is not whether your organization could be targeted, but how well prepared it is. If you want to understand your tenant’s current security posture and identify concrete risks, it is worth taking a structured look behind the scenes.
A targeted Security Assessment is often the first step from reactive protection to sustainable governance.
Questions? I am happy to help.
Would you like to learn more? Find out where your organization stands? Discuss your Microsoft 365 security strategy?
No problem. Get in touch today.
%20-%20Teams%20Logo.png?width=576&height=182&name=Logo%20in%20standard%20arrangement%202%20(RGB)%20-%20Teams%20Logo.png)