Blog & News

SharePoint Phishing: When Trust Becomes the Biggest Vulnerability.

Written by Roman Padrun | 04.02.2026

Recent warnings from BACS and the National Cyber Security Center clearly show that the threat landscape surrounding SharePoint-based phishing in Switzerland continues to escalate. What used to be recognizable as a classic email phishing campaign has evolved into highly professional attacks that specifically exploit trust, routine, and Microsoft ecosystems.

These attacks are technically well-executed, virtually indistinguishable from legitimate Microsoft notifications, and affect organizations of all sizes.

What is monitored.

Most currently reported campaigns follow a similar pattern:

  • Users receive seemingly legitimate SharePoint document sharing notifications or invitations.

  • Senders appear to be internal colleagues or trusted business contacts.

  • Linked pages lead to convincing fake Microsoft sign-in pages.

  • Credentials and, in some cases, MFA information are captured using AiTM (Adversary-in-the-Middle) attacks.

  • This often results in:

    • Identity compromise

    • Deployment of malicious OAuth applications

    • Mailbox compromise

    • Lateral movement within the organization

    • Data exfiltration

The key point: These attacks often do not rely on malware. Instead, they exploit compromised identities, making them difficult for traditional security controls to detect in time.

Why SharePoint is an attractive target.

SharePoint is a core part of the modern workplace. Document sharing, external collaboration, and ad hoc invitations are standard practice and rarely questioned. Attackers exploit this inherent trust:

  • SharePoint links are perceived as legitimate

  • Microsoft branding lowers users' guard

  • Technically sophisticated implementations bypass basic security filters

As a result, the attack vector shifts from the endpoint to the identity.

Practical perspective.

Many Microsoft tenants face recurring security challenges:

  • Endpoint protection detects attacks too late or not at all
  • Conditional Access policies are bypassed using valid tokens
  • Audit logs are available but not actively monitored
  • External sharing has evolved over time and is rarely governed
  • Non-phishing-resistant authentication methods are still in use

This combination makes SharePoint phishing particularly effective and dangerous.

Recommended measures.

From awareness to action.

At Epic Fusion, we do not see SharePoint phishing as an isolated email problem, but as a symptom of insufficient governance and security awareness across the Microsoft 365 environment. These attacks do not succeed because of a single vulnerability. Instead, they exploit accumulated configurations, overly permissive sharing settings, limited visibility into identities and access, and a lack of security awareness.

Recommendation.

SharePoint phishing is here to stay. The question is not whether your organization could be targeted, but how well prepared it is. If you want to understand your tenant’s current security posture and identify concrete risks, it is worth taking a structured look behind the scenes.

A targeted Security Assessment is often the first step from reactive protection to sustainable governance.