How are you mitigating Eviltoken-style SharePoint and MFA phishing?

0
1
Asked By MellowCedar42 On

We've had several near-breaches involving a phishing technique where a compromised account emails everyone in the victim's address book. The message links to a legitimate SharePoint site, but the site leads to a spoofed Microsoft sign-in and MFA prompt. If the recipient completes the prompt, the attacker can take over the account and repeat the process using the new victim's contacts. How are you preventing and responding to this?

5 Answers

Answered By QuietMaple63 On

For a compromised account, immediately revoke active sessions, reset the password, remove unfamiliar authentication methods, review OAuth app consent, forwarding rules, inbox rules, recent SharePoint activity, and outbound messages. A short help-desk playbook makes containment much faster.

Answered By NorthstarLynx7 On

Use Conditional Access to block device code authentication if your organization doesn’t have a legitimate need for it. If the attack depends on that flow, removing it is more reliable than expecting users to recognize the phishing page.

Answered By CopperVale19 On

Training is still useful, especially because these messages may come from trusted partners or internal departments and can point to genuine Microsoft pages. Simulated phishing exercises and clear guidance to verify unexpected file-share invitations help, but users shouldn’t be the only control.

Answered By SilverPine_27 On

I’d also review whether users really need permission to create SharePoint sites or similar collaboration resources. Restricting unnecessary creation and access paths can reduce the attacker’s ability to build convincing lures, while phishing-resistant MFA such as FIDO2 security keys or passkeys adds another strong layer.

Answered By BrightHarbor_8 On

Conditional Access can also require a corporate-managed or compliant device. That prevents sign-ins from unknown personal devices and makes it much harder for an attacker to use stolen credentials or an intercepted code.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.