The Microsoft 365 Defender Threat Intelligence Team posted its findings on its Security blog, which details how the attacks are done and advises what people can do to defend themselves.
CHUYN/Getty Images
The attack works by leading Office 365 users down a series of links and redirections to a Google reCAPTCHA page. Users are taken to a fake sign-in page where their credentials are stolen, leaving them compromised.
Comment