Vane3alga

Business
Focused
Technology

Using a fake internal memo from HR, per-user custom-named email attachments, SharePoint Online, and a realistic-looking HR form, this phishing attack has all the ingredients to trick your users.

it360 feb 01

This far into the pandemic, there are groups of users within your organization begging to come back to the office, as well as those that never want to set foot in the office again. This emotional attachment to either sentiment is the basis for this newest scam, documented by security researchers at Abnormal Security.

The scam appears to come from internal HR, informing users of dates that the offices are expected to reopen and when employees should return to the office to work. Each contains an HTML attachment with the victim’s name on it (see below).

it360 feb 02

Unlike most html attachments, the link doesn’t take the user to a malicious webpage; instead it takes them to a SharePoint Online document that appears to be an HR document the user is required to acknowledge. This use of a legitimate Office 365 SharePoint site helps these attacks bypass security and find their way to the user’s Inbox.

The most dumbfounding part of this attack is how the user is tricked out of their credentials. At the end of the HR form, they are simply asked for their email address (which is presumed to be their username) and then asked to enter in their password as a means to establish identity as part of agreeing to the presented HR policies. Anyone who understands when and where passwords would be used can easily see this isn’t one of those times.

The scam is a good one – it uses evasive techniques to ensure delivery, establishes legitimacy and urgency, and quickly seeks to reach its malicious goal. Users that have undergone Security Awareness Training should be able to spot this as being a scam, keeping their credentials – and your organization – secure.


SOURCE: KnowBe4.com

Success Stories

Principal Owner, Marketing Firm

Bringing IT360 on as our technology services “department” was one of the smartest business decisions we’ve made. Over the years, we’ve tried various similar services and have also hired internal IT staff, and we’ve never felt confident that we were adequately supported. IT360 has changed all that. They not only provide proactive, comprehensive technical support and consulting, they engage with us in a way that feels like they are part of our company…a true business partner.

Principal Owner, Marketing Firm

Recent
Technology News

IT 360 News - Why Your Old Phone System Is Holding You Back
Why Your Old Phone System Is Holding You Back

It’s Time to Rethink How Your Business Communicates Many businesses are still relying on traditional phone systems that were designed for a very different era—when everyone worked in one building, at one desk, on one device. Today’s workforce looks nothing like that. Teams are remote or hybrid. Employees expect mobility. Companies are growing, changing, and […]

Read more
IT 360 News - Why Technology Governance Is Moving From “IT Issue” to Executive Responsibility
Why Technology Governance Is Moving From “IT Issue” to Executive Responsibility

Over the past year, technology failures have increasingly made headlines—not because of system outages alone, but because of their business consequences. Cyber incidents, operational disruptions, and data exposure events are no longer viewed as isolated IT problems; they are now framed as governance, risk, and leadership issues. This shift is not theoretical. Insurers are tightening […]

Read more