04/23/2026
🚨 Heads Up: New Email Scam Making the Rounds (Microsoft 365 Users) 🚨
We’re starting to see more reports of emails that look like they’re coming from your own account… but you never sent them. If you’ve noticed anything like this lately, you’re not alone.
Security teams (including Blackpoint) are seeing a major spike in a tactic called “Direct Send abuse” within Microsoft 365. Attackers are bypassing normal protections and sending emails that appear internal — making them much more convincing.
⸻
⚠️ What’s Happening
* Users receive emails that look like they’re from themselves or coworkers
* Messages often include links like “Review this DocuSign document”
* You’re asked to enter a code to view the file
👉 This is a device code phishing attack
👉 If you enter that code, attackers can gain access to your account
👉 No password or MFA approval needed
⸻
🔐 Why This Matters
This method allows attackers to completely bypass traditional security controls — including passwords and multi-factor authentication. That’s what makes this spike especially dangerous.
⸻
✅ What You Should Do
* Be suspicious of emails that appear to come from your own address
* Do NOT enter any codes sent via email to “open documents”
* Verify unexpected requests through another method (call/text the sender)
* Report anything suspicious to your IT team immediately
⸻
🛠️ For IT/Admins
* Disable Direct Send if not needed
* Disable Device Code authentication flows where possible
* Review mail flow rules and logs
* Continue user awareness training
⸻
Stay sharp — attackers are getting more creative, but awareness is still your best defense. 💪