started · updated
Israel National Cyber Directorate warns of SharePoint phishing campaign
The Israel National Cyber Directorate issued an urgent alert about a new phishing campaign that masquerades as a request to view financial documents via Microsoft SharePoint. The fraudulent messages ask recipients to open an invoice, report, or payment document and forward it for review. Clicking the attached link directs users to a counterfeit Microsoft login page that solicits account credentials and, in some cases, verification codes.
If the credentials are entered, attackers can hijack the victim's email mailbox and use it to send additional phishing messages to contacts, employees, and other organizations. The Directorate advises users not to open unexpected documents, even if they appear to come from a known sender, and to verify requests through a separate communication channel. Recipients should carefully examine the URL before entering any personal data, avoid copying verification codes, and enable two‑factor authentication. Anyone who has already entered credentials should immediately change passwords, terminate active sessions, review mailbox rules for suspicious forwarding, and report the incident to the cyber unit at 119.
Entities
Israel National Cyber Directorate · Microsoft Corporation · SharePoint