A trusted vendor email can lead to Microsoft 365 credential phishing when attackers compromise a legitimate business partner’s account and use it to distribute malicious content. Because the message comes from a known sender, recipients may be more likely to trust the email, open its attachment, and follow links that lead to a credential-harvesting page.
ProArch’s Security Operations Center identified and disrupted a coordinated phishing campaign that used this exact technique. A malicious PDF sent from a compromised vendor account redirected recipients through multiple domains before taking them to a page designed to capture login credentials.
The investigation connected suspicious sign-in activity across multiple users to the malicious email, uncovered attacker-created mailbox rules, and revealed that the campaign had reached more employees than the original security alerts indicated.
ProArch’s Security Operations Center identified a coordinated credential-phishing campaign targeting multiple users in a client environment. The attack began with an email sent from an account belonging to a known and previously trusted vendor.
The email carried a malicious PDF attachment. When opened, the document redirected recipients through several intermediary domains before reaching a credential-harvesting page designed to capture login information.
Because the email appeared to come from a trusted business partner, several employees engaged with the attachment, and subsequent suspicious sign-in activity indicated that some accounts may have been compromised.
The investigation also uncovered attacker-created mailbox rules intended to hide the malicious activity from affected users, a classic sign of an attacker trying to maintain quiet access.
Rapid detection, correlation, and containment by the SOC stopped further spread and protected the client’s environment from deeper compromise.
This incident is directly relevant to CISOs, IT administrators, and SOC teams managing Microsoft 365 environments — especially organizations that rely on regular email communication with external vendors and third parties. Any business where a compromised or abused vendor account could be used to deliver phishing content should take note of the tactics observed here.
The campaign began with unfamiliar sign-in alerts across multiple users. Correlating identity telemetry with email activity, the SOC traced the root cause to a single malicious email carrying a weaponized PDF.
How Was the Phishing Campaign Executed?
What Immediate Actions Should You Take to Contain Credential Phishing?
A Microsoft 365 Security Assessment can help identify gaps across identity and access controls, email security, monitoring, external sharing, and core tenant configuration.
How Can You Reduce Future Vendor Email Compromise Risk?
The SOC continues to monitor for additional senders and infrastructure tied to this campaign, along with similar vendor-impersonation attacks across our client base. Organizations that have communicated with vendors exhibiting unusual send behavior are encouraged to review their own environments against the indicators identified in this investigation.
Organizations needing the campaign’s published attachment, domain, IP, and mailbox-rule indicators should consult ProArch’s related trusted third-party phishing warning signs and response advisory.
Security teams can also review related Microsoft 365 phishing research from the ProArch SOC:
This investigation highlights what sets a mature SOC apart from basic alert triage: the ability to connect a single sign-in alert to a broader, multi-stage attack chain spanning identity, email, mailbox, and network telemetry.
By correlating signals across systems, sandboxing suspicious attachments, and maintaining vigilance well after initial containment, ProArch’s SOC identified — and kept disrupting — a campaign that would have gone unnoticed by tools relying on sender reputation alone.
This proactive, connected approach is what keeps our clients protected against increasingly sophisticated, trust-based phishing techniques.