Your Colleague Didn't Send You That Link. Their Ghost Did.

Blog Author Img
Karen Letain
Subscribe

Get reasoning, in your inbox.

Threat research and field notes from inside customer inboxes. Twice a month, no spam, unsubscribe anytime.

Blog Main Img

Between 06:51 UTC on April 14, 2026 and 03:54 UTC on April 16 — forty-five hours — Microsoft's Defender Research team watched a single phishing campaign reach more than 35,000 users across 13,000 organizations in 26 countries. The lure wasn't exotic. It was a workplace code-of-conduct notice. Something that looked like it came from HR. Something nobody ignores.

The campaign used polished, enterprise-style HTML templates that Microsoft described as containing 'structured layouts and preemptive authenticity statements' — design choices specifically calculated to make the email read like an internal communication from a legitimate system. Recipients who clicked were routed through a CAPTCHA, through a fake document viewer, and finally to an adversary-in-the-middle proxy that captured their Microsoft 365 session token in real time after MFA completed. 92% of the 35,000 targets were in the United States. Healthcare and life sciences absorbed 19% of the attacks. Financial services took 18%.

Forty-five hours. 35,000 people. 13,000 organizations. All of them had MFA. None of it mattered.

But that April campaign — as large as it was — is not actually the attack this piece is about. The April campaign was a mass-targeting operation: send at volume, capture sessions at scale, move fast. The attack that should genuinely keep security teams awake is the one that ran three months earlier, against energy sector organizations, and operated on an entirely different logic. Slower. More patient. More dangerous.

Because the January 2026 SharePoint campaign didn't just phish employees. It turned them into phishers. It hijacked trusted accounts and used them — your account, your email history, your relationships — to phish everyone you know. And then it used those accounts to phish everyone they know. That is the attack this piece is about: account hijack for downstream propagation. Tagged at trajectory 6.1 and rising in StrongestLayer's 2026 email attack taxonomy. The attack that converts every trust relationship your organization has ever built into a potential attack vector.

Before We Talk About Defense — Let's Talk About What the Attacker Sees

Most security content describes attacks from the defender's perspective: the email arrives, the user clicks, the session is captured. What that framing misses is how methodical and operational this looks from the other side.

An attacker who has compromised a vendor's email account does not immediately act. They read. Here is what they find inside a typical enterprise email inbox — and here is how every piece of it becomes operational intelligence.

ATTACKER VIEW  ·  Subject lines in the inbox tell me which projects are active and which are wrapping up. I know which of your employees is working on the Q3 contract renewal and which is managing the facilities audit. I know what's urgent and what's routine.

Three years of sent items is a communication style guide. The attacker learns how this person opens emails. Whether they use first names or formal titles. Whether they attach documents directly or share SharePoint links. What their signature looks like. The exact phrasing they use when they need something quickly.

ATTACKER VIEW  ·  Your colleague writes 'Hey [name], quick one —' before every informal ask. They never use exclamation points. They always close with 'Thanks, [name].' I now write exactly like them. Your gateway cannot tell us apart because there is nothing to tell apart.

Calendar access shows travel schedules. An executive who is traveling is someone whose colleagues might expect delayed responses and unusual requests. It shows meeting patterns — who meets with whom, how often, about what. It shows the organizational structure in practice, not in theory.

ATTACKER VIEW  ·  You have a call with your CFO's office on Thursday. I'll time the financial request to arrive Wednesday afternoon. You're already in the mindset of preparing for that conversation. A payment question won't seem out of place.

Contact history maps the relationship graph. Who does this person email most frequently? Who do they copy? Who are the distribution lists that reach the most people in your organization? These are the targets for stage five — the propagation wave.

ATTACKER VIEW  ·  You email a distribution list of 340 internal contacts every Friday with project updates. I will send the phishing campaign on Friday morning. 340 people will receive what looks like this week's project update. Most of them will click.

This reconnaissance phase is invisible. The attacker is reading, not sending. No outbound email volume spike. No anomalous authentication. Just a patient, methodical study of everything in the inbox. The average dwell time across documented ATO-BEC incidents is five days. In a downstream hijack campaign, the reconnaissance phase can run longer — the attacker needs to understand enough about the organizational relationships to make their downstream phishing convincing.

The attacker doesn't need to know your organization. They need to know someone who does. And then they need to read that person's email for a week.

The Ghost Chain: Seven Stages, One Vendor Account, Multiple Organizations

What follows is the January 2026 SharePoint campaign as Microsoft's Defender Security Research Team documented it — told in the sequence the attacker executed it, built from Microsoft's own security blog, corroborated by Security Affairs, The Hacker News, eSecurity Planet, and Industrial Cyber.

Stage 1  Inside a compromised vendor's email system

The campaign begins upstream — at a partner organization whose email account was compromised in a prior, separate incident. The attacker is already inside. They have been reading. They know which of your employees this vendor communicates with, what projects are in progress, what a normal SharePoint notification from this vendor looks like. From inside the legitimate, authenticated vendor account, they identify your organization as a downstream target. They compose a phishing email using SharePoint document-sharing conventions — precisely matching the format this vendor uses in legitimate communications — and send it from the real account. The vendor's SPF record passes. Their DKIM signature validates. Their domain reputation is excellent. They've been emailing you for three years.

Stage 2  Your inbox — a Thursday morning

The email arrives. You recognize the sender immediately. The subject line references a project you're actually working on together. The SharePoint link uses a legitimate Microsoft domain — on first click it goes somewhere real. Your email gateway processes it: authenticated sender, clean reputation, Microsoft-hosted URL. No flags. No junk folder. You click the SharePoint link and are redirected to what looks exactly like your Microsoft 365 sign-in page. It is, in every visual dimension, indistinguishable from the real thing. Microsoft's own research notes that the credential prompts in these campaigns are designed specifically to be indistinguishable from legitimate Microsoft authentication flows. There is nothing to scrutinize. You type your password.

Stage 3  A proxy server the attacker controls — milliseconds

The proxy relays your credentials to the real Microsoft server. Microsoft issues an MFA challenge. The proxy relays that to you. You approve it. The proxy captures the session cookie Microsoft issues at the conclusion of a successful authentication. You are logged in. So is the attacker. From this moment, they have a valid, fully authenticated Microsoft 365 session for your account. No alarm fired. No threshold tripped. Every system that evaluated this authentication event returned a green light. Because from their perspective — and they are not wrong — you just logged in successfully.

Stage 4  Inside your Microsoft 365 account — minutes after

Two inbox rules are created. The first deletes all incoming emails and marks them as read. The second suppresses replies to specific threads. You will not see your colleagues' responses to the emails that are about to be sent from your account. The attacker now has persistent, operationally invisible control of your mailbox. Microsoft's security blog notes explicitly: this is the stage most organizations miss in remediation. A password reset does not touch these rules. They survive a credential change and continue operating unless someone specifically audits and removes them.

Stage 5  Your address book, your distribution lists, your sent items

The attacker — working from the reconnaissance they built during the dwell period — identifies the highest-value downstream targets in your contact list. Internal colleagues who would click a document link from you without thought. External partners whose organizations are the real downstream targets. Distribution lists that reach hundreds of recipients in a single send. They compose phishing emails in your name. Same SharePoint document-sharing template. Same subject line style your contacts would expect from you. Same sign-off. The emails go to people who trust you explicitly. Every one links to the same AiTM proxy that captured your session an hour ago.

Stage 6  The replies arrive — and disappear

Some of your colleagues click and get phished. Others reply with questions — 'What's this document about?' 'Is this related to the project we discussed?' The inbox rules delete those replies before you ever see them. The attacker reads each reply and responds — in your voice, with the context they gathered during reconnaissance — to keep uncertain recipients engaged long enough to click. They are having real-time conversations with your colleagues while you are in a meeting entirely unaware any of this is happening. Your colleagues are not talking to you. They are talking to the attacker, who has your email history, your communication style, and your professional context.

Stage 7  The expansion

Every recipient who clicked your phishing link had their session captured the same way yours was. Stage four repeats inside each new account: inbox rules created, contacts studied, phishing emails sent. The attack is now running simultaneously inside multiple accounts across multiple organizations. Microsoft's Defender Experts traced the full scope by correlating landing IP addresses with sign-in IP patterns across all affected accounts and organizations. The campaign had crossed organizational boundaries before most affected users were aware anything was wrong. What started with one compromised vendor account had propagated through a chain of trusted professional relationships — each link in the chain lending its hard-built credibility to the next wave.

That is the ghost chain. One compromised vendor. Seven stages. Six hundred emails. Multiple organizations. And Microsoft's own conclusion, stated directly in their January 21, 2026 disclosure: "This attack demonstrates the operational complexity of AiTM campaigns and the need for remediation beyond standard identity compromise responses." That is the maker of the platform being abused, telling the industry that the standard response to this attack is wrong.

Two Campaigns. One Month Apart. The Same Technique at Different Scales.

The January 2026 energy sector campaign and the April 2026 code-of-conduct campaign represent the same core technique deployed at different operational scales — and comparing them reveals something important about where this threat is going.

The January campaign was precision-targeted. Specific industries. Specific organizations. A patient, multi-week reconnaissance phase before any phishing email was sent. The downstream propagation was the point — using compromised trusted accounts to reach into organizations the attacker couldn't have reached directly. This is the adversarial equivalent of a supply chain attack: get upstream, then use the upstream position to reach targets who would never have been fooled by a cold approach.

The April campaign was volume-targeting. 35,000 users. 13,000 organizations. 45 hours start to finish. The lure — workplace code-of-conduct notices — was chosen specifically because nobody ignores an email that implies you've done something wrong at work. The CAPTCHA, the PDF attachment, the multi-stage redirect chain were all evasion infrastructure designed to delay security analysis long enough for the session tokens to be captured and used.

The scary implication of both campaigns existing simultaneously is that AiTM-driven account hijack is now being industrialized at both ends of the targeting spectrum. Patient, precision-targeted downstream campaigns for high-value organizational relationships. Volume-at-scale campaigns for maximum session capture across the broadest possible target pool. The technique works for both. The session token is equally valuable whether it came from a targeted energy sector executive or a healthcare administrator in a mass campaign.

35,000 users targeted in 45 hours across 13,000 organizations in 26 countries — April 14-16, 2026 — Microsoft Defender Security Research

The Inversion: Why This Attack Makes Every Defense Assumption Wrong

Security infrastructure has spent twenty years being optimized around a single question: is this email from who it claims to be from? SPF validates the sending server. DKIM validates the message signature. DMARC combines both into a policy framework. Domain reputation tracks sending history. All of it is built around authenticating the source.

Downstream account hijack makes that entire question irrelevant.

The vendor account that sent you the SharePoint link is exactly who it claims to be. The authentication passed because the authentication is genuine — the email came from the vendor's real server, signed with their real DKIM key, through a domain with three years of clean reputation. The question 'is this from who it says it's from?' has been answered correctly. The sender is legitimate. The account is compromised.

Classic BEC asks: is this person who they say they are? Downstream hijack answers that question correctly and then asks the one you weren't prepared for: but are they the one currently operating the account?

No gateway-based detection system was designed to answer the second question for external accounts. They have no model of how that vendor's account should behave. They have no baseline for what that colleague's normal communication pattern looks like. They evaluate inbound messages against known-bad signatures and authentication checks. An authenticated email from a compromised account with a clean reputation and a Microsoft-hosted URL gives them nothing to work with.

This is why the attack is tagged at trajectory 6.5 in the taxonomy and why it's rising. Not because it's new — AiTM session capture has been documented since 2022. But because the downstream propagation model specifically exploits the trust infrastructure that security teams have spent years building. The vendor relationship program. The partner network. The carefully managed allowlist of trusted senders. All of it becomes attack surface the moment one account upstream is compromised.

The Part Nobody Wants to Admit: The Standard Remediation Is Wrong

Scenario: your IT team is notified that an employee's Microsoft 365 account may have been compromised. They investigate. They confirm a suspicious authentication event. They reset the password. They close the ticket and log the incident as resolved.

The session token the attacker captured three hours ago is still valid.

This is not a hypothetical failure mode. Microsoft stated it explicitly in the January 2026 disclosure. A password reset does not invalidate an active session cookie. The attacker's browser — loaded with the captured token — still has full authenticated access to the account. The inbox rules they created at stage four are still running, deleting incoming emails, suppressing replies. The phishing emails they sent from the account are sitting in outbox history, and the downstream organizations whose users received those emails have not been notified. And the attacker, who still has an active session, is watching the password reset notification arrive in the inbox — the one they can still read.

Most organizations have no runbook item for active session revocation. It's not in the standard IT incident response checklist. Password reset is. Account lockout is. Session revocation isn't, because most IT teams have never been explicitly trained that a password reset doesn't close an AiTM-driven compromise.

The correct remediation sequence for a downstream hijack incident has five mandatory steps: password reset, active session revocation, inbox rule audit and removal, MFA method audit for attacker-registered authenticators, and downstream notification to every external contact who received a phishing email from the compromised account. Skip any one of those steps and the incident is not closed. As we detailed in the account takeover BEC runbook, the remediation window for session-based compromise is measured in hours. The downstream notification obligation may extend for days as affected organizations are identified.

The Propagation Math: How Far Does One Compromised Account Actually Reach?

The question that makes downstream account hijack genuinely different from every other BEC variant is the one about scale. Not how it starts — but how far it spreads before anyone catches it.

One compromised account in the January 2026 campaign generated hundreds of phishing emails. If even 5% of those recipients click and get their session captured — a conservative rate, given that the emails came from a trusted internal account — that's 30 new compromised accounts. Each of those 30 accounts has its own contact list. Each sends its own wave. The propagation is not linear. It compounds.

The graph of potential spread looks less like a chain and more like a tree. One compromised vendor account is the trunk. Each downstream victim is a branch. Each branch generates its own branches. The attacker doesn't need to do anything after stage five — the trust infrastructure of the organizations involved carries the campaign forward.

This is the operational logic that makes downstream account hijack worth the investment of a slower, more patient initial campaign. A direct AiTM mass campaign like the April 2026 code-of-conduct operation reaches 35,000 people through volume. A downstream hijack campaign reaches fewer people in the initial wave but accesses organizational trust networks that volume campaigns cannot touch — the existing relationships between specific vendors and specific clients, between specific partners and specific contacts, that represent the highest-value targets in any sector.

Financial services showed 22.2% file-sharing phishing rates in 2026 — nearly double the 12.4% industry average — per Abnormal Security's 2026 Attack Landscape Report. The reason is structural: financial services organizations run on external document exchange. Loan agreements. Audit packages. Compliance documentation. A SharePoint notification from a trusted counterparty is so unremarkable in that environment that it generates essentially no scrutiny. The downstream hijack model was built for exactly this environment — where the legitimate workflow provides perfect cover for the malicious payload.

Mid-Market Organizations: Both the Target and the Weapon

The January 2026 energy sector campaign targeted large organizations, but the mechanics of downstream account hijack are industry and size-agnostic. Any organization with real vendor relationships and real trusted partner networks is both a potential victim and a potential propagation vector. Mid-market organizations face a specific double exposure in this model that's worth understanding precisely.

A 300-person professional services firm is targeted downstream because it sits within the vendor ecosystem of larger enterprise clients. Its accounts are compromised. Its compromised accounts are then used to target those larger enterprise clients — organizations the attacker couldn't reach directly but can reach through the professional services firm's trusted relationship with them.

The damage is double. The firm loses the direct cost of the compromise — the fraud, the remediation, the downtime. And then it loses something harder to quantify: the trust of the enterprise clients who received phishing emails bearing the firm's name and email infrastructure. Those clients don't necessarily understand that the firm was a victim. They see an email that appeared to come from the firm trying to phish them. The firm's reputation is the collateral damage in an attack it didn't initiate and didn't know was happening.

This reputational dimension is what makes downstream account hijack uniquely damaging for mid-market organizations. Enterprise organizations have compliance teams, communications infrastructure, and client relationship protocols that can manage the notification of a security incident to affected parties. A 300-person firm typically does not. Their clients hear about the breach from their own security teams, not from a proactive disclosure. The relationship damage compounds the operational damage.

What Detection Has to Look Like for an Attack That Travels Through Trust

Downstream account hijack presents a distributed detection challenge. The compromise doesn't happen once, in one place, generating one alert. It happens continuously — across accounts, across organizations, using legitimate infrastructure at every stage. No single detection point has visibility into the full attack graph.

The Pre-Delivery Window: Hunting Infrastructure Before the Email Lands

For campaigns that use newly registered AiTM proxy infrastructure — as the April 2026 code-of-conduct campaign did — pre-campaign threat hunting offers a genuine early warning window. Domain registration patterns, certificate issuance clustering, and hosting provider correlations that match known AiTM tooling can surface emerging infrastructure before any phishing email is sent.

For campaigns that use established vendor accounts as the delivery vector — as the January 2026 SharePoint campaign did — that pre-campaign signal doesn't exist. The delivery infrastructure is the vendor's real email account and Microsoft's real SharePoint service. Neither generates a suspicious infrastructure signal. The pre-delivery detection window doesn't open until the email arrives in the inbox.

The Delivery Window: Relationship-Context Evaluation

When a phishing email arrives from a vendor's legitimate, authenticated account with a real Microsoft domain URL, the only detection model that has a chance of flagging it is one that evaluates whether this communication makes sense given everything known about the relationship between this vendor and this organization.

Has this vendor ever sent SharePoint links before? Does this type of document request fit the established pattern of this relationship? Does the subject line match the project context this vendor is typically involved in? Does the message arrive at a time and in a format consistent with how this contact typically communicates?

TRACE's relationship engine models exactly these dimensions for every external communication relationship in the organization. When a vendor account that has sent only operational project emails for three years suddenly initiates a document authentication flow, the behavioral deviation generates a detection signal — not because the sender's authentication failed, but because the communication pattern doesn't fit the established relationship model. For downstream attacks specifically, the relationship engine is the layer that matters — it's the only component that can evaluate whether this specific communication from this specific known contact makes sense, without access to the vendor's own account or internal systems.

The Post-Click Window: Account Behavioral Monitoring

For users who do click and get their session captured, the detection opportunity shifts to account-level behavioral monitoring inside the organization. Three signals, combined, are the signature of a downstream hijack propagation wave:

  • Inbox rule creation routing to an external domain — the operational setup for stage four suppression. An alert that fires immediately on any inbox rule creation is the highest-value single control for catching this attack at the last intervention point before the phishing campaign launches.
  • Anomalous outbound email volume — an account that send email in a compressed window is deviating sharply from any established baseline. Per-account volume monitoring with threshold alerts catches stage five before it has reached its full recipient list.
  • Sign-in geography anomaly — a session appearing from an IP range inconsistent with the account owner's established pattern is a high-confidence indicator of captured session use.

The combination of all three simultaneously is the clearest behavioral signature of a downstream hijack in active progress. TRACE's behavioral baseline for each user tracks all three dimensions continuously — typical outbound volume, typical sign-in geography, typical inbox configuration — and generates a high-priority alert when they deviate sharply and simultaneously, independent of any content analysis on the messages being sent.

The Cross-Organizational Notification Gap

When a downstream hijack is identified, the remediation obligation extends beyond the compromised organization. Every external party who received a phishing email from the compromised account is a potential secondary victim who needs notification. Most organizations have no protocol for this. They know how to notify their own users. They have no established process for identifying and notifying the external organizations in their contact list who received malicious emails bearing their name.

Building this protocol before an incident — defining which relationships to notify, through what channel, in what timeframe, using what message — transforms a chaotic reactive process into a manageable one. The NTMA, after the July 2025 vendor fraud incident, commissioned a Deloitte forensic review specifically because their existing protocols didn't cover the full scope of what happened. Having that process in place before the incident is the difference between a contained breach and a reputational event.

Defending the Trust Network: Five Controls That Actually Close This Gap

Phishing-Resistant MFA on Every Account That Holds Organizational Relationships

FIDO2 security keys and passkeys are the architectural solution to the AiTM session capture that powers every stage of the ghost chain. The cryptographic handshake is domain-bound — a proxy serving a different URL cannot complete it, which means the session capture at stage three simply cannot occur if the account uses phishing-resistant MFA. The full AiTM phishing analysis covers the technical architecture. For downstream hijack specifically: every account that communicates with high-value external relationships — every account that could become a propagation node — should be on phishing-resistant MFA. The cost of a security key is trivial relative to the cost of being the account that starts a downstream campaign against your clients.

Inbox Rule Creation Alerts — Immediate, Not Daily

The inbox rule creation at stage four is the last practical intervention point before the propagation wave begins. An alert that fires immediately — not in a daily digest, not as a low-priority notification — when any inbox rule is created on any account gives the security team a window to investigate and revoke the session before phishing emails go out. This single monitoring control requires no sophisticated detection model. It requires configuring a real-time alert in the email management platform and someone who is actually watching it.

Outbound Volume Anomaly Monitoring

Per-account outbound email volume baselines and threshold alerts catch the stage five propagation wave in progress. Combined with inbox rule monitoring, these two controls create overlapping detection coverage for the two most distinctive behavioral signatures of a downstream attack. Both are technically straightforward. Both are absent from most mid-market security configurations.

Vendor Communication Baseline Reviews

Quarterly reviews of communication patterns with key vendor relationships — what does a normal SharePoint notification from this vendor look like, has this contact ever sent document authentication requests before, what channels do we normally use for project handoffs — give employees a documented reference point when a request arrives that doesn't fit the established pattern. It also gives the security team baseline data that makes relationship-context anomaly detection more precise. What's normal for this vendor? What isn't? That question needs an answer before the phishing email arrives, not after.

A Written Cross-Organizational Notification Protocol

When a downstream hijack is confirmed, the clock starts on notifying the external parties who received phishing emails from the compromised account. Having a written protocol in place — the list of key external relationships, the contact channels for security notification, the template for the disclosure message, the threshold for when notification is required versus optional — transforms this from a crisis improvisation into a managed process. It also demonstrates the organizational maturity that regulators and clients increasingly expect to see documented when they ask 'what would you do if this happened?'

The Ghost Network

Here is the thing about the downstream account hijack attack that doesn't get said plainly enough: it is not primarily a technical attack. It's a social one. It succeeds because it exploits something that no technology can manufacture — the trust that accumulates between people and organizations over years of real professional relationship.

The attacker who compromised that energy sector vendor's email account in late 2025 didn't need to be sophisticated. They needed to be patient. They needed three weeks inside a compromised inbox to understand the texture of the professional relationships therein — and then they needed a proxy server and a convincing SharePoint notification to turn those relationships into a propagation network.

What made the April 2026 campaign reach 35,000 people in 45 hours was automation and volume. What makes downstream hijack reach the people a volume campaign never could is the irreplaceable trust of a real professional relationship, borrowed without consent.

The ghost that sends emails from your account knows how you write. It knows what projects you're on. It knows who trusts you enough to click without scrutinizing. It has read everything you've written for the past three years and it uses all of it. Not because it's clever — because it read your inbox.

The defense against it is not more sophisticated threat intelligence or better content filters. It is detection that operates at the level where the anomaly actually lives: in the behavior of the account, in the deviation from the established communication pattern, in the inbox rule that appeared at 3pm on a Wednesday for an account that has never created an inbox rule before. TRACE was built to see those signals — not because it's looking for a known attack signature, but because it knows what normal looks like well enough to recognize when, quietly and precisely, it isn't. The StrongestLayer email attack taxonomy tags account hijack for downstream attacks at 6.1 and rising. The ghost chain is industrializing. The question is whether your detection layer is watching the account — or just the inbox.

Frequently Asked Questions (FAQs)

Q1: Someone on my team got phished through a SharePoint link from a trusted vendor. How?

The vendor's email account was compromised before the phishing email arrived at your organization. The attacker had been inside the vendor's inbox long enough to understand your relationship — what projects you're working on, what a normal SharePoint notification from them looks like. They sent the phishing email from the real, authenticated vendor account — which is why it passed every authentication check and why your team member trusted it. The SharePoint link led to an adversary-in-the-middle proxy that captured your team member's Microsoft 365 session token after MFA completed. Your vendor's account was the weapon. Your team member was the downstream target.

Q2: If MFA was enabled, how did they get into the account?

Adversary-in-the-middle phishing doesn't defeat MFA — it lets MFA succeed and steals the result. The proxy sits between the user and Microsoft's real login page. When the user approves the MFA prompt, the proxy captures the session cookie that Microsoft issues at the end of a successful authentication flow. That session cookie is what gives an attacker authenticated access to the account — no password, no MFA required after that point. The only authentication method that defeats this at the architectural level is FIDO2 security keys or passkeys, because their cryptographic handshake is bound to the legitimate domain and cannot be completed by a proxy.

Q3: We reset the password. Is the account safe now?

No. A password reset does not invalidate an active session. Microsoft stated this explicitly in their January 21, 2026 security blog: 'password resets alone are insufficient.' The session cookie the attacker captured remains valid after a credential change. The attacker's browser still has full authenticated access to the account. The inbox rules they created to delete incoming emails and suppress replies are still running. The complete remediation requires: password reset, active session revocation, review and removal of all inbox rules created during the compromise window, audit of any MFA methods registered during the compromise, and notification to any external contacts who received phishing emails from the compromised account.

Q4: What is the 'ghost chain' and why is it called that?

The ghost chain describes the propagation pattern in downstream account hijack attacks. An attacker compromises one account, uses it to phish multiple contacts, captures those sessions, and then uses those accounts to phish their contacts. At each stage, the emails appear to come from someone the recipient knows and trusts — a colleague, a vendor, a partner. The 'ghost' is the attacker operating inside a legitimate identity, writing in the account owner's voice, using their professional relationships, conducting their conversations with colleagues — while the real account owner has no idea any of it is happening. The chain refers to how the compromise propagates through trust networks rather than technical vulnerabilities.

Q5: How many people can be affected from one compromised account?

In the January 2026 Microsoft-documented energy sector campaign, a single compromised vendor account generated phishing emails to internal and external contacts. In the April 2026 code-of-conduct campaign, 35,000 users across 13,000 organizations in 26 countries were targeted in 45 hours. A May 2026 Infoblox-analyzed campaign targeting universities and multinational institutions — including bodies linked to the EU and UN — used the same downstream propagation model: compromise one account, phish its contacts, use those compromised accounts to phish their contacts. The math is exponential, not linear. One account generates hundreds of phishing opportunities. If 5% click, that's dozens of new compromised accounts, each generating their own wave.

Q6: What is an inbox rule and why do attackers create them immediately after getting access?

An inbox rule is an automated action the email client applies to incoming messages — move to a folder, mark as read, forward to another address, delete. Attackers create inbox rules immediately after gaining access because they need to suppress any incoming messages that might alert the legitimate account owner to what's happening. Specifically, they create rules that delete replies to the phishing emails being sent from the account, mark unexpected emails as read so they don't appear as new, and sometimes forward copies of all incoming mail to an attacker-controlled address for ongoing reconnaissance. These rules operate silently in a part of the email environment most security tools don't monitor in real time — which is why they persist after a password reset and why the remediation has to explicitly include auditing and removing them.

Q7: Why did the phishing email come from a Microsoft domain?

The SharePoint link in the phishing email goes to a legitimate Microsoft-hosted URL on first click — specifically because the lure uses SharePoint document-sharing as its theme, and legitimate SharePoint notifications genuinely do link to Microsoft domains. This is the living-off-trusted-sites technique: instead of building fake infrastructure with suspicious domains, the attacker routes the victim through real, trusted enterprise platforms before reaching the malicious component. Microsoft's own platform — SharePoint, OneDrive — is the delivery vehicle. Only after the initial click does the victim reach the attacker's AiTM proxy. Your email gateway sees a Microsoft URL and passes it. So does every reputation scanner. Because on the first hop, it genuinely is Microsoft.

Q8: How is downstream hijack different from regular phishing?

Regular phishing arrives from a stranger — an attacker-controlled domain, a spoofed sender, a fake brand. The attacker is on the outside trying to get in. Downstream account hijack arrives from someone you already trust — a colleague, a vendor, a partner — because their account was compromised upstream. The attacker is already inside a legitimate identity when they reach you. There is no spoofed domain to flag. No stranger sender to be suspicious of. No fake brand to scrutinize. Every technical check returns clean because the sender is genuinely legitimate. The only anomaly is behavioral — does this communication fit what you'd normally expect from this person, at this moment, about this topic?

Q9: We're a small company. Would attackers actually target us this way?

Yes — and possibly more efficiently than targeting a large enterprise directly. A 200-person professional services firm that serves large enterprise clients is a valuable upstream compromise target because of its relationships, not despite its size. Compromising the firm's email accounts gives an attacker a trusted identity to reach into those enterprise clients — organizations that would never fall for a cold phishing attempt but would click a document link from a vendor they've worked with for three years. Mid-market firms are also typically running Microsoft 365 with default security configurations, no inbox rule creation alerts, and no phishing-resistant MFA across all accounts. The attack surface is large. The monitoring is thin. And the professional relationships are real and valuable.

Q10: What's the fastest way to know if our organization sent phishing emails to our contacts?

Four checks immediately. 1. Review the sent items of any suspected compromised account for the past 30-60 days — look for emails to large contact lists or distribution groups. 2. Check inbox rules on the account for any routing to external domains or deletion rules that the account owner didn't create. 3. Review sign-in logs for authentication events from IP addresses inconsistent with the account owner's known locations. 4. Contact your key external relationships directly — a quick call or message asking 'did you receive anything unusual from us recently?' surfaces downstream exposure fast and demonstrates the proactive communication that clients expect when a vendor has been involved in a security incident.

Q11: Do we have to notify our clients and partners that they might have received a phishing email from us?

Legally it depends on your jurisdiction, the nature of the data involved, and whether any downstream harm occurred. Practically, yes — and promptly. If your compromised account sent phishing emails to clients or partners, they need to know so they can check whether anyone clicked, whether any sessions were captured, and whether they need to run their own remediation. Not notifying them creates a situation where downstream organizations are unknowingly operating with compromised accounts because the upstream organization whose account was used didn't tell them. Beyond the legal considerations, failing to notify damages the professional relationship far more than the incident itself would. The organizations that handle this well notify early, clearly, and with specific information about what happened and what the recipient should check.

Subscribe to Our Newsletters!

Be the first to get exclusive offers and the latest news

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Talk To Us

Your gateway can't see
what's already inside.

Deploy in minutes, not months. Zero tuning. See what your current tools are missing.