SharePoint Phishing Wave: Trusted Links, Stolen Credentials
A live SharePoint phishing wave shows how convincing these attacks have become.
A new wave of phishing attacks is using SharePoint sharing links to steal credentials, and the emails show none of the usual warning signs. Attackers are increasingly using trusted platforms to slip past both filters and instinct. A clean looking email is no longer proof that it is safe.
ANATOMY OF THE ATTACK
No warning signs to catch. These emails show none of the typical hallmarks of fraud. The header is legitimate, there is no spoofed domain or spelling mistakes, and the sender is often someone the recipient already knows.
A genuine link, hiding a fake one. The link in the email points to a real, legitimate SharePoint site. The file shared through it, however, contains a phishing link that harvests the user’s credentials the moment they are entered.
Part of a wider campaign. This is not an isolated case. Switzerland’s National Cyber Security Centre (NCSC) has flagged a global SharePoint phishing wave confirmed to be affecting Switzerland as well.
Source: NCSC, Week 5 - Global SharePoint phishing wave, Switzerland also affected
19% of breaches across EMEA now involve phishing, and the attacks are getting harder to spot on sight.
Source: Verizon 2025 Data Breach Investigations Report, EMEA
WHAT TO DO IF YOU SUSPECT PHISHING
Act immediately, not after confirmation. If a user reports or suspects a fraudulent email, the first step is to reset the affected password and revoke active sessions right away, before the investigation is complete.
When in doubt, escalate. Escalate immediately if you are unsure. A few minutes spent checking a suspicious email is always cheaper than the hours spent recovering from a compromised account.
HOW MATSCO HELPS YOU STAY AHEAD
Dark Web ID Monitoring. Continuous, human led monitoring of criminal marketplaces and forums for your exposed company credentials, so you find out before an attacker does, not after. Ask your Matsco account manager to arrange a free Dark Web scan for your organization.
Phishing-Resistant Awareness Training. Ongoing simulated phishing campaigns and short-form training that sharpen employee instincts against exactly this kind of attack, the ones with no spelling mistakes and no spoofed domain.
24/7 Managed Detection & Response. Real-time monitoring and rapid incident response, so a single stolen credential is caught and contained before it becomes a network-wide compromise.
Not sure if an email is genuine? Forward it to your Matsco service desk before you click anything. Verifying a link takes seconds; recovering from a breach doesn’t.
Ready to see what’s already exposed? Ask your Matsco account manager about a free Dark Web scan, a phishing simulation for your team, or a full security review, whichever gets you ahead of the next one of these.
Any questions, we’re here to help.