All Resources
Security Alerts

Security Alert: Active Microsoft 365 Phishing Campaign

Over the last several days our team has seen a spike in Microsoft 365 login-harvest phishing attempts against businesses across Greater Sudbury and Northern Ontario. This short alert covers what the emails look like, what to do if a user has already clicked, and the fastest way to reduce your exposure.

July 18, 2026 3 min read Greater Sudbury & Ontario

What the phishing emails look like

  • Subject lines referencing shared documents, e-signature requests, or a 'quarantined' message
  • Sender display name looks legitimate; underlying address is suspicious
  • Link leads to a convincing fake Microsoft login page
  • The fake page captures the password AND the MFA code in real time

If a user has already clicked and entered credentials

  • Reset the user's Microsoft 365 password immediately (from a clean device)
  • Revoke all active sessions for the account
  • Check for and remove any mailbox forwarding rules the attacker created
  • Review sign-in logs for unusual locations
  • Enable MFA if not already enforced — and prefer number-matching over simple push

How to reduce future exposure

  • Enforce MFA on every Microsoft 365 account
  • Enable Conditional Access to block risky sign-ins
  • Turn on external sender warnings and mailbox rule auditing
  • Roll out short, focused phishing training to remind staff to hover before clicking

Need help right now?

If you suspect an active compromise, contact us immediately for incident response support.

Keep exploring

Related services, locations, and resources

Related services

Related resources