Researchers spotted a new phishing campaign, abusing Dynamics 365 Customer Voice, a Microsoft tool with over 500,000 users including Fortune 500 companies.
Attackers are using phishing emails with fake Dynamics 365 Customer Voice links to steal login credentials from victims.
The phishing emails focus on financially related topics, targeting organizations in various sectors, including community groups, universities, news outlets, health information groups, and more.
The attackers have targeted over 3,000 emails, aiming at more than a million different inboxes belonging to 350 organizations, with the ability to capture MFA codes as well.