phishingcybersecurityMicrosoft 365small businessIT management

New phishing kits target Microsoft 365 accounts, evade MFA

July 13, 2026

Back to all posts

Source: BleepingComputer

A new wave of phishing attacks has been detected, specifically designed to target Microsoft 365 accounts. These sophisticated phishing kits, known as 'WebQuest' and 'Finnish Gold', have been found to evade Multi-Factor Authentication (MFA) measures commonly used for account security. The attacks trick users into providing their credentials by disguising themselves as legitimate Microsoft notifications or links, which are then sold on the dark web. This poses a significant threat to Canadian businesses, as M365 is widely used and these attacks can result in data breaches, financial losses, and damage to reputation. To protect your business, it's crucial to educate employees about phishing attempts, use strong authentication methods beyond just MFA, and ensure regular security audits and employee training sessions are conducted.
phishingcybersecurityMicrosoft 365small businessIT management

Concerned about this threat to your business?

We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.

Book a free assessment