phishingcybersecurityMicrosoft 365small businessIT management
New phishing kits target Microsoft 365 accounts, evade MFA
July 13, 2026
Back to all postsA new wave of phishing attacks has been detected, specifically designed to target Microsoft 365 accounts. These sophisticated phishing kits, known as 'WebQuest' and 'Finnish Gold', have been found to evade Multi-Factor Authentication (MFA) measures commonly used for account security. The attacks trick users into providing their credentials by disguising themselves as legitimate Microsoft notifications or links, which are then sold on the dark web. This poses a significant threat to Canadian businesses, as M365 is widely used and these attacks can result in data breaches, financial losses, and damage to reputation. To protect your business, it's crucial to educate employees about phishing attempts, use strong authentication methods beyond just MFA, and ensure regular security audits and employee training sessions are conducted.
Source: BleepingComputer
phishingcybersecurityMicrosoft 365small businessIT management
Concerned about this threat to your business?
We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.
