HomeTechnologyHow hackers are using this Microsoft 365 feature to target PayPal accounts

How hackers are using this Microsoft 365 feature to target PayPal accounts

Cybercriminals are reportedly abusing the SRS (Sender Rewrite Scheme) feature within Microsoft 365 to trick PayPal users and gain control over their accounts.

February 05, 2025 / 18:31 IST
Story continues below Advertisement
Hackers are reportedly abusing Microsoft 365 feature to take over PayPal accounts
Hackers are reportedly abusing Microsoft 365 feature to take over PayPal accounts

As part of an unusual phishing campaign, cybercriminals are reportedly abusing the SRS (Sender Rewrite Scheme) feature within Microsoft 365 to trick PayPal users and gain control over their accounts. Targeted PayPal account holders log into their accounts to make payments when actually, it is the hackers who end up taking control of their PayPal accounts, as per a report by Dark Reading. The report is based on a blog post by Carl Windsor, Chief Information Security Officer (CISO) at Fortinet Labs, who claims to have been targeted himself.

According to Windsor, the phishing attack is unconventional as the email address of the sender and the URL provided seem to be genuine. Generally, emails used in a phishing attack look suspicious.

Story continues below Advertisement

Hackers reportedly are exploiting a Microsoft 365 feature to create a test domain which helps them build an email distribution list and then target PayPal users by sending requests for payment. Since the email address and the url look legit (“service@paypal.com”), the payment-request messages could be construed as being legitimate requests from PayPal.

How the PayPal phishing campaign works