
Fake 'Code of Conduct' Emails Are Stealing Work Passwords. How to Spot Them
Scammers are sending realistic looking work emails about company policies to steal login credentials. Even two-factor authentication isn't always protecting victims.
Source
Microsoft Security Blog
Original headline: Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
Plain-English summary by GetCyberRight. Read the full report at the source above.
A new email scam is making the rounds that looks extremely convincing. Scammers are sending emails that appear to be from your employer about reviewing or signing a company code of conduct or policy document. The emails look legitimate because the attackers are using real email services and making the messages appear fully authenticated.
When you click the link and try to log in, you are actually giving criminals your work password. This primarily affects people who work at companies or organizations that use Microsoft 365 for email and work tools. What makes this attack especially dangerous is that it can bypass even two-factor authentication in some cases.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
The scammers steal not just your password but also your active login session, giving them full access to your work accounts, emails, and files.
- Do not click any links in the email. Instead, go directly to your company's intranet or HR portal by typing the address yourself.
- Call your IT department or HR to verify whether they actually sent this request.
- Look at the sender's email address carefully. Hover over any links without clicking to see where they really go.
- If you already clicked a link and entered your password, change your work password immediately and contact your IT department right away. Make it a habit to never click links in unexpected emails, even if they look official. When in doubt, go directly to the website yourself or call to verify. Teach your family members who work from home or have work email on their phones to do the same. Scammers are getting better at making fake emails look real, so your best defense is to stop and think before clicking anything. If an email creates urgency or pressure to act quickly, that is often a red flag.
Curated from trusted cybersecurity sources by GetCyberRight
Source: Microsoft Security BlogStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles
Critical Linux Bug Being Exploited: What Small Businesses Need to Know
CISA warns that hackers are actively exploiting a major Linux vulnerability affecting systems built since 2017. Here's what you need to do right now.
3 min readCopyFail Linux Bug: What Small Businesses Need to Know Right Now
A serious Linux security flaw is under active attack. If your business uses Linux servers, cloud hosting, or web services, you need to act today.
3 min readCritical Office Software Flaw Puts Business Networks at Risk
A serious security hole in widely used office automation software has been exploited by hackers since March, potentially exposing business data and networks.
3 min readCritical Linux Flaw Now Under Attack: What Small Businesses Must Know
A serious security flaw affecting Linux systems since 2017 is now being actively exploited. Here's what you need to know and do today.
3 min read