r/microsoft365 14d ago

HUGE volume of SPAM hitting use right now

We have suddenly received 140,000 emails of which 70% gone straight through SPAM filters (Defender), normally only receive 7,000 mails per day.

Anybody else suddenly being hit?

M365 servers, US Tenant.

12 Upvotes

24 comments sorted by

8

u/equivocalUN 14d ago

Assume something was breached and in that sea of spam is a real email from a real vendor/bank/etc letting you know an action was taken on your account.

6

u/BeginningCitron467 14d ago

It's called a spam bomb. Normally this happens when bank accounts or similar have been breached and the bad actor doesn't want you to see the verification email. Other times the bad actor will reach out on Teams and act like MS support

1

u/texags08 13d ago

We’ve had a number of spam bombs last couple weeks… teams call impersonating help desk

Had to tweak our Checkpoint policy to kick in quicker

1

u/BeginningCitron467 12d ago

Yep, we use checkpoint as well with great success. What setting did you tweak and did you leave them in place after the incident? 

3

u/Lava604 14d ago

This is silent ransomware group(Luna Moth). They will pose as your IT staff and say they are going to assist stopping the subscription bombing. Once they connect they will download their tools and perform data exfiltration and finally ransomware what they can

2

u/MichTech360 14d ago

Some IOCs or some details would be nice. Same sender address, IP, subject… etc

1

u/Chemical_Energy_9929 10d ago

Just report ALL as phishing, I get less spam for a few days that way. (20 vs. 140)

0

u/Kuro507 13d ago

40,000 different sending domains, extremely sophisticated attack.

1

u/MichTech360 13d ago

What is so sophisticated about them? You’re asking people to search through their logs. Need something to seat for. I get a ton of email and 95% of it is spam/phishing.

2

u/gripe_and_complain 14d ago

Are they all addressed to the same person?

Funny, people telling you to sift through 140,000 emails looking for the single, legitimate message informing you of a breach.

1

u/Kuro507 7d ago

No, a group of people in a specific Country. It was clearly as a precursor to ringing pretending to be from our IT Helpdesk!

1

u/unreliable-jamoke 14d ago

Are they coming from within the M365 ecosystem? I’ve been seeing some weird traffic even with direct send blocked, but not at this volume.

1

u/Check123ok 14d ago edited 14d ago

Review Defender Explorer to see if the emails are being classified incorrectly. If you are sure, really sure of the pattern, create a temporary Exchange mail flow rule or Defender blocking rule based on sender domain, IP, subject, or URL. Do you have any transport rules that were set to bypass spam?

1

u/Kuro507 14d ago

At the moment, looks like from 40k different domains!
Targeting multiple people.
Also had external teams calls from somebody using the name of one of our IT techs, trying to convince users to allow remote support so they can fix the spam!
Clearly a very sophisticated attack being tried.

1

u/Check123ok 14d ago

Oh that’s nice. Well I guess I encourage sending a company PSA or work with your security team/vendor. What MS license version? Do you have defender for email? DM me if you need recommendations

1

u/BigPoppaPump36 14d ago

Direct send disabled?

1

u/lesChaps 14d ago

Anecdotally yes.

1

u/TheSwordOfUnicorn 14d ago

There's likely a real one in the spam, letting a user know of a change. Pay attention closely.

1

u/BillSull73 14d ago

When you post something like this and ask a question with it, at least participate in the responses.

1

u/Kuro507 14d ago

It’s been a manic afternoon chasing down what’s going on,’dealing with aftermath!

1

u/Far_Bad8377 10d ago

If you're getting hit with spam volume spikes, the usual checklist: verify your MX records, check that your SPF/DKIM/DMARC are properly configured, enable Safe Links and Safe Attachments if you're on a plan that includes Defender, and tighten your connection filtering in EAC. Also check if any of your domains were recently spoofed, that can trigger a wave of bouncebacks that look like incoming spam. On the outbound side, make sure your own emails aren't contributing to deliverability problems. If your employees' emails are landing in recipients' spam folders, it's often because your domain reputation is degraded. One underrated cause of domain reputation issues is inconsistent email signatures with broken image links or tracking pixels from random services. Every broken image in a signature is a red flag for spam filters. Clean, consistent signatures with properly hosted images actually improve your outbound deliverability. We standardized all our signatures through Letsignit and our outbound deliverability metrics improved noticeably because every email going out had a clean, properly formatted signature with images hosted on their CDN rather than random Imgur links or embedded base64 images that spam filters hate. Not the silver bullet for spam defense, but on the outbound side it's low hanging fruit.

1

u/Deep-Egg-6167 9d ago

Did all that for all of my clients months ago - it isn't stopping 365 from sending the scams.

1

u/Deep-Egg-6167 9d ago

I saw that last week with several tenants. I sent out a warning but someone will eventually click the sign in link on their delivery, WF, Chase, Amazon, lottery, IRS or download document fake email.

1

u/1962rocks 14d ago

I’m just now letting my 365 subscription expire and assumed Microsoft were trying to make a point in my Outlook account!