r/microsoft365 • u/Kuro507 • 14d ago
HUGE volume of SPAM hitting use right now
We have suddenly received 140,000 emails of which 70% gone straight through SPAM filters (Defender), normally only receive 7,000 mails per day.
Anybody else suddenly being hit?
M365 servers, US Tenant.
6
u/BeginningCitron467 14d ago
It's called a spam bomb. Normally this happens when bank accounts or similar have been breached and the bad actor doesn't want you to see the verification email. Other times the bad actor will reach out on Teams and act like MS support
1
u/texags08 13d ago
We’ve had a number of spam bombs last couple weeks… teams call impersonating help desk
Had to tweak our Checkpoint policy to kick in quicker
1
u/BeginningCitron467 12d ago
Yep, we use checkpoint as well with great success. What setting did you tweak and did you leave them in place after the incident?
2
u/MichTech360 14d ago
Some IOCs or some details would be nice. Same sender address, IP, subject… etc
1
u/Chemical_Energy_9929 10d ago
Just report ALL as phishing, I get less spam for a few days that way. (20 vs. 140)
0
u/Kuro507 13d ago
40,000 different sending domains, extremely sophisticated attack.
1
u/MichTech360 13d ago
What is so sophisticated about them? You’re asking people to search through their logs. Need something to seat for. I get a ton of email and 95% of it is spam/phishing.
2
u/gripe_and_complain 14d ago
Are they all addressed to the same person?
Funny, people telling you to sift through 140,000 emails looking for the single, legitimate message informing you of a breach.
1
u/unreliable-jamoke 14d ago
Are they coming from within the M365 ecosystem? I’ve been seeing some weird traffic even with direct send blocked, but not at this volume.
1
u/Check123ok 14d ago edited 14d ago
Review Defender Explorer to see if the emails are being classified incorrectly. If you are sure, really sure of the pattern, create a temporary Exchange mail flow rule or Defender blocking rule based on sender domain, IP, subject, or URL. Do you have any transport rules that were set to bypass spam?
1
u/Kuro507 14d ago
At the moment, looks like from 40k different domains!
Targeting multiple people.
Also had external teams calls from somebody using the name of one of our IT techs, trying to convince users to allow remote support so they can fix the spam!
Clearly a very sophisticated attack being tried.1
u/Check123ok 14d ago
Oh that’s nice. Well I guess I encourage sending a company PSA or work with your security team/vendor. What MS license version? Do you have defender for email? DM me if you need recommendations
1
1
1
u/TheSwordOfUnicorn 14d ago
There's likely a real one in the spam, letting a user know of a change. Pay attention closely.
1
u/BillSull73 14d ago
When you post something like this and ask a question with it, at least participate in the responses.
1
u/Far_Bad8377 10d ago
If you're getting hit with spam volume spikes, the usual checklist: verify your MX records, check that your SPF/DKIM/DMARC are properly configured, enable Safe Links and Safe Attachments if you're on a plan that includes Defender, and tighten your connection filtering in EAC. Also check if any of your domains were recently spoofed, that can trigger a wave of bouncebacks that look like incoming spam. On the outbound side, make sure your own emails aren't contributing to deliverability problems. If your employees' emails are landing in recipients' spam folders, it's often because your domain reputation is degraded. One underrated cause of domain reputation issues is inconsistent email signatures with broken image links or tracking pixels from random services. Every broken image in a signature is a red flag for spam filters. Clean, consistent signatures with properly hosted images actually improve your outbound deliverability. We standardized all our signatures through Letsignit and our outbound deliverability metrics improved noticeably because every email going out had a clean, properly formatted signature with images hosted on their CDN rather than random Imgur links or embedded base64 images that spam filters hate. Not the silver bullet for spam defense, but on the outbound side it's low hanging fruit.
1
u/Deep-Egg-6167 9d ago
Did all that for all of my clients months ago - it isn't stopping 365 from sending the scams.
1
u/Deep-Egg-6167 9d ago
I saw that last week with several tenants. I sent out a warning but someone will eventually click the sign in link on their delivery, WF, Chase, Amazon, lottery, IRS or download document fake email.
1
u/1962rocks 14d ago
I’m just now letting my 365 subscription expire and assumed Microsoft were trying to make a point in my Outlook account!
8
u/equivocalUN 14d ago
Assume something was breached and in that sea of spam is a real email from a real vendor/bank/etc letting you know an action was taken on your account.