Fraud involving Dynamics 365 affects over one million accounts
2 min read
Fraud involving Dynamics 365 exposes over one million accounts in a phishing campaign primarily targeting businesses and organizations in the United States.
Check Point Research has revealed a new phishing campaign exploiting Dynamics 365 Customer Voice, a Microsoft tool used by more than 2 million businesses worldwide, according to Statista.
This software is widely used for call recording, surveys, and collecting customer feedback. Due to its large global user base, it has become an attractive target for cybercriminals.
Details of the Attack.
To date, over 3,370 malicious emails have been identified. These emails have affected more than one million mailboxes across over 350 companies, most of which are located in the United States.
The compromised entities include universities, media outlets, community organizations, healthcare organizations, and others.
In this attack, cybercriminals send business-related files and even invoices from previously compromised accounts.
The emails contain fake links that appear to come from Microsoft Dynamics 365 Customer Voice, designed to deceive recipients.
The convincing appearance of these messages makes it easier for victims to fall into the trap. The email subjects often relate to financial matters, such as settlement statements, electronic payments (EFT), ALTA documents, or closure disclosures.
Deceptive Techniques Used.
The fraudulent links redirect to fake pages that mimic showing a voice message or a PDF file.
Some emails even combine legitimate links with malicious ones to increase their credibility.
Once the victims click on the links, they are directed to a page that presents a CAPTCHA test, designed to look legitimate.
They are then redirected to a fake Microsoft login page, aimed at stealing user credentials.
Consequences of the Theft.
The primary goal of this campaign is credential theft. If the attackers succeed, they could gain access to internal systems, steal sensitive information, funds, and even disrupt operations of the affected companies.
Microsoft has managed to block some of the pages used in this campaign. However, some emails may have reached users’ inboxes before the malicious links were removed.
In response to this threat, Check Point Software recommends that cybersecurity officers inform their employees about such attacks.
They also suggest always verifying the source of suspicious emails, especially those that appear to come from Microsoft services like Dynamics 365 Customer Voice.
Manuel Rodríguez, Engineering Manager at Check Point Software’s NOLA, emphasized:
“Organizations should implement advanced email security solutions, preferably with AI capabilities, cloud protection, and integrated threat detection mechanisms. Check Point Software has proactively blocked this campaign by removing malicious links and adding new layers of protection to its products.”