Direct Send: How Attackers Weaponize Your Infrastructure Against You
An employee at your company receives an email from hr@yourcompany.com. The domain matches. There is no warning banner. The message asks them to review a payment approval document. They click. That email was never sent by your HR team. An attacker sent it, and your own Microsoft email infrastructure delivered it, with no password and no credentials required.