Drooid Logo
Back to story perspectives

Full Breakdown

Microsoft Uncovers Global Code-of-Conduct Phishing Campaign Targeting 35,000 Users

5/6/2026, 12:18:30 PM

Campaign Overview

Microsoft Defender Security Research observed a credential-theft operation on April 14-16 2026 that sent fake “code of conduct” emails to more than 35,000 users in 13,000 organizations across 26 countries. Ninety-two percent of the victims were in the United States, with healthcare & life-sciences (19 %), financial services (18 %), professional services (11 %) and technology (11 %) most represented. The messages were dispatched via a legitimate email-delivery service, used polished HTML templates, and included a PDF attachment that linked to attacker-controlled domains.

Technical Details

The PDF prompted recipients to click a “Review Case Materials” link, which directed them to a Cloudflare CAPTCHA. After solving the challenge, victims encountered a series of staged pages that mimicked internal validation before reaching a counterfeit Microsoft sign-in form. The form captured authentication tokens in real time, allowing adversary-in-the-middle (AiTM) phishing to bypass multi-factor authentication. Links pointed to domains such as acceptable-use-policy-calendly.de, and a green Paubox banner claimed HIPAA-compliant encryption. Separate analysis showed attackers also leveraged compromised Amazon Simple Email Service (SES) credentials to send authenticated messages that passed SPF, DKIM and DMARC checks.

Impact and Why It Matters

By harvesting authentication tokens, the campaign circumvented MFA and granted immediate access to compromised accounts. The use of trusted services such as Amazon SES and Paubox, combined with sophisticated UI mimicry, reduced detection odds and heightened risk for sectors handling sensitive data, notably healthcare and finance.

Official Findings and Recommendations

Microsoft said the operation was among the most sophisticated code-of-conduct-themed credential theft campaigns observed to date. It advises a layered defense: enable Exchange Online Protection and Defender for Office 365 features such as Zero-hour Auto-Purge, Safe Links, and Safe Attachments; deploy network protection and SmartScreen-enabled browsers; enforce strong authentication (MFA, passwordless, conditional access); conduct regular user-awareness training; and activate automated attack disruption in Defender XDR.

Verbatim Quotes

  • “The lures in this campaign used polished, enterprise-style HTML templates with structured layouts and preemptive authenticity statements, making them appear more credible than typical phishing emails and increasing their plausibility as legitimate internal communications,” — Microsoft Defender Security Research Team and Microsoft Threat Intelligence
  • “Because the messages contained accusations and repeated time-bound action prompts, the campaign created a sense of urgency and pressure to act.” — Microsoft Defender Security Research Team and Microsoft Threat Intelligence
  • “The insidious nature of Amazon SES attacks lies in the fact that attackers aren't using suspicious or dangerous domains; instead, they are leveraging infrastructure that both users and security systems have grown to trust,” — Kaspersky
  • “one of the most sophisticated code-of-conduct-themed credential theft operations observed to date,” — Microsoft

Outlook

Microsoft will extend Defender XDR automation to disrupt similar AiTM flows and will monitor the shifting hosting patterns of phishing-as-a-service operators. Analysts expect CAPTCHA-gated phishing to keep rising, urging organizations to strengthen detection, email-authentication controls, and user education.