Ghost-Sender Flaw in Exchange Online Raises Financial Fraud Risk
Exchange Online is a cloud email service widely used by businesses. Cybersecurity company InfoGuard said a systemic configuration flaw dubbed Ghost-Sender allows attackers to spoof any sender address, exploiting recipients' trust in an identity. Attackers could impersonate suppliers or executives and send fraudulent invoices, increasing the risk of business email compromise and misdirected payments.
InfoGuard's latest disclosure said Ghost-Sender has already been used in fraudulent invoice schemes, though the dates of the incidents, losses and number of affected organizations have not been disclosed. Microsoft had yet to provide a fix at the time of the disclosure, and researchers estimated that more than 20% of Exchange Online environments remained exposed.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.