Phishing recipients targeted by role
At a glance
| Field | Details |
|---|---|
| Actor or Group | Unidentified phishing actors and cybercrime groups |
| Activity Type | Email spoofing, business email compromise, and spearphishing |
| Targets or Victims | Corporate executives, finance managers, and procurement staff |
| Scale | Multiple enterprise tenants targeted between 2025 and 2026 |
| Jurisdiction Status | Under observation by threat researchers; no official charges filed |
| Source | ReliaQuest Threat Research |
Executive Summary
Security researchers identified an active Microsoft 365 RejectDirectSend bypass using empty envelope senders. This security loophole allows external senders to deliver unauthenticated messages showing internal company addresses. Consequently, malicious actors exploit this blind spot to impersonate trusted colleagues and deceive corporate employees.
What Happened in the Direct Send Attacks
Researchers discovered that external senders can circumvent native Microsoft 365 protections without using stolen credentials. According to the investigation, “ReliaQuest observed that an empty Simple Mail Transfer Protocol (SMTP) envelope sender can bypass RejectDirectSend, the Microsoft 365 control meant to block unauthenticated Direct Send mail.”
Normally, Direct Send permits on-premises hardware like scanners or printers to transmit notifications across a tenant. As the team explains, “Direct Send allows devices and applications to send email to recipients in the same Microsoft 365 tenant without authentication.” Microsoft introduced RejectDirectSend to block unauthorized sources from sending internal emails.
However, security analysts proved that this defensive mechanism contains a serious design gap. During controlled lab tests, researchers delivered two separate emails to an Exchange Online mailbox. The first baseline message used a legitimate internal domain within the SMTP envelope. Microsoft 365 detected this address and immediately blocked the transmission. Next, the researchers cleared the envelope sender field and transmitted the second message using a null reverse path.
The Mechanics of the Null Sender Flaw
The test results revealed an immediate breakdown in tenant protections. As noted in the study, “RejectDirectSend evaluates the domain in the SMTP envelope sender, but an empty value means there’s no domain to check.” Because the field was blank, Microsoft 365 accepted the incoming connection and queued the message for delivery.
The visible From header still showed a legitimate internal technical support address. Therefore, the recipient saw a familiar sender name on their screen. Downstream spam filters assigned a high spam score to the unauthenticated email. However, the message already bypassed the front-line barrier. The complete findings appear in the published ReliaQuest threat research report.
Who Is Behind the Phishing Activity
Researchers attribute these attacks to diverse cybercriminals rather than a single state-sponsored unit. Threat analysts hold moderate confidence that multiple independent groups now use this method routinely. Because the tactic is simple, various fraud groups adopt it for daily business email compromise. Moreover, attackers continuously look for subtle loopholes in cloud mail routing.
Furthermore, the intrusion pattern requires minimal technical preparation. As the researchers highlighted, “The technique requires only one empty field-no credentials, no registered lookalike domain, and no dedicated sending infrastructure-so organizations should expect continued use.” Consequently, attackers do not need expensive infrastructure or compromised accounts to initiate contact.
Impact and Operational Scale Across Enterprises
Investigators observed this empty-envelope method hitting enterprise networks between September 2025 and August 2026. During these intrusions, attackers repeatedly targeted high-profile corporate accounts. Specifically, threat groups aimed their deceptive messages at executives, finance leaders, and procurement managers.
These roles routinely handle sensitive financial authorizations, invoices, and contracts. For example, attackers circulated fake payment notifications, document-sharing alerts, and procurement requests. Additionally, cybercriminals crafted meeting invitations and fake investment propositions to lure unsuspecting targets. In several instances, the emails delivered malicious SVG files disguised as voicemail recordings.
Alarmingly, several spoofed emails reached employee inboxes despite failing every standard authentication test. In one documented incident, an email failed SPF, DKIM, and DMARC verification checks. The security filters flagged the message as high-confidence phishing. Nevertheless, the email landed in the user inbox because administrators previously added the spoofed executive address to an internal allow list. This case proves how permissive filtering rules undermine automated safeguards.
How Organizations Can Protect Their Mailboxes
Organizations cannot safely block all empty envelope senders. In standard email architecture, automated systems use null senders for legitimate non-delivery reports. Therefore, blanket blocks would disrupt normal business communications.
Instead, security teams must deploy layered network controls to defeat the RejectDirectSend bypass. First, administrators should configure IP-restricted inbound connectors for all internal mail devices. Lab testing showed that IP-restricted connectors successfully halted every unauthorized Direct Send attempt, regardless of the envelope address.
Second, defenders should audit existing tenant allow lists. Companies must eliminate safe-sender rules that grant blanket exemptions to executive email addresses. Third, security teams should configure transport rules to inspect incoming traffic. Defenders should also examine message headers for unresolvable hostnames and mismatched routing paths. These rules can flag external messages that combine empty envelope senders with internal From domains. By combining these controls, security teams can neutralize this evasive technique.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!