KnowBe4’s Threat Lab said it logged 29,785 confirmed phishing emails abusing Microsoft 365’s Direct Send feature between July and August 2026, and the campaign’s most distinctive trait is not its volume but its schedule. Weekday sends ran between 22,000 and 32,000 emails a week, peaking in the two hours before noon and again around 2pm Eastern; weekend volume dropped to 1,500 to 2,000. Direct Send is a legitimate Microsoft 365 feature meant for devices like printers and scanners to relay mail without a full account, which the attackers used to spoof internal senders, most often HR, admin and accounting, without ever compromising a real employee mailbox.
Why it matters: Direct Send abuse skips the two things most phishing defenses are tuned to catch, a compromised account and a spoofed external domain, because the message is unauthenticated mail that never has to pass through the organization’s normal security gateway at all. KnowBe4 found that about 35% of the messages carried attachments, nearly all of them malicious, and that 4,023 of the emails, roughly one in seven, used a reply-to address pointing to a different domain, routing any employee response straight to the attacker’s own infrastructure.
The original insight: the business-hours clustering is itself a detection signal, not just a curiosity. KnowBe4’s own data shows attackers deliberately timing sends to blend into normal Monday and Tuesday traffic patterns, which means a security team that only reviews phishing volume in aggregate will miss a spike that is, by design, shaped to look unremarkable. Combined with the account-takeover angle in CyberTech’s recent coverage of session-cookie theft and the verification gap described in our help-desk vishing analysis, the throughline is that identity-adjacent attacks are increasingly built to avoid the exact controls, MFA and domain filtering, that defenders lean on hardest.
Source: KnowBe4