Access to any email account can lead to a payday for cyber criminals. But not all email accounts are created equal. Domain Administrator accounts have high levels of access and are becoming specific targets of phishers.
Admins make great targets because of what can be accomplished if an attacker gains access to one of these accounts. Office 365 admins can change passwords, create new accounts, read other user’s emails and even send email as any member of the organization.
Phishers have recently started rolling out targeted campaigns to steal admin credentials. These campaigns utilize fraudulent, but convincing, Office 365 admin alert emails. Office 365 admins typically receive legitimate alerts about things like unauthorized access or if email services are impacted. Since these fake emails look so much like the real thing, some admins are falling prey and providing attackers with their credentials, opening a serious security hole.