Microsoft 365 security · Incident analysis

Security Articles

Practical write-ups on Microsoft 365 incidents — what happens, why it happens, and how to stop it.

⚠ Active threat 12 March 2026 · 7 min read

Stryker Cyberattack: Lessons for Microsoft 365 Tenants

A sophisticated attack targeting Stryker's Microsoft 365 environment used compromised admin credentials to issue mass Intune device wipes. What the attack chain looked like and which controls would have stopped it.

Read article
Incident Compromised account

Microsoft 365 Compromised Account

How attackers gain access to Microsoft 365 accounts, what they do once inside, and the steps to contain the damage and recover control of the tenant.

Read article
Incident Email abuse

Office 365 Mailbox Sending Spam

Why compromised Office 365 mailboxes get used for spam campaigns, how Microsoft responds with outbound limits, and what remediation actually looks like.

Read article
Incident Phishing

M365 Phishing Incident

Internal phishing sent from a trusted Microsoft 365 account is harder to catch and more damaging than external spam. How these attacks propagate and how to investigate them.

Read article