Attackers are turning trusted Microsoft workflows against your users. And the quiet retirement of Defender’s built-in VPN is a good reason for every IT manager to look hard at what their bundled tools actually cover.
If you run IT for a growing business, none of this will surprise you: the tools your users trust most are exactly the ones attackers want to imitate. Two recent developments in the Microsoft ecosystem show that clearly. SharePoint has become one of the most abused brands in phishing, and Microsoft has retired the Privacy Protection VPN that shipped inside Microsoft Defender. Both are worth your attention, and both point to the same weakness.
SharePoint phishing: how a trusted brand became an attacker’s weapon
When most IT managers hear “SharePoint vulnerability,” they picture server patching. The bigger day-to-day threat is SharePoint phishing: social engineering that borrows the trust your organization already places in SharePoint’s file-sharing workflows.
SharePoint phishing emails have exploded. In one campaign documented by Check Point, attackers sent more than 40,000 phishing emails disguised as SharePoint and e-signature notifications, reaching roughly 6,100 Check Point–protected customers in about two weeks. The messages spoofed sender names like “[Name] via SharePoint (Online),” reused genuine Microsoft and Office branding, and even routed their malicious links through Mimecast’s legitimate URL-rewriting service so the links looked pre-scanned and safe. Consulting, technology, and construction firms took the heaviest hits, which makes sense given how many contracts and invoices those industries exchange every day.
Microsoft’s own security team documented something more concerning in a multi-stage campaign against the energy sector that it reported in January 2026. Attackers didn’t just imitate SharePoint. They used compromised accounts at trusted vendors to send document-sharing emails that were, on their face, completely legitimate. The subject lines matched real SharePoint sharing notifications. The sending domain belonged to a business partner the target had already worked with. And the link led to an adversary-in-the-middle (AiTM) page built to steal not only passwords but active session cookies.
That session-cookie piece is the part your leadership team needs to understand. AiTM attacks get around multi-factor authentication. When a user signs in through the attacker’s proxy page, the attacker captures the resulting session token and logs in as that user, with no second factor needed, because the user already completed it. From there, the attackers create inbox rules that auto-delete all incoming mail and mark it as read, burying any security warnings so the victim stays unaware while they move toward business email compromise (BEC) and fraudulent wire requests.
For an IT manager, a few points stand out:
- MFA is no longer a finish line. You still need it, but AiTM session theft means basic MFA can’t carry the load by itself.
- A “legitimate” sender proves nothing. When a partner’s account is compromised, the email really did come from their real mailbox.
- Detection has to continue after the click. You need tooling that flags unusual sign-ins, impossible-travel activity, and suspicious inbox rules, not just an email filter on the way in.
Does Microsoft Defender have a VPN? Not anymore
Does Microsoft Defender have a VPN? Not anymore, for most people. Microsoft retired the Privacy Protection VPN that came bundled with Microsoft 365 Personal and Family on February 28, 2025, removing it from Windows, macOS, iOS, and Android. If you relied on Microsoft Defender’s VPN to protect traffic on public Wi-Fi, that feature is gone and needs replacing. (We covered the change in more detail in our earlier post on the Defender VPN update.)
The second story looks unrelated to phishing at first. But when Microsoft ended support for the Defender VPN, its explanation was brief. As the company put it, “We routinely evaluate the usage and effectiveness of our features,” and it moved those resources elsewhere.
A lightly used consumer VPN going away is not a crisis on its own. The pattern behind it should worry anyone building a security stack on bundled features. Plenty of users, and plenty of small businesses, assumed that “Microsoft Defender includes a VPN” meant their traffic was protected on public Wi-Fi. That protection disappeared on short notice, and Android users had to remove the leftover VPN profile themselves.
The point is not that you need a VPN. It’s that any security capability you don’t control can be changed, downgraded, or shut off on a vendor’s schedule rather than yours. If your defense against phishing, session hijacking, or unsecured connections depends on whatever happens to ship inside a subscription this quarter, you’re building on someone else’s roadmap. A security program that lasts is deliberately layered, owned by you, and checked on a regular basis, not stitched together from whatever defaults are turned on today.
How iFlock protects clients across both threats
Closing that gap is the work iFlock does. Our approach doesn’t count on any single vendor feature, whether it’s enabled or retired, to do the whole job. We layer people, process, and technology so that when one control is bypassed or discontinued, the others still hold.
We test your people against real SharePoint phishing lures. Through iFlock’s simulated phishing campaigns, we send your team the same document-sharing and e-signature bait attackers use in SharePoint phishing emails, then turn the results into targeted training. You learn who clicks before a real attacker finds out, and you get a measurable record of improvement over time.
We harden identity against AiTM, not just password guessing. Our consultants help you move past basic MFA to phishing-resistant authentication and conditional access policies that weigh device health, location, and risk on every sign-in. We also help configure Microsoft Defender’s automatic attack disruption, session-cookie revocation, and alerts for suspicious inbox rules, so a stolen session doesn’t quietly turn into a wire-fraud loss.
We give you one owner for the whole picture. Through our vCISO and MSSP services, iFlock provides the strategy and the daily monitoring that bundled tools never will. When Microsoft changes a feature, as it did with Defender’s VPN, you have a partner already tracking the change and adjusting your defenses, instead of finding the gap after an incident. Add our penetration testing, vulnerability management, and compliance and audit-readiness work, and you get a program validated by people rather than assumed from a checkbox.
Across both stories the lesson is the same. Trusting a familiar brand or a bundled default is not a security strategy. Attackers are counting on that trust, and vendors will change their defaults whenever it suits them.
Find your gaps before an attacker does
iFlock’s certified team will assess where your organization is exposed to SharePoint phishing, session hijacking, and over-reliance on bundled tools, then give you a clear, prioritized plan to close those gaps.
Book a no-obligation security assessment with iFlock today. Visit iflockconsulting.com/contact-us or call 1-833-4-HAXORS (1-833-442-9677).
Fly with confidence.
Sources:
- Resurgence of a multi-stage AiTM phishing and BEC campaign abusing SharePoint — Microsoft Security Blog
- 40,000 Phishing Emails Disguised as SharePoint and e-Signing Services — Check Point Blog
- End of support — Privacy protection (VPN) in Microsoft Defender for individuals — Microsoft Support
- Microsoft kills off Defender ‘Privacy Protection’ VPN feature — BleepingComputer
Subscribe To Our Newsletter
Get updates and learn from the best
More To Explore