Empty Envelope Email Attacks Target Company Leaders: Cybersecurity Threats
Threat actors are using a new phishing method to bypass Microsoft 365’s security measures, targeting high-level executives with deceptive emails.
Phishing Technique Overview
Threat actors have been exploiting a novel phishing method targeting high-level executives within organizations, leveraging a technique that circumvents Microsoft 365’s RejectDirectSend mechanism for Exchange Online. The attack involves unauthenticated emails that display a legitimate internal domain in the “From” header while leaving the Simple Mail Transfer Protocol (SMTP) envelope sender field blank. This approach allows messages to bypass RejectDirectSend protections, which typically block emails with mismatched SMTP envelopes.
ReliaQuest’s Findings
According to findings from ReliaQuest, the attack involves unauthenticated emails that display a legitimate internal domain in the “From” header while leaving the Simple Mail Transfer Protocol (SMTP) envelope sender field blank. This approach allows messages to bypass RejectDirectSend protections, which typically block emails with mismatched SMTP envelopes. Testing conducted by the researchers confirmed that such “empty envelope” emails are accepted and processed by the system, as the protocol does not flag them as suspicious under current configurations. ReliaQuest emphasized that this is not a vulnerability in Microsoft 365 or Exchange Online but rather a byproduct of how the platform handles legitimate email traffic, such as non-delivery reports.
Attack Patterns and Targets
Analysis of attack patterns between September 2025 and August 2026 revealed that 40% of phishing emails utilizing this method were directed at senior executives, while 25% targeted managers and sales personnel, 20% reached individual contributors, and 15% were sent to shared or service mailboxes. The primary deception vectors in these attacks included fake document-sharing notifications, payment requests, procurement invitations, and loan or investment offers.
Technical Details and Countermeasures
Attackers embedded Scalable Vector Graphics (SVG) files as attachments, masquerading as voicemail recordings to entice recipients to engage with malicious content. While the empty envelope technique enables emails to bypass initial security checks, subsequent layers such as spam filters may still redirect them to junk folders. ReliaQuest also noted that implementing a secure gateway with IP-restricted inbound connectors effectively blocked all test attempts involving blank SMTP envelope senders.
Additional Security Concerns
Microsoft Defender for Office 365 mistakenly flags Google search links as malicious. Brave browser introduces aliases to enhance user privacy, shielding users’ primary addresses from websites while ensuring messages from these services are forwarded. The attack’s simplicity—requiring no credentials, compromised domains, or dedicated infrastructure—makes it a persistent threat. Researchers anticipate continued use of this method over the next six to 12 months, as it exploits gaps in existing email validation protocols without necessitating advanced resources.
Other Security Terms and Updates
- Six pillars, zero gateways: The security model your SEG can’t deliver
- Get daily updates: SC Media’s daily must-read of the most current and pressing daily news
- Bring Your Own Device (BYOD)
- Eavesdropping
- Spoofing
- Internet Message Access Protocol (IMAP)
- Post Office Protocol, Version 3 (POP3)
- Spam
- Store-and-Forward
