What's happening in email security: June 22 – June 28, 2026
Here's a sentence to ruin an email admin's afternoon: this week produced phishing that passed SPF, DKIM, and DMARC cleanly, plus a separate kit that sidesteps MFA without ever breaking it. Microsoft named the first technique "authentication laundering." The second, a device-code phishing platform, posted a 1,380% growth chart. Attackers also spent the week hiding lures inside Microsoft 365 Groups and calendar invites. If you've been treating an authentication pass or an MFA prompt as proof of trust, this is the week to stop.
Microsoft warns of "authentication laundering" through Calendly
Since April, attackers have been phishing hotels across Europe and Asia by routing their messages through Calendly's real notification infrastructure. Because the mail genuinely originates from Calendly, it inherits Calendly's trusted authentication and passes SPF, DKIM, and DMARC on the way in. Microsoft calls this authentication laundering, and it's a precise name. The lures reference guest complaints, bedbug reports, and inspections, targeting front-desk and reservations staff, and they end in a ZIP with a disguised shortcut that installs a memory-only Node.js implant reported as TonRAT.
This is the clearest demonstration in a while of a thing email teams know intellectually but don't always defend against: SPF, DKIM, and DMARC authenticate the sending infrastructure, not the sender's intent or the message's content. A legitimate SaaS relay is a perfectly valid, fully authenticated way to deliver a malicious payload. The takeaway isn't that authentication is useless. It's that an authentication pass is the start of your inspection, not the end of it. You still have to look at the downstream links and behavior.
Attackers are hiding in Microsoft 365 Groups and your calendar
Fortra documented attackers abusing legitimate M365 collaboration features to make phishing look like routine business. They invite targets into attacker-controlled Groups themed around payroll, contracts, or training, then deliver lures through group mailboxes, shared files, and calendar invites. The "CalPhishing" variant drops recurring malicious events straight onto victims' calendars with .ics files, so the reminders keep the lure alive long after the original message would have been deleted. Because it all flows through genuine Microsoft infrastructure, external-sender warnings and early detection often don't fire.
Up to 14.2 million email logins exposed in a Japanese ISP breach
KDDI disclosed a breach of the shared email platform it runs for six ISPs, including JCOM, NIFTY, and BIGLOBE. Attackers exploited a flaw in third-party software, and only "some" passwords were hashed. Treat every affected address as exposed. A pool of ISP mail credentials that size is fuel for credential stuffing, account takeover, and the targeted phishing that follows.
Device-code phishing is up 1,380%, and it's an AI business now
Huntress detailed EvilTokens, a phishing-as-a-service platform with generative AI built in, designed to steal Microsoft 365 tokens at scale. Device-code phishing rose 1,380% comparing the back half of 2025 to the first four months of 2026. In one wave that hit 344 organizations, no two lures were identical, which is the tell for AI-generated personalization. The technique abuses Microsoft's legitimate device-code authentication flow to capture access and refresh tokens, so it sidesteps MFA rather than breaking it. There's no fake login page and no malware for a gateway to catch.
If your M365 tenant doesn't need the device-code flow, restrict or disable it in Conditional Access. Then watch for anomalous token grants, because this is one your login-focused monitoring will miss.
- A phishing email cost a healthcare vendor 1.4 million records
Xsolis disclosed a breach affecting nearly 1.4 million people, with initial access via a targeted phishing attack back in January, exposing Social Security numbers and medical treatment information.
Want email security news in your inbox every week?
Subscribe here and stay up to date with what's happening in email security.




