Microsoft 365 mailboxes hijacked for spyware

Published July 20, 2026

Microsoft 365 accounts can be hijacked to steal emails and files. Attackers use the calendar feature to send commands and steal data without you noticing.

Report priority
Medium
Targets
Microsoft 365

How it works

Attackers hijack a Microsoft 365 account, then use its calendar to send hidden commands and steal emails and files.

What to do

Check if your Microsoft 365 account was hacked by reviewing recent logins and looking for unknown devices or locations.

Enable multi-factor authentication in Microsoft 365 security settings to block attackers from logging in, even if they steal your password.

Technical details

An attacker steals a Microsoft 365 password, maybe from a phishing scam or a leaked password list. They log in, hide their activity, and start using the victim's calendar to send secret commands. The victim's own Microsoft 365 account then sends stolen emails and files back to the attacker's hidden server, all while the victim sees nothing unusual in their calendar or inbox.

A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.