Common signs include unexpected file sharing from a user account, links changed to public access, malicious files hosted in collaboration tools, and follow-on phishing sent to contacts or external recipients. Suspicious activity can also appear as unusual mailbox or file behavior after the initial compromise. When these signals show up together, teams should assume the account is being used as a delivery point for further attacks.
How SharePoint or OneDrive takeover becomes a phishing delivery path
Once an attacker controls a user’s SharePoint or OneDrive account, they can use the tenant’s own trust to distribute malicious content. That often looks less like a loud takeover and more like normal collaboration activity with a malicious purpose. Watch for sharing links, file replacements, or new content that appears to come from a trusted internal account but behaves like a lure.
The important distinction is that the compromise is not only about data access. In a phishing campaign, the account becomes a staging point for delivery, which means the attacker is trying to reach other users through familiar Microsoft 365 workflows rather than through obvious external spam infrastructure.
That pattern is consistent with techniques seen in account abuse cases such as GitLocker GitHub extortion campaign and MailChimp Breach, where trusted accounts and platforms were used to extend the attacker’s reach.
Signals that the account is being used to spread the lure
One of the clearest signs is unexpected file sharing from a user who normally does not distribute external links or broad-access documents. Another is a link or folder that has been changed to public or anonymous access without a legitimate business reason. If a file suddenly becomes externally accessible, especially after a recent sign-in anomaly, that is a strong indicator the account is being used operationally, not just viewed.
Also look for malicious payloads hosted inside collaboration tools. Phishing attachments may be replaced with shared Office documents, compressed files, or links that redirect recipients to credential-harvesting pages. Follow-on messages sent to contacts, distribution lists, or external recipients are especially important because they show the attacker is moving from compromise to propagation.
For Microsoft 365 environments, compromise patterns can resemble the abuse paths described in ToolShell SharePoint exploitation 2025 and CoPhish OAuth Token Theft via Copilot Studio, where the platform or its trust relationships were used to sustain access and drive further abuse.
What the surrounding behavior usually tells defenders
SharePoint or OneDrive takeover rarely stays confined to one symptom. Teams often see abnormal mailbox activity, odd file edits, new sharing events, or messages sent shortly after the compromise. If the same account is generating both storage activity and outbound messages, treat it as a coordinated abuse path rather than isolated user error.
The strongest signal is the combination, not any single event. A legitimate user can share a file by mistake, but a legitimate user usually does not simultaneously create public links, deliver suspicious content, and generate follow-on phishing from the same account. When that cluster appears, the account should be treated as a delivery mechanism until proven otherwise.
account takeover campaigns often depend on trust reuse and privilege abuse, which is why account governance guidance in the Customer IAM (CIAM) Guide is useful for understanding how compromise can move from access to abuse, and why Meta AI Instagram Account Takeover is a reminder that overprivileged trusted workflows can be turned into attack infrastructure.
Risk and Threat Considerations
When SharePoint or OneDrive takeover is used for phishing, the risk is broader than a single stolen account. The attacker inherits internal trust, which can improve delivery success, bypass user suspicion, and give the campaign a foothold inside collaboration and messaging workflows that defenders may not inspect as aggressively as external email.
Failure mechanism: The attacker uses a compromised collaboration account to publish malicious links or files, then leverages trusted sender reputation and existing permissions to reach other users before the compromise is contained.
Impact: That can lead to credential theft, additional account compromise, wider internal spread, and faster campaign persistence because the malicious content appears to originate from a legitimate business source.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Phishing via takeover succeeds when sharing and access exceed need. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Unusual sharing and message patterns must be detectable in logs. | |
| Recommendation — Reduce sharing scope and revoke unnecessary access paths immediately. Review audit trails for new links, sharing changes, and outbound abuse. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account takeover abuse depends on weak account lifecycle and oversight. |
| Recommendation — Tighten account oversight and disable abused accounts fast. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | Account takeover is rooted in failed authentication protections. |
| Recommendation — Harden authentication paths and investigate compromised sessions. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The same abuse pattern applies when non-human accounts can publish or share broadly. |
| Recommendation — Limit non-human access so compromised identities cannot spread phishing. | ||
Practitioner Guidance
What to verify: Confirm whether the shared item, link setting, or outbound message was created by a normal user workflow or by an attacker after account compromise. The key question is whether the account is acting as an authenticated collaboration user or as a phishing relay.
Decision rule: If a SharePoint or OneDrive account is creating public links, sharing outside the normal recipient pattern, or sending follow-on lures, treat it as an incident response case immediately and contain the account before focusing on content cleanup.
Practitioner takeaway: In this scenario, the account is not just compromised, it is being operationalised. The most important judgement is to treat any mix of unusual sharing and outbound lure behavior as evidence of active campaign use, not a simple user mistake.
Related resources from NHI Mgmt Group
- What are the signs that a travel booking site may be part of a phishing or account takeover attempt?
- What are the signs that a GitHub account takeover is being used to erase or exfiltrate code?
- What are the signs that a collaboration app account takeover campaign is becoming a broader identity problem?
- What are the signs that a phishing attack is moving beyond email into account takeover or post-compromise activity?