Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What are the signs that SharePoint or OneDrive…
Threats, Abuse & Incident Response

What are the signs that SharePoint or OneDrive account takeover is being used as part of a phishing campaign?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Threats, Abuse & Incident Response

Common signs include unexpected file sharing from a user account, links changed to public access, malicious files hosted in collaboration tools, and follow-on phishing sent to contacts or external recipients. Suspicious activity can also appear as unusual mailbox or file behavior after the initial compromise. When these signals show up together, teams should assume the account is being used as a delivery point for further attacks.

How SharePoint or OneDrive takeover becomes a phishing delivery path

Once an attacker controls a user’s SharePoint or OneDrive account, they can use the tenant’s own trust to distribute malicious content. That often looks less like a loud takeover and more like normal collaboration activity with a malicious purpose. Watch for sharing links, file replacements, or new content that appears to come from a trusted internal account but behaves like a lure.

The important distinction is that the compromise is not only about data access. In a phishing campaign, the account becomes a staging point for delivery, which means the attacker is trying to reach other users through familiar Microsoft 365 workflows rather than through obvious external spam infrastructure.

That pattern is consistent with techniques seen in account abuse cases such as GitLocker GitHub extortion campaign and MailChimp Breach, where trusted accounts and platforms were used to extend the attacker’s reach.

Signals that the account is being used to spread the lure

One of the clearest signs is unexpected file sharing from a user who normally does not distribute external links or broad-access documents. Another is a link or folder that has been changed to public or anonymous access without a legitimate business reason. If a file suddenly becomes externally accessible, especially after a recent sign-in anomaly, that is a strong indicator the account is being used operationally, not just viewed.

Also look for malicious payloads hosted inside collaboration tools. Phishing attachments may be replaced with shared Office documents, compressed files, or links that redirect recipients to credential-harvesting pages. Follow-on messages sent to contacts, distribution lists, or external recipients are especially important because they show the attacker is moving from compromise to propagation.

For Microsoft 365 environments, compromise patterns can resemble the abuse paths described in ToolShell SharePoint exploitation 2025 and CoPhish OAuth Token Theft via Copilot Studio, where the platform or its trust relationships were used to sustain access and drive further abuse.

What the surrounding behavior usually tells defenders

SharePoint or OneDrive takeover rarely stays confined to one symptom. Teams often see abnormal mailbox activity, odd file edits, new sharing events, or messages sent shortly after the compromise. If the same account is generating both storage activity and outbound messages, treat it as a coordinated abuse path rather than isolated user error.

The strongest signal is the combination, not any single event. A legitimate user can share a file by mistake, but a legitimate user usually does not simultaneously create public links, deliver suspicious content, and generate follow-on phishing from the same account. When that cluster appears, the account should be treated as a delivery mechanism until proven otherwise.

account takeover campaigns often depend on trust reuse and privilege abuse, which is why account governance guidance in the Customer IAM (CIAM) Guide is useful for understanding how compromise can move from access to abuse, and why Meta AI Instagram Account Takeover is a reminder that overprivileged trusted workflows can be turned into attack infrastructure.

Risk and Threat Considerations

When SharePoint or OneDrive takeover is used for phishing, the risk is broader than a single stolen account. The attacker inherits internal trust, which can improve delivery success, bypass user suspicion, and give the campaign a foothold inside collaboration and messaging workflows that defenders may not inspect as aggressively as external email.

Failure mechanism: The attacker uses a compromised collaboration account to publish malicious links or files, then leverages trusted sender reputation and existing permissions to reach other users before the compromise is contained.

Impact: That can lead to credential theft, additional account compromise, wider internal spread, and faster campaign persistence because the malicious content appears to originate from a legitimate business source.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP API Security Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegePhishing via takeover succeeds when sharing and access exceed need.
AU-6 — Audit Record Review, Analysis, and ReportingUnusual sharing and message patterns must be detectable in logs.
Recommendation — Reduce sharing scope and revoke unnecessary access paths immediately. Review audit trails for new links, sharing changes, and outbound abuse.
CIS Controls v8CIS-5 — Account ManagementAccount takeover abuse depends on weak account lifecycle and oversight.
Recommendation — Tighten account oversight and disable abused accounts fast.
OWASP API Security Top 10API2 — Broken AuthenticationAccount takeover is rooted in failed authentication protections.
Recommendation — Harden authentication paths and investigate compromised sessions.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe same abuse pattern applies when non-human accounts can publish or share broadly.
Recommendation — Limit non-human access so compromised identities cannot spread phishing.

Practitioner Guidance

What to verify: Confirm whether the shared item, link setting, or outbound message was created by a normal user workflow or by an attacker after account compromise. The key question is whether the account is acting as an authenticated collaboration user or as a phishing relay.

Decision rule: If a SharePoint or OneDrive account is creating public links, sharing outside the normal recipient pattern, or sending follow-on lures, treat it as an incident response case immediately and contain the account before focusing on content cleanup.

Practitioner takeaway: In this scenario, the account is not just compromised, it is being operationalised. The most important judgement is to treat any mix of unusual sharing and outbound lure behavior as evidence of active campaign use, not a simple user mistake.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org