Solutions
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M21.25 12C21.25 13.2426 20.2426 14.25 19 14.25C17.7574 14.25 16.75 13.2426 16.75 12C16.75 10.7574 17.7574 9.75 19 9.75C20.2426 9.75 21.25 10.7574 21.25 12Z" stroke="black" stroke-width="1.5"/><path d="M7.25 12C7.25 13.2426 6.24264 14.25 5 14.25C3.75736 14.25 2.75 13.2426 2.75 12C2.75 10.7574 3.75736 9.75 5 9.75C6.24264 9.75 7.25 10.7574 7.25 12Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 16.1143C15.4512 15.4931 16.827 15.8617 17.4482 16.9377C18.0694 18.0137 17.7008 19.3895 16.6248 20.0107C15.5488 20.6319 14.173 20.2633 13.5518 19.1873C12.9306 18.1113 13.2992 16.7355 14.3752 16.1143Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 3.98927C8.45117 3.36805 9.82701 3.73671 10.4482 4.81269C11.0694 5.88867 10.7008 7.26451 9.62481 7.88573C8.54883 8.50695 7.17298 8.13829 6.55177 7.06231C5.93055 5.98633 6.29921 4.61048 7.37519 3.98927Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 20.0107C6.29921 19.3895 5.93055 18.0137 6.55177 16.9377C7.17298 15.8617 8.54883 15.4931 9.62481 16.1143C10.7008 16.7355 11.0694 18.1113 10.4482 19.1873C9.82701 20.2633 8.45117 20.6319 7.37519 20.0107Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 7.88573C13.2992 7.26451 12.9306 5.88867 13.5518 4.81269C14.173 3.73671 15.5488 3.36805 16.6248 3.98927C17.7008 4.61048 18.0694 5.98633 17.4482 7.06231C16.827 8.13829 15.4512 8.50695 14.3752 7.88573Z" stroke="black" stroke-width="1.5"/> </svg>

Modern Work

Modern workplaces and collaboration.

Effective solutions
We solve the IT challenges that most hinder Swiss SMEs. From Modern Work and Cyber Security to Cloud Migration.
Discover all solutions
Services
Craftsmanship Excellence
We support you from strategy consulting to seamless 24/7 operations. Professional, proactive, and individually tailored to your infrastructure.
Compare Service Models
About
Our story
100 years of experience. Your partner for innovation since 1925.
Blog Artikel
01.06.2026
1 min read

Chain phishing via Microsoft 365 can be prevented

Hands typing on a laptop with floating email icons, one flagged red with a warning.

Das Wichtigste in Kürze

  • Attackers hijack Microsoft 365 accounts with fake sign-in pages and send phishing emails with OneDrive or SharePoint links to the entire contact list, often including forwarding rules in the hacked account
  • Protection: passkeys, a cloud security assessment, critical scrutiny of every email and immediate notification of the IT department

With this method, fake emails from already compromised accounts are sent to the victim's entire contact list. This approach exploits the snowball effect and is reminiscent of an escalating chain reaction («chain»).

The perfidious part: the recipients know the sender and therefore often react incorrectly by disclosing their access credentials. Because of the network effect, a single successful attack has far-reaching consequences.

Perfidious chain attacks

The Federal Office for Cybersecurity (BACS) has investigated such attacks: the attackers use fake Microsoft 365 sign-in pages to steal access credentials. The emails sent ask recipients to update their account information. The message contains a supposed OneDrive or SharePoint link. Unknowingly, the recipient enters their credentials in order to open the supposed document. A single account cracked in this way is enough to attack the entire company and its suppliers. In this way they can gain access to confidential documents. Data leaks damage the company's reputation and lead to financial consequences.

To take the whole thing to extremes, according to the BACS the attackers often create forwarding rules in the hacked account that forward incoming emails to the cybercriminals.

How to communicate securely

Baggenstos and the BACS recommend the following measures:

  • Use passkeys. Learn more in our explainer video.
  • A cloud security assessment reveals the vulnerabilities and offers solutions.
  • If employees receive emails supposedly from you, your account has been hacked.
  • For emails from colleagues in the Microsoft 365 environment, the usual rules apply: check the email sender, check the links contained, never open forms via a link embedded in the email and, in general, scrutinise unexpected emails very carefully – with a query to the colleague via another channel.
  • After receiving a suspicious email, be sure to inform the IT department.
  • According to Art. 24 revFADP, data security breaches with a high risk for the persons concerned must be reported to the FDPIC. This applies to private individuals, companies and federal bodies. The report must be made without delay: https://databreach.edoeb.admin.ch/report
No items found.

Share article

Zwei Mitarbeiter im Gespräch am Tisch, einer lächelt im Vordergrund
Schedule an appointment now

Ready for your digital transformation?

In a no-obligation discussion, we'll jointly clarify where your IT can have the greatest impact and how we can support you.