Top
MAMBO ExplainsExplainers

Phishing is learning to look legitimate because attackers are using trusted cloud platforms as infrastructure

Netskope says GitHub and Microsoft OneDrive each affected 10% of European organisations through cloud malware distribution. Trusted SaaS is becoming attacker infrastructure.

trusted cloud abuse shown as an original tecMAMBO analysis graphic linking familiar platform with security gateway.
Kaspersky Lab

The old phishing lesson was easy to teach.

Do not trust strange websites.

Check the domain.

Avoid suspicious downloads.

That advice is becoming less sufficient.

Netskope's 2026 Europe Threat Labs report says attackers are increasingly abusing trusted cloud platforms to distribute malicious content.

GitHub and Microsoft OneDrive were the most abused platforms for distribution in the dataset, each affecting 10% of organisations.

CERT-EU has separately highlighted credential-phishing activity targeting Microsoft 365 users across European countries through convincing sign-in lures delivered with trusted infrastructure.

The pattern is important.

Attackers are borrowing the reputation of the software companies employees already use.

Why trusted platforms are attractive to attackers

Security teams are good at blocking obviously suspicious infrastructure.

A newly registered domain with a strange name can trigger filters.

GitHub and OneDrive are different.

Companies use them legitimately every day.

Blocking the entire service can disrupt work.

That gives attackers cover.

A malicious file or link can sit inside a domain that already has a good reputation.

The network sees familiar infrastructure.

The user sees a familiar brand.

Trust becomes part of the attack surface.

This does not mean GitHub or OneDrive are unsafe products

The distinction matters.

Cloud platforms actively detect and remove malicious content.

The problem is scale and timing.

A service used by millions of legitimate people can still be abused for a short period before a malicious file is detected.

Attackers only need that window to reach victims.

The correct security lesson is not:

"Do not use OneDrive."

It is:

"A trusted domain does not make every file on that domain trustworthy."

Microsoft 365 phishing exploits familiarity

Credential theft becomes easier when the login page resembles something an employee sees every morning.

Microsoft 365 is a natural target because it is deeply embedded in enterprise work.

A stolen account can provide access to email, files, contacts and internal conversations.

That can make one compromised identity more valuable than infecting one laptop.

Modern attackers therefore focus heavily on identity.

The goal is often to become the user rather than simply compromise the device.

SaaS has blurred the old network boundary

Traditional security assumed the corporate network was a meaningful perimeter.

Work now happens across:

  • Video meetings
  • Web applications
  • AI tools
  • Personal devices
  • Remote connections

The employee can be on a company laptop while interacting with dozens of services the company does not own.

That makes traffic classification harder.

A request to Microsoft can be legitimate work, a phishing page, a malicious file or an attacker-controlled account.

Security needs more context than the domain name.

AI adoption adds another data problem

Netskope says AI usage is now close to universal across the European organisations in its dataset.

The report also shows data-policy violations involving regulated data, source code, intellectual property, passwords and keys.

That creates two overlapping risks.

Attackers abuse trusted services to enter the organisation.

Employees can accidentally send sensitive information into trusted services the organisation does not control fully.

Both problems are about the same thing: trust needs to be granular.

A well-known app can still contain an unsafe action.

What organisations should change

The defensive response should focus on behaviour and content rather than banning the internet.

Useful controls include:

  • Inspecting downloads from cloud services where lawful and appropriate
  • Applying data-loss prevention controls
  • Separating managed business accounts from personal accounts
  • Using -resistant multi-factor authentication
  • Monitoring unusual account activity
  • Training employees to verify unexpected login prompts
  • Limiting unnecessary OAuth permissions
  • Maintaining fast incident response for compromised accounts

The goal is not to make employees suspicious of every legitimate service.

It is to stop brand familiarity from becoming proof of safety.

Why phishing-resistant matters

Passwords are easy to steal because they can be typed into the wrong page.

Some one-time codes can also be relayed through convincing phishing workflows.

Hardware-backed passkeys and other phishing-resistant authentication methods can reduce that risk because the credential is tied to the legitimate service.

No control is perfect.

Identity protection becomes much stronger when a fake page cannot simply collect a reusable secret.

The tecMAMBO take

Enterprise security spent years teaching people to look for strange domains.

Attackers adapted by moving onto normal ones.

That does not make trusted SaaS a mistake.

It means reputation has become only one signal.

The modern security question is not just, "Do we trust Microsoft, GitHub or Zoom?"

It is, "Do we trust this specific file, login request, account and action happening inside the service right now?"

That is a harder problem.

It is also a more realistic description of how work now happens.

Sources

Ask MAMBO

Have a plain-English question about this topic? Send it in and we may answer it in a future guide.

Ask a question