A Technique Designed to Bypass Security Filters
Email security filters are good at blocking known malicious files. Cyber criminals have responded by sending deliberately corrupted files instead. A corrupted Word document arrives in your inbox, and when you open it, Microsoft Word automatically attempts a repair. The document then appears entirely normal, with nothing to suggest anything is wrong.
Inside the repaired document is a malicious QR code or link leading to a fake Microsoft 365 login page. Enter your credentials there and the attacker has everything they need to access your account, your files, and potentially your entire business network.
Why It Is Effective
The technique works because the file arrives in a corrupted state that security scanners struggle to analyse. By the time Word has repaired it and the content is visible, the security check has already passed. The login page the link leads to is a convincing replica of a genuine Microsoft page, with no obvious signs of fraud.
Attackers only need one employee to enter their details. A single compromised account gives access to cloud systems, email contacts, shared files, and potentially the ability to send further phishing messages to colleagues and clients from a trusted address.
How to Protect Your Business
Pause before opening unexpected attachments
Urgency is a core part of these attacks. Emails requesting immediate action, claiming a payment is due, or suggesting a document needs urgent review are designed to bypass careful thinking. Taking a moment to question whether you were expecting this document, and from this sender, is enough to catch many attacks.
Verify through a different channel
If an email looks suspicious, contact the sender directly by phone or a separate message to confirm they sent it. Do not reply to the original email, as the sender address may be spoofed. This is particularly important for any email requesting login credentials or containing a QR code.
Enable multi-factor authentication
Even if an employee’s credentials are stolen via a phishing page, MFA prevents the attacker from using them to log in without the second factor. It does not stop the credentials being taken, but it does stop them being used.
Train your team on current techniques
Most staff will not have encountered this specific attack before. Sharing awareness of how corrupted attachment phishing works, and what to look for, gives your team the context to treat unexpected Word documents with appropriate caution.
Support Across the North West
Blowfish Technology provides email security, MFA deployment, and cyber awareness training across the North West, including IT Support Manchester, IT Support Liverpool, IT Support Chester, IT Support Ormskirk, IT Support Southport, and IT Support Preston.
The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.