Serious security oversight at Microsoft

Vaisha Bernard, chief hacker at Eye Security, saves thousands of companies from risk of cyber attack

Microsoft’s “Attack Simulation Training” software, designed to educate company employees on phishing attacks, suffered from serious security oversights. Originally intended as a training ground for employees to recognise and respond to potential threats, the program harboured a critical security error, posing a significant risk to millions of unsuspecting Microsoft users to be taken advantage of by cybercriminals. 

These serious security errors were brought to light by Vaisha Bernard, Chief Hacker at the European cybersecurity and insurance firm Eye Security, who played a pivotal role in assisting Microsoft in rectifying the vulnerability. Initially considering “Attack Simulation Training” for Eye Security’s customer portfolio, Bernard was testing the program when he uncovered a security gap through a phishing email template within the system. 

A link in the template directed him to a ‘non-existing’ confluence page. He promptly registered the page in his name, triggering requests from users around the world to access the page. It was at this point that Bernard identified two major issues: not only did the templates contain links to unregistered pages and domains, but the email addresses used by Microsoft for sending out phishing simulations were also linked to unregistered domains. 

This meant that anyone could easily register them for a mere $10 each. Bernard registered some domains and started receiving responses to the phishing simulations from employees in companies worldwide. Alongside those who recognised it as a scam, many requested a resend of the simulated malware in PDF format. 

“Of course, I immediately alerted Microsoft, and together we have since resolved the issue. However, had a cybercriminal beaten me to it, thousands of unsuspecting employees from companies worldwide – Microsoft customers and users – would have clicked on suspicious links and fallen victim to phishing attacks. Ironically, Microsoft’s attack simulation program would have transformed into a genuine phishing attack program, bypassing all protective mechanisms,” warned Bernard. 

Bernard continues, “On a broader point, it goes to show preventative measures – such as awareness training, end point and cloud monitoring – are only the first line of defence. You need to assume that you will be breached so be ready to respond quickly.” 

Blog Categories

Threats and Vulnerabilities

Recent Blogs

Cyber Insurance Renewal Checklist for 2027 

  A lot can change in 12-months. Your business may have added new systems, suppliers, or employees. The amount of data you hold may have increased. Your security controls may have changed. And your current insurance policy may no longer offer the protection you think it does. 

2027 Cybersecurity priorities: are you spending in the right places? 

Cyber budgets have climbed every year for a decade. Attacks keep succeeding anyway. This gap tells us that the size of the budget was rarely the issue. September is when European leadership teams set the budget allocation for 2027. Every department competes for the same investment, and cybersecurity has to earn its place alongside the […]

How to Secure Microsoft 365 Against Modern Cyber Attacks

If a threat actor logged into one of your employees’ Microsoft 365 accounts right now, how long would it take you to notice?