Cybersecurity Threat TCO Raises Alarm with TwinLoot Attacks on SharePoint and Teams
A sophisticated attack campaign, code-named “TwinLoot,” has been spotted targeting organizations that use Microsoft’s collaboration platforms, SharePoint and Teams. The attackers have been leveraging a combination of clever tactics to steal sensitive credentials and move laterally across networks, leaving victims scrambling to contain the damage.
At its core, TwinLoot exploits vulnerabilities in the way SharePoint and Teams handle permissions and authentication. Attackers are taking advantage of misconfigured access controls to gain elevated privileges on compromised systems. Once inside, they use these elevated permissions to pivot across domains, effectively creating a path for further lateral movement.
The affected organizations have been using standard protocols for sharing files and collaborating with colleagues through SharePoint and Teams. However, the attackers have managed to subvert these secure workflows by injecting malicious code that allows them to bypass traditional security measures. This enables them to steal credentials from users who have access to sensitive information, often unwittingly providing the necessary permissions.
Experts warn that this attack campaign’s sophistication is a reflection of the increasing complexity of modern networks and collaboration platforms. As more organizations adopt cloud-based services like SharePoint and Teams, the potential for attacks exploiting vulnerabilities in these tools grows exponentially. The fact that TwinLoot has been able to evade traditional security measures highlights the need for enhanced monitoring and response capabilities.
Moreover, this attack campaign’s use of privilege escalation techniques underscores the critical importance of proper identity management and access controls. Organizations that have not implemented robust multi-factor authentication (MFA) or regular security audits are particularly vulnerable to these types of attacks.
As the cybersecurity landscape continues to evolve, it’s essential for organizations to prioritize proactive threat detection and response strategies. This includes implementing regular security updates, enhancing user education, and maintaining strong incident response plans. By doing so, businesses can mitigate the risk of similar attacks and protect sensitive information from unauthorized access.
Source: The Hacker News — 2026-08-18