Your Office Printer Might Be Sending Phishing Emails Right Now
Microsoft warns that attackers are hijacking the same Direct Send feature your printer uses for scan-to-email. Here's how to check if your business is exposed and what to do about it.
If your office printer can scan documents and email them to your team, congratulations — you have a feature that hackers are actively exploiting to phish your employees.
In January 2026, Microsoft published a major security alert revealing that phishing actors are exploiting Microsoft 365's Direct Send feature — the exact same email pathway your multifunction printer uses to send scanned documents — to deliver phishing emails that appear to come from inside your own organization.
How Direct Send Becomes a Phishing Weapon
Here's the short version: when you set up scan-to-email on your office printer, most IT guides tell you to configure Direct Send through Microsoft 365. It's convenient because the printer doesn't need a mailbox license — it just sends through your organization's mail server.
The problem? Attackers discovered they can abuse this same pathway from outside your network. Without proper email authentication configured, they can send emails that:
- Appear to come from your own domain (e.g., [email protected])
- Bypass basic spam filters because they look internal
- Carry QR codes or HTML attachments designed to steal credentials
Microsoft blocked over 13 million malicious emails linked to the Tycoon2FA phishing platform in October 2025 alone — many exploiting exactly this vulnerability.
Who's at Risk?
Your business is vulnerable if:
- Your MX records don't point directly to Microsoft 365
- You haven't enforced strict spoof protection policies
- You haven't implemented DMARC, SPF, and DKIM properly
- Your printers use Direct Send without restrictions
If you're not sure whether your email authentication is configured correctly, that's exactly the kind of thing the team at StopSpoofingMe.com helps businesses figure out. They specialize in email spoofing protection and can audit your DMARC/SPF/DKIM setup.
What to Do Right Now
1. Enable "Reject Direct Send" in Microsoft 365
Microsoft introduced this feature in April 2025, but it's off by default. Go to Exchange Admin Center → Mail flow → Connectors and configure inbound connector restrictions to reject unauthenticated Direct Send traffic from external sources.
2. Audit Your Email Authentication
Make sure you have all three configured: - SPF (Sender Policy Framework) — specifies which servers can send email for your domain - DKIM (DomainKeys Identified Mail) — cryptographically signs your outgoing email - DMARC (Domain-based Message Authentication) — tells receiving servers what to do with emails that fail SPF/DKIM
3. Restrict Your Printer's Send Permissions
Configure your multifunction printer to only send to specific internal addresses, or set up a dedicated service account with limited permissions rather than using Direct Send.
4. Train Your Team
Employees need to know that just because an email appears to come from an internal address doesn't mean it's legitimate. Phishing emails exploiting Direct Send are particularly convincing because they pass the basic "does the sender look right?" test.
The Bigger Picture
This isn't just about one vulnerability — it's about understanding that your printer is a network-connected computer that handles email, stores documents, and connects to cloud services. Every feature it has is a potential attack surface.
67% of organizations experienced a printer-related security incident in 2024, according to Quocirca's Print Security Report. That number is almost certainly higher now.
---
Worried about your printer's email configuration? Valley Printer Pros can audit your multifunction printer setup and ensure scan-to-email is configured securely. We also partner with StopSpoofingMe.com for comprehensive email authentication audits.
Call us at (818) 574-8240 for a free 15-minute consultation.
---
Sources: Microsoft Security Blog (January 2026), Proofpoint Threat Research, BleepingComputer, Quocirca Print Security Landscape Report 2024
About Valley Printer Pros Team
Our team of printer industry experts brings decades of experience helping small businesses optimize their printing operations. We provide unbiased advice and practical solutions that save money and improve productivity.
Get Expert AdviceServing San Fernando Valley Businesses
We provide on-site printer consulting, setup, and lease escape support across the Valley:
Related Articles
On September 17, HP Wolf Security reported phishing emails with PDF "invoices" blurred behind a QR code that tells staff to scan it with their phone, leading to a fake Microsoft sign-in page. Tell accounts-payable staff never to scan QR codes in unexpected invoices, verify invoices by phone, and protect Microsoft 365 with MFA.
Microsoft's September 8, 2026 Patch Tuesday fixed a Critical (CVSS 9.8) Windows HTTP Print Provider flaw, CVE-2026-69769, that needs no sign-in or click, plus Print Spooler privilege bugs. None were exploited, and the month's zero-days weren't print-related. Test the September cumulative update on one PC, then install it everywhere.
On August 27, PaperCut warned that attackers were exploiting flaws in its NG and MF print-management software, and on August 31 CISA listed both chained bugs as actively exploited. Ask your copier dealer whether you run PaperCut, restrict its admin page to trusted addresses, patch versions 24 to 26, and upgrade anything older.
Need Help with Your Printer Decisions?
Don't navigate printer purchases, leases, or problems alone. Our experts provide unbiased advice tailored to your specific business needs.