Forum Discussion
Is Exchange Online Threatened by Ransomware?
Akshay_Mane Given that I have been writing about Office 365 since 2011, and Exchange since 1996, I think I know where the Exchange Online servers are located.
Remember that ransomware can be delivered by email. As we have already established, some malware gets through anti-malware defenses and will arrive in user mailboxes. Depending on the attack vector, all it might take is for a user to open a message and click a suspect link to cause their complete mailbox to be infected by ransomware (the proof of concept offered in the Mitnick demo). MFA doesn't come into the equation if a user is lured into granting an app permissions over their mailbox.
The possibility of a successful ransomware attack on Exchange Online exists. I personally feel that attackers will choose easier targets, but that doesn't mean that we should be complacent and rely on anti-malware tools to protect mailboxes from infection.