{"id":1474,"date":"2026-01-27T11:29:20","date_gmt":"2026-01-27T10:29:20","guid":{"rendered":"https:\/\/gfdde.de\/?p=1474"},"modified":"2026-04-30T15:52:34","modified_gmt":"2026-04-30T13:52:34","slug":"phishing-ueber-echte-microsoft-adresse-power-bi-missbrauch-und-dsgvo-pflichten-fuer-unternehmen","status":"publish","type":"post","link":"https:\/\/gfdde.de\/en\/phishing-ueber-echte-microsoft-adresse-power-bi-missbrauch-und-dsgvo-pflichten-fuer-unternehmen\/","title":{"rendered":"Phishing via a legitimate Microsoft address: Power BI abuse and GDPR obligations for companies"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"1474\" class=\"elementor elementor-1474\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4125e5d8 e-con-full e-flex e-con e-parent\" data-id=\"4125e5d8\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-265da6d4 elementor-align-center elementor-widget elementor-widget-post-info\" data-id=\"265da6d4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"post-info.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-inline-items elementor-icon-list-items elementor-post-info\">\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-repeater-item-7f530f1 elementor-inline-item\" itemprop=\"datePublished\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text elementor-post-info__item elementor-post-info__item--type-date\">\n\t\t\t\t\t\t\t\t\t\t<time>27.01.2026<\/time>\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-1d5f678c e-con-full e-flex e-con e-child\" data-id=\"1d5f678c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-5bfde858 elementor-widget__width-initial elementor-widget-tablet__width-inherit elementor-widget elementor-widget-heading\" data-id=\"5bfde858\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Phishing via a legitimate Microsoft address: Power BI abuse and GDPR obligations for companies<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3a8004cd elementor-widget__width-initial elementor-widget-tablet__width-inherit elementor-widget elementor-widget-text-editor\" data-id=\"3a8004cd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\tSince January 2026, a sophisticated phishing campaign has been active in which attackers send deceptive emails using the legitimate Microsoft sender address no-reply-powerbi@microsoft.com\n. This is technically possible due to a legitimate feature of Microsoft Power BI: when creating a dashboard, any external email address can be added as a subscriber, and the content of the automatically sent notification can be freely configured. Since the emails are actually sent through Microsoft\u2019s infrastructure, these messages pass email authentication and security mechanisms without obstruction and are generally not detected by spam filters. For companies, this results in a multi-layered need for action: technical, organizational, and data protection-related.\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1b012ee8 elementor-widget__width-inherit elementor-invisible elementor-widget elementor-widget-image\" data-id=\"1b012ee8\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"800\" height=\"534\" src=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-1024x683.webp\" class=\"attachment-large size-large wp-image-1505\" alt=\"\" srcset=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-1024x683.webp 1024w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-300x200.webp 300w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-768x512.webp 768w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-1536x1024.webp 1536w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-2048x1365.webp 2048w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-18x12.webp 18w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-55c43b8 e-con-full e-flex e-con e-child\" data-id=\"55c43b8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-3739c4f e-con-full e-flex e-con e-child\" data-id=\"3739c4f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2d1f364 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"2d1f364\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>Background<\/h5>\nMicrosoft Power BI is a business intelligence and analytics platform that enables dashboard subscriptions for external recipients. When a user creates a Power BI dashboard and adds external email addresses as subscribers, Microsoft automatically sends a notification email from the address no-reply-powerbi@microsoft.com\n. The key point is that the creator of the dashboard can freely define the content of this notification.\n\nAttackers have been systematically exploiting this mechanism since at least early 2026. They create Power BI accounts, add target email addresses as subscribers, and design the notification text to include fake payment demands (typically between 400 and 700 US dollars) as well as fraudulent support phone numbers. Victims are instructed to call these numbers to stop an allegedly unauthorized transaction (voice phishing), while the actual fraud occurs during the phone call itself.\n\nFrom a security perspective, this is particularly relevant: the emails show no signs of a spoofed sender address. Authentication and security mechanisms such as SPF, DKIM, and DMARC checks pass successfully, as the messages are genuinely sent from Microsoft servers. Microsoft itself recommends in its official documentation that the address no-reply-powerbi@microsoft.com\n be whitelisted in spam filters so that legitimate Power BI notifications are not blocked. This institutional trust is deliberately exploited in the attack. Only at the end of the email is there a small notice indicating that the message originates from a Power BI subscription notification, which is easy to overlook.\n\nThis attack pattern is not entirely new: security researchers have previously documented the misuse of Power BI for phishing links, as well as similar attacks involving Google Cloud services. However, the current wave represents an escalation in sophistication, as no separate phishing links are required anymore\u2014links that could otherwise be detected by filtering systems.\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cc37044 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"cc37044\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>Legal and Data Protection Assessment<\/h5>\n<h6>Technical and organizational measures<\/h6>\nArticle 32 GDPR requires controllers to ensure a level of security appropriate to the risk. In the context of this wave of attacks, companies using Microsoft 365 and Power BI are faced with two concrete questions: first, whether the configuration of Power BI\u2014particularly regarding permissions for creating external subscriptions\u2014is appropriately documented and restricted as a technical and organizational measure (TOM). Second, whether the use of a service provider (Microsoft), whose platform is structurally susceptible to social engineering attacks or is being actively exploited in this way, is compatible with the company\u2019s own risk assessments.\n<h6>Notification Obligations in Case of Data Breaches<\/h6>\nIf employees or customers of an organization fall victim to this phishing campaign and disclose personal data (such as login credentials or payment information), it must be assessed whether this constitutes a notifiable personal data breach under Article 33 GDPR. The 72-hour notification period to the competent supervisory authority begins as soon as the controller becomes aware of the breach.\n<h6>Integrity and Confidentiality<\/h6>\nThe principle of integrity and confidentiality under Article 5(1)(f) GDPR requires that personal data be protected against unauthorized processing. If employees are tricked by this attack vector into disclosing credentials or payment information, the confidentiality of affected data sets is compromised. Organizations that have not implemented sufficient protective and awareness-raising measures risk being unable to demonstrate adequate compliance with this principle in the event of damage.\n<h6>Processor Relationships and Third-Party Risk<\/h6>\nOrganizations using Microsoft 365 under a data processing agreement (DPA) must be aware that the described abuse does not constitute a data breach on Microsoft\u2019s side, but rather an exploitation of a legitimate platform feature. Nevertheless, it should be carefully assessed whether the use of Power BI in its current default configuration is compatible with internal IT security policies.\n\nSince the emails originate from Microsoft\u2019s legitimate infrastructure and pass all cryptographic verification checks, gateway solutions, spam filters, and reputation-based systems are structurally ineffective. Even advanced threat protection solutions such as Microsoft Defender did not initially flag these messages.\n\nThe attack is technically easy to execute but difficult for recipients to recognize without prior awareness. Employees without strong IT expertise and individuals unfamiliar with Power BI notifications are particularly at risk.\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f5f439e elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"f5f439e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>Risks<\/h5>\n<h6>Risk of data protection breaches:<\/h6>\nSuccessful attacks may lead to the disclosure of access credentials, payment information, or the compromise of end devices through remote access tools \u2013 resulting in immediate GDPR notification obligations.\n<h6>Reputational risk for companies:<\/h6>\nIf customers, suppliers, or business partners are entered as subscribers in an attacker-controlled dashboard using a company\u2019s email address, they may mistakenly attribute the attack to the affected company.\n<h6>Power BI configuration risk:<\/h6>\nCompanies using Power BI that grant employees permission to create external subscriptions potentially expose their own platform usage to misuse by third parties.\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-571f177 e-con-full e-flex e-con e-child\" data-id=\"571f177\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3e38358 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"3e38358\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>Recommendations for Action<\/h5>\n<h6>Short-term: Information and employee awareness<\/h6>\n<ul>\n \t<li>Immediate communication to all employees regarding the attack vector \u2013 including specific indicators: unexpected Power BI subscription notifications, payment requests via email, and prompts to call a phone number.<\/li>\n \t<li>Internal reporting procedures must be clearly communicated: employees must know where and how to report suspicious emails.<\/li>\n \t<li>Internal reporting procedures must be clearly communicated: employees must know where and how to report suspicious emails.<\/li>\n<\/ul>\n<h6>Medium-term: Implement technical and organizational measures<\/h6>\n<ul>\n \t<li>Review Power BI tenant configuration: In the Microsoft 365 Admin Center, it is possible to control who is allowed to subscribe external recipients to Power BI reports. Restrictive configurations reduce the potential for misuse by third parties.<\/li>\n \t<li>Set up email rules for no-reply-powerbi@microsoft.com: Organizations that do not actively use Power BI can route incoming emails from this address directly to quarantine or automatically warn recipients.<\/li>\n \t<li>Incident response process for social engineering attacks: Ensure that your incident management also covers vishing attacks, including the assessment of whether a personal data breach under Article 33 GDPR has occurred.<\/li>\n \t<li>Include in Data Protection Impact Assessment (DPIA): If Power BI is used to process personal data, the current abuse vector must be documented and evaluated within the risk analysis.<\/li>\n<\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5c48eb0 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"5c48eb0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>Need for consulting?<\/h5>\nGfDDE \u2013 Gesellschaft f\u00fcr Datenschutz und Datensicherheit \u2013 in Europa GmbH supports you in assessing phishing incidents in the GDPR context, configuring cloud services in accordance with Article 32 GDPR, and developing GDPR-compliant incident response processes.\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-620ad85 elementor-align-center elementor-mobile-align-center elementor-tablet-align-center elementor-widget__width-inherit elementor-invisible elementor-widget elementor-widget-button\" data-id=\"620ad85\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeInUp&quot;}\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm elementor-animation-grow\" href=\"https:\/\/gfdde.de\/en\/?preview_id=57&#038;preview_nonce=5ba13b97f0&#038;preview=true#Kontakt\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Get in Touch now<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d3be417 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"d3be417\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>Sources<\/h5>\n<p>Ars Technica (January 2026): There\u2019s a rash of scam spam coming from a real Microsoft address<\/p>\n<p>t3n (January 2026): Echte Microsoft-Mailadresse verschickt Spam<\/p>\n<p>PCWorld (January 2026): Beware! That Microsoft email is genuine, but it\u2019s also a scam<\/p>\n<p>ProArch (February 2026): Power BI Notifications Used for Phishing: Risks and User Awareness<\/p>\n<p>Jennifer Stirrup \/ BI Expert Blog (February 2026): When Trusted Domains Betray Trust: Power BI Scam-Spam and Proactive BI Governance<\/p>\n<p>Cofense Phishing Defense Center: When Data Tools Become Dangerous: MS Power BI Links Used in Phishing Campaigns<\/p>\n<p>Microsoft Q&amp;A (Community-Dokumentation des Vorfalls): Payment Successfuly processed Mail from no-reply-powerbi@microsoft.com<\/p>\n<p>GDPR (Regulation (EU) 2016\/679), Articles 5(1)(f), 32, 33, 34<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-39c473da e-con-full e-flex e-con e-parent\" data-id=\"39c473da\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6bfd0417 elementor-widget elementor-widget-heading\" data-id=\"6bfd0417\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">More news<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4b3adda8 elementor-posts__hover-none elementor-grid-3 elementor-grid-tablet-2 elementor-grid-mobile-1 elementor-posts--thumbnail-top elementor-widget elementor-widget-posts\" data-id=\"4b3adda8\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;cards_row_gap&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:80,&quot;sizes&quot;:[]},&quot;cards_row_gap_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:71,&quot;sizes&quot;:[]},&quot;cards_row_gap_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:30,&quot;sizes&quot;:[]},&quot;cards_columns&quot;:&quot;3&quot;,&quot;cards_columns_tablet&quot;:&quot;2&quot;,&quot;cards_columns_mobile&quot;:&quot;1&quot;}\" data-widget_type=\"posts.cards\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-posts-container elementor-posts elementor-posts--skin-cards elementor-grid\" role=\"list\">\n\t\t\t\t<article class=\"elementor-post elementor-grid-item post-1580 post type-post status-publish format-standard has-post-thumbnail hentry category-allgemein\" role=\"listitem\">\n\t\t\t<div class=\"elementor-post__card\">\n\t\t\t\t<a class=\"elementor-post__thumbnail__link\" href=\"https:\/\/gfdde.de\/en\/us-supreme-court-kippt-ftc-unabhaengigkeit\/\" tabindex=\"-1\" target=\"_blank\"><div class=\"elementor-post__thumbnail\"><img decoding=\"async\" width=\"2000\" height=\"1334\" src=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/07\/tim-mossholder-3Xl3lI5gjqg-unsplash_bearb.webp\" class=\"attachment-full size-full wp-image-1579\" alt=\"\" srcset=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/07\/tim-mossholder-3Xl3lI5gjqg-unsplash_bearb.webp 2000w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/07\/tim-mossholder-3Xl3lI5gjqg-unsplash_bearb-300x200.webp 300w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/07\/tim-mossholder-3Xl3lI5gjqg-unsplash_bearb-1024x683.webp 1024w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/07\/tim-mossholder-3Xl3lI5gjqg-unsplash_bearb-768x512.webp 768w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/07\/tim-mossholder-3Xl3lI5gjqg-unsplash_bearb-1536x1025.webp 1536w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/07\/tim-mossholder-3Xl3lI5gjqg-unsplash_bearb-18x12.webp 18w\" sizes=\"(max-width: 2000px) 100vw, 2000px\" \/><\/div><\/a>\n\t\t\t\t<div class=\"elementor-post__text\">\n\t\t\t\t<h4 class=\"elementor-post__title\">\n\t\t\t<a href=\"https:\/\/gfdde.de\/en\/us-supreme-court-kippt-ftc-unabhaengigkeit\/\" target=\"&quot;_blank&quot;\">\n\t\t\t\tUS Supreme Court kippt FTC-Unabh\u00e4ngigkeit: Rechtsgrundlage des EU-US Data Privacy Framework weiter ersch\u00fcttert\t\t\t<\/a>\n\t\t<\/h4>\n\t\t\t\t<div class=\"elementor-post__excerpt\">\n\t\t\t<p>US Supreme Court kippt FTC-Unabh\u00e4ngigkeit: Rechtsgrundlage des EU-US Data Privacy Framework weiter ersch\u00fcttert Der US Supreme Court hat am 29. Juni 2026 im Verfahren Trump v. Slaughter mit 6:3-Mehrheit entschieden, dass die gesetzlichen Abberufungsschutzregelungen f\u00fcr<\/p>\n\t\t<\/div>\n\t\t\n\t\t<a class=\"elementor-post__read-more\" href=\"https:\/\/gfdde.de\/en\/us-supreme-court-kippt-ftc-unabhaengigkeit\/\" aria-label=\"Read more about US Supreme Court kippt FTC-Unabh\u00e4ngigkeit: Rechtsgrundlage des EU-US Data Privacy Framework weiter ersch\u00fcttert\" tabindex=\"-1\" target=\"_blank\">\n\t\t\tRead more\u2026\t\t<\/a>\n\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/article>\n\t\t\t\t<article class=\"elementor-post elementor-grid-item post-1496 post type-post status-publish format-standard has-post-thumbnail hentry category-allgemein\" role=\"listitem\">\n\t\t\t<div class=\"elementor-post__card\">\n\t\t\t\t<a class=\"elementor-post__thumbnail__link\" href=\"https:\/\/gfdde.de\/en\/cloud-act-fisa-und-co-wann-eu-rechenzentren-europaeischen-daten-keinen-schutz-bieten\/\" tabindex=\"-1\" target=\"_blank\"><div class=\"elementor-post__thumbnail\"><img decoding=\"async\" width=\"2560\" height=\"1696\" src=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-scaled.webp\" class=\"attachment-full size-full wp-image-1506\" alt=\"\" srcset=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-scaled.webp 2560w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-300x199.webp 300w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-1024x678.webp 1024w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-768x509.webp 768w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-1536x1017.webp 1536w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-2048x1356.webp 2048w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/domaintechnik-ledl-net-VHmBX7FnXw0-unsplash_bearb-18x12.webp 18w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><\/div><\/a>\n\t\t\t\t<div class=\"elementor-post__text\">\n\t\t\t\t<h4 class=\"elementor-post__title\">\n\t\t\t<a href=\"https:\/\/gfdde.de\/en\/cloud-act-fisa-und-co-wann-eu-rechenzentren-europaeischen-daten-keinen-schutz-bieten\/\" target=\"&quot;_blank&quot;\">\n\t\t\t\tCLOUD Act, FISA and Co.: When EU Data Centers Fail to Protect European Data\t\t\t<\/a>\n\t\t<\/h4>\n\t\t\t\t<div class=\"elementor-post__excerpt\">\n\t\t\t<p>Storing corporate data in European data centers operated by U.S. providers does not rule out access by U.S. authorities. A legal opinion by the University of Cologne, commissioned by the German Federal Ministry of the Interior and published in December 2025, confirms that U.S. authorities have extensive access to cloud data stored in Europe.<\/p>\n\t\t<\/div>\n\t\t\n\t\t<a class=\"elementor-post__read-more\" href=\"https:\/\/gfdde.de\/en\/cloud-act-fisa-und-co-wann-eu-rechenzentren-europaeischen-daten-keinen-schutz-bieten\/\" aria-label=\"Read more about CLOUD Act, FISA und Co.: Wann EU-Rechenzentren europ\u00e4ischen Daten keinen Schutz bieten\" tabindex=\"-1\" target=\"_blank\">\n\t\t\tRead more\u2026\t\t<\/a>\n\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/article>\n\t\t\t\t<article class=\"elementor-post elementor-grid-item post-1474 post type-post status-publish format-standard has-post-thumbnail hentry category-allgemein\" role=\"listitem\">\n\t\t\t<div class=\"elementor-post__card\">\n\t\t\t\t<a class=\"elementor-post__thumbnail__link\" href=\"https:\/\/gfdde.de\/en\/phishing-ueber-echte-microsoft-adresse-power-bi-missbrauch-und-dsgvo-pflichten-fuer-unternehmen\/\" tabindex=\"-1\" target=\"_blank\"><div class=\"elementor-post__thumbnail\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1707\" src=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-scaled.webp\" class=\"attachment-full size-full wp-image-1505\" alt=\"\" srcset=\"https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-scaled.webp 2560w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-300x200.webp 300w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-1024x683.webp 1024w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-768x512.webp 768w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-1536x1024.webp 1536w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-2048x1365.webp 2048w, https:\/\/gfdde.de\/wp-content\/uploads\/2026\/04\/le-vu-vSlCNmZdjHQ-unsplash_bearb-18x12.webp 18w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><\/div><\/a>\n\t\t\t\t<div class=\"elementor-post__text\">\n\t\t\t\t<h4 class=\"elementor-post__title\">\n\t\t\t<a href=\"https:\/\/gfdde.de\/en\/phishing-ueber-echte-microsoft-adresse-power-bi-missbrauch-und-dsgvo-pflichten-fuer-unternehmen\/\" target=\"&quot;_blank&quot;\">\n\t\t\t\tPhishing via a legitimate Microsoft address: Power BI abuse and GDPR obligations for companies\t\t\t<\/a>\n\t\t<\/h4>\n\t\t\t\t<div class=\"elementor-post__excerpt\">\n\t\t\t<p>Since January 2026, a sophisticated phishing campaign has been active in which attackers send deceptive emails using the legitimate Microsoft sender address no-reply-powerbi@microsoft.com\n. This is technically possible due to a legitimate feature of Microsoft Power BI: when creating a dashboard, any external email address can be added as a subscriber, and the content of the automatically sent notification can be freely configured.<\/p>\n\t\t<\/div>\n\t\t\n\t\t<a class=\"elementor-post__read-more\" href=\"https:\/\/gfdde.de\/en\/phishing-ueber-echte-microsoft-adresse-power-bi-missbrauch-und-dsgvo-pflichten-fuer-unternehmen\/\" aria-label=\"Read more about Phishing \u00fcber echte Microsoft-Adresse: Power-BI-Missbrauch und DSGVO-Pflichten f\u00fcr Unternehmen\" tabindex=\"-1\" target=\"_blank\">\n\t\t\tRead more\u2026\t\t<\/a>\n\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/article>\n\t\t\t\t<\/div>\n\t\t\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Since January 2026, a sophisticated phishing campaign has been active in which attackers send deceptive emails using the legitimate Microsoft sender address no-reply-powerbi@microsoft.com\n. This is technically possible due to a legitimate feature of Microsoft Power BI: when creating a dashboard, any external email address can be added as a subscriber, and the content of the automatically sent notification can be freely configured.<\/p>","protected":false},"author":2,"featured_media":1505,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1474","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-allgemein"],"_links":{"self":[{"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/posts\/1474","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/comments?post=1474"}],"version-history":[{"count":19,"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/posts\/1474\/revisions"}],"predecessor-version":[{"id":1552,"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/posts\/1474\/revisions\/1552"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/media\/1505"}],"wp:attachment":[{"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/media?parent=1474"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/categories?post=1474"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gfdde.de\/en\/wp-json\/wp\/v2\/tags?post=1474"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}