WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Threat Awareness – Microsoft 365 AutoSave Features Can be Exploited to Encrypt Files
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Threat Awareness – Microsoft 365 AutoSave Features Can be Exploited to Encrypt Files

Author: Alec Davison

Created: Tuesday, June 21, 2022 - 19:28

Categories: Cybersecurity

Security researchers have uncovered a potential new ransomware-related threat to Office 365 account users. In this case, adversaries could utilize compromised Office 365 accounts to encrypt files stored in SharePoint and OneDrive cloud services. The attack relies on manipulating the “AutoSave” feature which creates cloud backups of older file types when users make edits. To conduct this attack threat actors need only to compromise an employee’s Office 365 account, usually done via phishing or malicious OAuth apps. This attack-type does not require administrative privileges and can be conducted from any compromised employee account.

Adversaries can then use Microsoft APIs and PowerShell scripts to automate malicious activity on large document lists. To encrypt the files, attackers reduce the version numbering limit and encrypt all files more than that limit. According to BleepingComputer, “With a file version limit set to “1,” when the attacker encrypts or edits the file twice, the original document will no longer be available through OneDrive and cannot be restored.” Once the documents are encrypted, the threat actor can request a ransom from the victim in order to restore their files. Read more at BleepingComputer.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 18, 2026)

Jun 18, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:AMBER) IOC Associated with Volt Typhoon Performed Network Enumeration on Utah Infrastructure

Jun 18, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Email Impersonation Remains a Persistent Risk for Water Utilities

Jun 18, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar