SEV3 — ElevatedCLOSEDCyber✓ Corroborated · 5 sources12d ago

HOLLOWGRAPH Espionage Campaign Exploits Microsoft 365 Calendars — Dallas-Fort Worth Contact-Center and Knowledge-Worker Operations

The HOLLOWGRAPH campaign is actively abusing Microsoft 365 calendar sharing features as covert communication channels, enabling threat actors to exfiltrate data and maintain persistence inside corporate environments without triggering standard email-based detection. Dallas-Fort Worth hosts nearly 790,000 contact-center, back-office, and knowledge-worker seats with deep M365 dependency, making this a high-exposure footprint. Operations leaders should coordinate with IT/security to audit calendar-sharing permissions, enforce conditional access policies, and confirm that SIEM rules cover calendar-based anomalies — particularly on agent and supervisor workstations where M365 is the primary productivity layer.

Impact Summary

The HOLLOWGRAPH campaign is actively abusing Microsoft 365 calendar sharing features as covert communication channels, enabling threat actors to exfiltrate data and maintain persistence inside corporate environments without triggering standard email-based detection. Dallas-Fort Worth hosts nearly 790,000 contact-center, back-office, and knowledge-worker seats with deep M365 dependency, making this a high-exposure footprint. Operations leaders should coordinate with IT/security to audit calendar-sharing permissions, enforce conditional access policies, and confirm that SIEM rules cover calendar-based anomalies — particularly on agent and supervisor workstations where M365 is the primary productivity layer.

Domain
Cyber
Opened By
watchkeeper
Jul 20, 2026, 10:00 PM UTC
Validated By
auto
Jul 20, 2026, 10:00 PM UTC
Event Cluster
1 event
OVIX Score
10.0
Closed
watchkeeper-auto(resolved)
Jul 22, 2026, 10:30 AM UTC

Timeline4

Incident openedby watchkeeperJul 20, 2026, 10:00 PM UTC
Declared from 1 signals. OVIX 10. News 0. BPO 3. LLM-confirmed.
Severity validatedby autoJul 20, 2026, 10:00 PM UTC
Auto-validated: SEV3 per policy.
Note addedby watchkeeperJul 20, 2026, 10:00 PM UTC
External corroboration: corroborated (5 sources via Exa). theregister.com, helpnetsecurity.com, infosecurity-magazine.com, itsecurityguru.org, cybersecuritynews.com
Incident closedby watchkeeperJul 22, 2026, 10:30 AM UTC
Auto-closed: no new material events within 36h for this incident.

Evidence / Why this?

Traced to source — read-onlyUpdated Jul 20, 10:00 PM UTC
Why declareddeclareHybrid
Incident declaration (deterministic floor + LLM relevance gate + quality gates)v9
agents-043 VALUE>COST model (ALERTING-PHILOSOPHY.md — Horvitz VALUE>COST, Simon attention, EEMUA discipline). The declare gate is TWO gates, ORed — declare iff Gate A OR Gate B (composed with the existing floors + suppressors). ANTI-SILENCE FIX (gate G1): worthAnalyzing now admits ANY cluster at maxSeverity>=GEO_FLOOR_MIN_SEV (8) OR any Gate-B travel disruption, in addition to the prior (>=2 signals | news>=1 | systemic-travel | wide-AQ-footprint). The old singleton filter dropped every lone sev>=8 signal (70+/day) before Gate A saw it — from 2026-07-18 18:30 only 2-signal cyber roundups reached the gate and nothing declared. Gate A (workforce footprint = geoExposureFloor, generalized from agents-034): VALUE = event magnitude × workforce-footprint density (geo_density). See the geoExposureFloor clause below. Gate B (travel disruption, agents-043): a footprint-INDEPENDENT arm of travelSystemicFloor — see travelSystemicFloor below. DECLARE when deterministicFloor AND (llm.declare OR acuteWeatherFloor OR geoExposureFloor OR travelSystemicFloor OR enviroAirQualityFloor) AND NOT aggregateTitle AND NOT footprintZero AND NOT cyberDeny, and no open same-domain incident merges it (see incident_dedup v1). footprintZero (Gate 1, agents-036) = cluster is geo-scoped (any real region) AND bpoScore=0 (resolved exposure negligible/unmatched) — suppresses declaration INCLUDING via acuteWeatherFloor; the event becomes a brief; logged stage=relevance decision=suppress with the exposure inputs. No national-significance escape hatch (revisit with data). agents-043: a Gate-B travel-disruption declaration is EXEMPT from footprintZero (travel relevance, not local CC density — an airline IT outage/airport ground-stop at a low-density airport must still declare). cyberDeny (Gate 2, agents-036, domain=cyber only) = isNonCcCyberAsset OR isNonSpecificCyberHeadline over the cluster signal titles (the same asset-class check the Impact Engine gates at 0.15x) — hard deny, logged stage=relevance decision=deny. Additionally a cyber declaration at SEV2 requires active-exploitation/CX-nexus evidence matching /actively exploited|exploited in the wild|under active exploitation|known exploited|kev|ransomware|breach(ed|es)|outage/i in the CLUSTER’S OWN signal titles+messages (never domain-wide news context, never LLM output), else it caps at a brief. Replaces the disabled agents-009 cyberFloor (dead code removed). Geo honesty (agents-036): location_* comes from the declaring event’s own region (top-severity signal), never from a different max-exposure member; cyber declarations set location_* null (exposure cities live in affected_regions only). deterministicFloor = (maxSeverity>=8 AND (newsScore>=1 OR bpoScore>=1 OR acuteWeatherFloor)) OR travelSystemicFloor OR enviroAirQualityFloor OR enviroAirQualitySustainedFloor. acuteWeatherFloor = maxSeverity>=9 AND any signal is an acute severe-weather WARNING (tornado/severe-thunderstorm/flash-flood) — overrides the LLM footprint-based suppression but NOT the footprint gate. geoExposureFloor = GATE A (agents-043 workforceFootprintReason, generalizing agents-034): VALUE = magnitude × footprint. Eligible domain in {geopolitical, financial, labor, supply_chain, travel, infrastructure, seismic, disaster, environmental, health} (cyber excluded), OR weather ONLY via the major-storm arm (MAJOR_STORM_CUE hurricane/typhoon/cyclone — the EU-heat suppression is untouched). Declares when bpoScore>=GEO_FLOOR_MIN_BPO (2 — a REAL moderate+ hub; lowered from agents-034 bpo>=3 to stop missing moderate hubs) AND maxSeverity>=GEO_FLOOR_MIN_SEV (8). bpo=0 (no footprint) NEVER declares — a magnitude-9 quake in an unpopulated region is not an incident. Implies footprintZero=false. Severity by workforceFootprintSeverity (incident_severity v5), NOT mapSevLevel: sev>=9 × bpo>=3 → SEV1 (Manila-class), sev>=9 × bpo==2 → SEV2, sev>=8 × bpo>=2 → SEV3. agents-046 (G1 UNDER-DECLARE FIX — ALERTING-PHILOSOPHY.md G1): the TROPICAL-SYSTEM active-threat arm lowers Gate A's floor to MAJOR_STORM_MIN_SEV (7) when a cluster matches MAJOR_STORM_CUE (named tropical system) AND carries a STORM_ACTIVE_THREAT_CUE (watch/warning/approaching/landfall/storm-surge/evacuation) AND bpo>=GEO_FLOOR_MIN_BPO (2). A tracked, in-progress tropical storm bearing on a member coastline (sev 7–7.5, below the sev-8 bar hurricanes reach) is a legitimate 0–72h contact-center risk and MUST declare (it was silently missed by 0.5 sev). THIS ARM ONLY drops to 7; every other Gate A path keeps sev>=8, and a tropical system with NO active-threat cue (a distant mid-ocean advisory) also keeps 8. worthAnalyzing admits it (majorStormFloorEligible) even below the sev-8 anti-silence bar. reason=tropical-storm:sev7xbpoN; maps to SEV3 (workforceFootprintSeverity tropicalActiveThreat, incident_severity v5). NOTE (data follow-up, not this rule): disaster-feed tropical systems geo-tagged "Global" resolve to bpo=0 and are still suppressed — an api geo-quality task. travelDisruption = GATE B (agents-043 travelDisruptionReason, an arm of travelSystemicFloor): the MORE-SENSITIVE, footprint-INDEPENDENT travel bar (travel is the strategic showcase). domain=travel AND maxSeverity>=TRAVEL_SYSTEMIC_MIN_SEV (6) AND (a named travel operator/system with a disruption cue via travelSystemKey — airline/ATC/GDS/rail — OR an aviation ground_stop/airspace/it_outage hazard with aviation context TRAVEL_AVIATION_CONTEXT). Declares REGARDLESS of local CC-hub density (bypasses footprintZero). Declares SEV3 (isSystemicTravel mapping). Composes WITH (does not replace) the agents-039 aggregate hub/system arms. travelSystemicFloor (agents-039 Gate 5, domain=travel only; travel clusters pull at sev>=6 instead of 8) = maxSeverity>=6 AND (HUB arm: >=3 distinct underlying events (eventKey identity) in one (travel, geoKey) cluster AND bpoScore>=3; OR SYSTEM arm: the cluster names a travel operator/system entity (airline/ATC/GDS/rail — travelSystemKey, disruption-cue required) carrying >=5 distinct events across >=2 geo cluster keys this cycle AND bpoScore>=2). Member-relevance mandatory on both arms (implies footprintZero=false); overrides the LLM footprint suppression like the other floors; scattered unrelated low-sev travel news fails every arm. Sibling clusters of one systemic operator event merge via the travel-system entity key (incident_dedup v3), not as clones. enviroAirQualityFloor (agents-040 Gate 6 + agents-041 windowed footprint, domain=environmental only; environmental air-quality/smoke clusters pull at sev>=6 instead of 8, scoped to an air-quality title pre-filter) = FOOTPRINT arm: this CURRENT-cycle cluster carries an air-quality/smoke hazard signal (enviroHazardOf — air quality/AQI/smoke/haze/ozone advisory, EXCLUDING political/diplomatic/opinion framing per ENVIRO_AQ_POLITICAL_DENY — "blasts"/"threatens tariffs"/"slams"/lawsuit/sanctions etc. are not hazard readings and cast no vote nor declare) at sev>=6 AND >=3 distinct cities/metros carry such a hazard at sev>=6 over the last 18h (agents-041 ENVIRO_AQ_WINDOW_H — a cumulative hazard fans across HOURS not one ~60-min cycle; tallyEnviroAirQualityWindow over the signals table, the resolved geoKey is the vote unit so re-emission within a city and macro-region collapse cannot inflate breadth, distinct cities like Chicago/Cleveland/Detroit each count) AND bpoScore>=2 (a member-relevant hub). Member-relevance mandatory (smoke over unpopulated areas never declares); a single-city AQI alert (1 city, incl. one city re-emitting over the window) never declares; low-sev environmental noise sits below the sev floor. Overrides the LLM footprint suppression like the other floors. Sibling clusters of one smoke wave merge via the air-quality EPISODE key (incident_dedup v3), not as clones — a wider window refreshes ONE incident per (smoke family, macro-region), never dailies. The sev>=8 geoExposureFloor (single-city) is untouched. enviroAirQualitySustainedFloor (agents-042 Gate 6b, domain=environmental only) = the SUSTAINED-footprint arm, ORed onto the agents-041 fresh-cluster arm (not a replacement): >=ENVIRO_AQ_MIN_CITIES (3) distinct MEMBER-HUB cities (bpo>=ENVIRO_AQ_MIN_BPO=2) carry a genuine air-quality/smoke hazard (enviroHazardOf non-null — political/opinion framing still denied, casts no vote) at sev>=ENVIRO_AQ_MIN_SEV (6) over the last 18h window (tallyEnviroAirQualityMemberHubs), EVEN WITH NO fresh current-cycle declaring cluster. This surfaces a waning/ongoing multi-day smoke episode that arrives in WAVES (genuine member-hub readings hours apart) as an incident — the exact 07-17/18 live failure where the freshest genuine member-hub reading was ~7.5h old and only political noise arrived fresh, so the fresh-cluster arm never fired and ZERO incidents declared despite a real 3-city footprint. The difference vs the fresh-cluster arm: there is NO declaring cluster, so member-relevance is carried by the FOOTPRINT — the city count is restricted to bpo-qualified member hubs (3 non-hub cities, e.g. Indonesia-only, cannot declare; 3+ real member hubs can). The incident is DETERMINISTICALLY anchored to the WINDOW (title/severity/regions from the member-hub AQ signals + max severity, anchorSustainedEnviroIncident), not a single fresh signal. It EPISODE-merges into the same air_quality/smoke incident (incident_dedup v3) so consecutive cycles never spawn a duplicate — a sustained-cycle merge refreshes ONLY on genuinely-new member-hub material event keys (agents-010 Fault B), so the SEV3 36h quiet-close + max-age backstop retire the incident once the footprint decays below K (no explicit decay-close required). Logged with a DISTINCT reason string smoke-sustained-footprint:Ncities (vs the fresh arm smoke-footprint:Ncities). aggregateTitle (grab-bag "Multiple/Several/Various…") is refused (agents-019 §D). Asset-class deny (military/war-zone, WFM-37) suppresses earlier.
domain
cyber
regions
["Dfw"]
bpo score
3
gate a via
news score
0
value gate
LLM relevance + deterministic floor
llm declare
yes
max severity
10
signal count
1
actionability
Ops action (0–72h): monitor staffing/connectivity/service-level impact for this sev-10 cyber event and adjust coverage as it develops.
density class
high
llm rationale
Declared: HOLLOWGRAPH directly targets M365 infrastructure that underpins one of the largest contact-center and knowledge-worker concentrations in the US (DFW, high density), with confirmed multi-source coverage and realistic potential to disrupt productivity tooling, data handling, and compliance posture across in-house and outsourced operations.
footprint zero
no
aggregate title
no
high confidence
no
travel system key
geo exposure floor
no
acute weather floor
no
deterministic floor
yes
travel systemic via
exposure region label
Dallas-Fort Worth, US
travel disruption via
travel systemic floor
no
enviro air quality via
enviro aq max severity
0
travel disruption floor
no
enviro air quality floor
no
enviro aq footprint cities
0
model claude-sonnet-4-6 · prompt watchkeeper-declare-2026-06
Why SEV3SEV3score 3Deterministic
Incident severity level (SEV1–SEV4) at declarationv5
agents-043 (v4): a Gate A workforce-footprint declaration (geoExposureFloor) is scored on VALUE = magnitude × footprint via workforceFootprintSeverity, NOT the base mapSevLevel: catastrophic (sev>=9) × MAJOR hub (bpo>=3) → SEV1 (the Manila 7.0-quake worked example — this deliberately supersedes the single-event cap per ALERTING-PHILOSOPHY.md / Ted's criteria); sev>=9 × moderate hub (bpo==2) → SEV2; sev>=8 × bpo>=2 → SEV3. SEV1/SEV2 remain human-gated at declaration (validation pending). Every other path keeps the base mapSevLevel below unchanged. agents-046 (v5): the named-tropical-system active-threat arm (workforceFootprintSeverity tropicalActiveThreat, sev 7–7.99 × bpo>=2) → SEV3 — a tracked storm approaching a footprint coast is a genuine 0–72h disruption a WFM leader pre-positions for (same SEV3 honesty as the acute-severe-weather floor). The flag is a no-op for sev>=8 (those hit the higher branches), so hurricanes are unaffected. Base: SEV2 if sev>=9 AND news>=2 AND bpo>=1; else SEV3 if sev>=8 AND (news>=1 OR bpo>=1); else SEV4. Acute severe-weather (agents-028): if sev>=9 floor to SEV3 (SEV2→SEV3); minor/transient watches+advisories drop SEV2/SEV3→SEV4. Single-event cap: any SEV2 caps to SEV3 absent sustained multi-day BPO-region corroboration (SEV2 promotion is human-gated via revalidation). Systemic-travel floor (agents-039): a travelSystemicFloor declaration (multi-signal aggregate on member-relevant geography, sev 6-7 by design) floors SEV4→SEV3 — a region-level operational disruption, same honesty argument as the acute-weather SEV3 floor. It never raises anything to SEV2: SEV2 keeps its base intensity+news+human gating. Environmental air-quality floor (agents-040): an enviroAirQualityFloor declaration (multi-city cumulative air-quality/smoke aggregate on member-relevant geography, sev 6-7 by design) likewise floors SEV4→SEV3, and never raises anything to SEV2. score = numeric SEV (1=most severe … 4); SEV3/SEV4 auto-validate, SEV1/SEV2 require human validation.
domain
cyber
bpo score
3
news score
0
persistent
no
max severity
10
auto validated
yes
acute weather floor
no
travel systemic floor
no
Geo Provenance
Tierapprox
Sourcenone
Deterministic

Related Signals16

[Dfw] cyber 10.0 — AutomationDirect Productivity Suitesentinel10d ago[Dfw] cyber 10.0 — SALTO ProAccess Spacesentinel10d ago[Dfw] cyber 10.0 — Tycon Systems TPDIN-Monitor-WEB2sentinel11d ago[Dfw] cyber 10.0 — SALTO ProAccess Spacesentinel11d ago[Dfw] cyber 10.0 — Tycon Systems TPDIN-Monitor-WEB2sentinel11d ago[Dfw] cyber 10.0 — AutomationDirect Productivity Suitesentinel11d ago[Dfw] cyber 10.0 — NASA Core Flight System (cFS) Health & Safety (HS) Applicationsentinel11d ago[Dfw] cyber 10.0 — SALTO ProAccess Spacesentinel11d ago[Dfw] cyber 10.0 — CISA Adds Four Known Exploited Vulnerabilities to Catalogsentinel11d ago[Dfw] cyber 10.0 — AutomationDirect Productivity Suitesentinel11d ago[Dfw] cyber 10.0 — NASA Core Flight System (cFS) Health & Safety (HS) Applicationsentinel11d ago[Dfw] cyber 10.0 — CISA Adds Four Known Exploited Vulnerabilities to Catalogsentinel11d ago[Dfw] cyber 10.0 — AutomationDirect Productivity Suitesentinel11d ago[Dfw] cyber 10.0 — NASA Core Flight System (cFS) Health & Safety (HS) Applicationsentinel11d ago[Dfw] cyber 10.0 — SALTO ProAccess Spacesentinel12d ago[Dfw] cyber 10.0 — AutomationDirect Productivity Suitesentinel12d ago

External Corroboration

✓ Corroborated · 5 sourcesChecked Jul 20, 2026, 10:00 PM UTC
Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaigntheregister.comJul 20, 2026, 12:00 AM UTCHOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel - Help Net Securityhelpnetsecurity.comJul 20, 2026, 05:20 PM UTCNew HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 - Infosecurity Magazineinfosecurity-magazine.comJul 20, 2026, 12:00 AM UTCResearchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites - IT Security Guruitsecurityguru.orgJul 20, 2026, 12:00 AM UTCHackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channelscybersecuritynews.comJul 20, 2026, 12:00 AM UTC

Affected Regions

Dfw