Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon

https://www.itvoice.in/wp-content/uploads/2026/07/Copy-of-Redington-2026-07-29T161106.126.jpg

Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize.

Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users across approximately 120 organizations, spanning a wide range of industries and countries worldwide. The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page. Victims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoft’s trusted authentication flow while concealing its malicious intent.

The Lure

The message impersonates a Microsoft Planner task-assignment notification. The sender name is “There’s New Activity On Team,” and the subject line is “HR@[company].com Sent 3 Messages Via Teams Chat”. The body closely mimics Teams styling and references a “Payroll, Compensation +...

Copyright of this story solely belongs to itvoice.in. To see the full text click HERE

Read more