Home / Latest

Photo of code, software, cryptocurrency
Image: via cdn.mos.cms.futurecdn.net
Latest

Microsoft login pages exploited in phishing campaign

WireByte Staff · August 5, 2026

A phishing campaign targeting over 200 organizations worldwide has compromised user accounts by tricking victims into granting permissions to an attacker-controlled app, rather than stealing passwords. The campaign, which ran from late June to July 2026, used fake Microsoft Teams notifications to route victims to genuine Microsoft login pages. Check Point's email research team identified the campaign and notes that this tactic has become commoditized into a rentable service.

Key points

  • A phishing campaign targeting over 200 organizations worldwide compromised user accounts by tricking victims into granting permissions to an attacker-controlled app.
  • The campaign, which ran from late June to July 2026, used fake Microsoft Teams notifications to route victims to genuine Microsoft login pages.
  • Check Point's email research team identified the campaign and notes that this tactic has become commoditized into a rentable service.
  • The attack relied on tricking users into granting permissions, rather than stealing passwords, making it a sophisticated and effective tactic.
  • Microsoft's Multi-Factor Authentication (MFA) was bypassed in the attack, highlighting the need for additional security measures beyond password protection.

A recent phishing campaign has highlighted a shift in attackers' tactics, as they move away from forging Microsoft's front door and instead walk through it. The campaign, which targeted over 200 organizations worldwide, used fake Microsoft Teams notifications to route victims to genuine Microsoft login pages. This approach allowed attackers to bypass Microsoft's Multi-Factor Authentication (MFA) and gain access to user accounts without stealing passwords.

The campaign, which ran from late June to July 2026, was identified by Check Point's email research team. The team noted that this tactic has become commoditized into a rentable service, making it a sophisticated and effective approach for attackers. This highlights the need for organizations to implement additional security measures beyond password protection, such as restricting app consent and educating users on the risks of phishing attacks.

The attack relied on tricking users into granting permissions to an attacker-controlled app, rather than stealing passwords. This approach is a reminder of the importance of user education and awareness in preventing phishing attacks. Organizations must take steps to protect their users and prevent such attacks from succeeding in the future.

Sources

WireByte Staff — Editorial Team

The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.