• Watch out Microsoft login pages are being abused as hackers try

    From TechnologyDaily@1337:1/100 to All on Wed Aug 5 00:30:24 2026
    Watch out Microsoft login pages are being abused as hackers try and lure in unlucky victims, here's what to look out for

    Date:
    Tue, 04 Aug 2026 23:15:00 +0000

    Description:
    No passwords were stolen, and MFA never came into it; they walked away with access to mail, files, Teams, SharePoint, and calendars across around 120 organizations.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Phishing campaign used fake Teams notifications to route victims to a genuine Microsoft sign-in page Rather than stealing passwords, attackers asked victims to approve
    permissions for an attacker-controlled app, gaining access to mail, files, Teams, SharePoint, OneDrive and calendars without defeating MFA Check Point says the technique has been commoditized in 2026 into a rentable service; the practical defense is restricting app consent rather than relying on users to spot a fake A phishing campaign that ran from late June into July 2026 did something that breaks most of the advice organizations have spent a decade teaching their staff: it sent victims to a real Microsoft login page.

    Check Point's email research team, which disclosed the campaign , identified more than 200 phishing emails targeting users across roughly 120
    organizations worldwide. The lure was a fake Microsoft Teams notification
    with a genuine destination; what actually compromised accounts was not a stolen password but a permissions prompt that the victim clicked through voluntarily. Latest Videos From TechRadar Watch full video here: A sophisticated attack that relied on tricking users into granting permissions Check Point noted in its brief that what actually compromised the accounts
    was not a stolen password but a permissions prompt that the victim clicked through voluntarily. This is a reminder of a stark change in attackers' tactics: they have stopped forging Microsoft's front door and started walking through it.

    The email appeared to be a Microsoft Planner task-assignment notification.
    The sender name read "There's New Activity On Team," the subject line claimed that HR had sent three messages via Teams chat, and the body referenced a payroll and benefits update, along with a counter showing four overdue employee tasks. You may like 81 million login attempts hit Microsoft 365 accounts as hackers try password-spraying to force entry Microsoft warns hackers are exploiting password resets to gain access to user accounts The enemy within: how to stop a simple Teams message taking down your business

    To someone who works in security, the message had its own telltale signs of being a typical phishing attempt: every link in the email, including both call-to-action buttons, routed through the same redirect. And the visible sender address belonged to the recipient's own organization, meaning the
    email appeared to have been sent to the same person it came from.

    The link opened a real OAuth authorization URL on login.microsoftonline.com, not a look-alike domain. Signing in displayed a permissions prompt asking the user to approve the permissions or accept them on behalf of their organization. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
    or sponsors By submitting your information you agree to the Terms &
    Conditions and Privacy Policy and are aged 16 or over.

    If they did, Microsoft redirected the browser to the redirect address specified in the original request, which in this particular campaign was an AWS API Gateway endpoint under the attackers' control. The authorization code was delivered there, and the attackers exchanged it for access. No password was stolen at any point, and there was no fake page to spot.

    This is not unlike how the phishing-as-a-service Kali365 platform compromises Microsoft accounts, but instead of stealing session cookies or OAuth tokens, it opts for a more permanent illicit grant of consent.

    This runs counter to the usual security training checklist, which emphasizes adhering to norms rather than going against the grain; users are told to
    check the URL, look for the padlock, and watch for misspelled domains. None
    of those measures matter because there is nothing forged to catch. The domain and certificate are Microsoft's, while the sign-in page is the one the user sees every morning, offering a false sense of security to a user not looking for this particular attack vector. What to read next The FBI warns Microsoft 365 services are being bombarded with new phishing emails here are 3 steps you can take to stay safe Devious phishing campaign hijacks a genuine Meta business feature to send scam emails as they really do come from Meta's own address AI security scams: How to spot the signs, and not fall for this growing menace

    Multi-factor authentication does not help either; it protects the login sequence but not access to the user's data post-login. The attacker never needs the password or the second factor because they walk away with a token granted by the user's valid session, a technique called 'consent phishing'.

    There are many ways to prevent this, but the simplest two are asking users to check every single permission/consent screen they click (the phishing attempt still requires users to allow it) and limiting access to permissions for user accounts that applications can request via Microsoft Entra at the system administrator level.

    It would be prudent to do the latter at a minimum, even as Check Point notes that the campaign is no longer active because the underlying technique it
    used is not going anywhere. Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/watch-out-microsoft-login-pages-are-bei ng-abused-as-hackers-try-and-lure-in-unlucky-victims-heres-what-to-look-out-fo r


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)