













Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize.
Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users across approximately 120 organizations, spanning a wide range of industries and countries worldwide. The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page. Victims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoft’s trusted authentication flow while concealing its malicious intent.
The message impersonates a Microsoft Planner task-assignment notification. The sender name is “There’s New Activity On Team,” and the subject line is “HR@[company].com Sent 3 Messages Via Teams Chat”. The body closely mimics Teams styling and references a “Payroll, Compensation + Benefits Update,” alongside a “4 Overdue Employee Tasks” counter intended to create urgency and encourage a quick click. Every link in the message, including both call-to-action buttons, leads through the same redirect. The visible sender address also belongs to the target’s own organization, meaning the email is sent to the same person it appears to come from.


This technique is already common and becoming increasingly widespread. It is a named and tracked technique in the MITRE ATT&CK framework, and in 2026 it evolved from a targeted, manually built attack into a service that virtually anyone can rent.
Depending on the permissions the user approves on the consent screen, the attacker-controlled app can operate across the victim’s entire Microsoft 365 environment:
Among customers whose locations could be classified, the geographic distribution was as follows:
Among customers whose sectors could be classified, the leading sectors were as follows:
Based on the findings, Check Point Email researchers believe that attackers have stopped forging Microsoft’s front door and started walking through it. Every screen the victim sees is authentic, the only fake thing in this entire chain is the intent behind the app requesting access.
The campaign is no longer active, but it’s yet another example of how attackers have fundamentally changed how they’re bypassing traditional phishing defenses.
Report suspicious messages immediately. Early reporting allows security teams to investigate the application, revoke malicious consent, identify affected accounts, and block related campaign activity.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。