Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon
Attackers are exploiting Microsoft’s legitimate login system by directing victims to real Microsoft sign-in pages to grant permissions to malicious apps, enabling phishing campaigns to bypass traditional detection. This method, observed in over 200 phishing emails targeting around 120 organizations worldwide, allows attackers to access email, files, Teams, SharePoint, OneDrive, and calendars within the victim’s Microsoft 365 environment. The campaign emphasizes the growing threat of abuse of trusted authentication flows and highlights the need for vigilance despite appearances of legitimate Microsoft login prompts.













